<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=from+wasm+highperformance+localfirst%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 03:45:32 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 03:45:32 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=from+wasm+highperformance+localfirst%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=from+wasm+highperformance+localfirst%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 660]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3672376/tools/this-week-in-rust-this-week-in-rust-660/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672376/tools/this-week-in-rust-this-week-in-rust-660/</guid>
<pubDate>Thu, 16 Jul 2026 07:09:13 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/2026/07/09/Rust-1.97.0/">Announcing Rust 1.97.0</a></li>
<li><a href="https://blog.rust-lang.org/2026/07/13/crates-io-development-update/">crates.io: development update</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://bun.com/blog/bun-in-rust">Rewriting Bun in Rust</a></li>
<li><a href="https://bullmq.io/news/260712/rust-release/">Announcing BullMQ for Rust</a></li>
<li><a href="https://github.com/zs-dima/prost-protovalidate/releases/tag/v0.6.0">prost-protovalidate 0.6 — buf.validate (protovalidate) for prost and buffa: compile-time codegen + runtime CEL, 2872/2872 conformance</a></li>
<li><a href="https://github.com/StaszeKrk/plaza/releases/tag/v1.0.0">plaza 1.0: a ratatui package-manager TUI that searches pacman, the AUR, apt, dnf, and Flatpak at once</a></li>
<li><a href="https://github.com/danube-messaging/danube/releases/tag/v0.15.1">Danube v0.15.1: native Apache Iceberg integration for streaming-to-lakehouse export</a></li>
<li><a href="https://www.willsearch.com.br/sentinel/">Guardian Sentinel. The Terminal User Interface for Guardian Decentralized Database - P2P</a></li>
<li><a href="https://github.com/kunobi-ninja/kobe/releases/tag/v0.33.0">kobe 0.33.0: a Rust operator for instant CI Kubernetes clusters</a></li>
<li><a href="https://navigatorbuilds.github.io/elara-mesh/blog/black-box-for-ai-agents.html">Elara Mesh: what the black box for AI agents actually does</a></li>
<li>
<p><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.10.0">kache 0.10.0: instant download dedup, no more polling</a></p>
</li>
<li>
<p><a href="https://richer-richard.github.io/cochlea/">cochlea 0.1.0: a headless, deterministic audio engine for AI agents</a></p>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://opensourcesecurity.io/2026/2026-07-rfmf-lori-niko/">Open Source Security Podcast: Rust Foundation Maintainers Fund with Lori and Niko</a></li>
<li><a href="https://pulsebeam.dev/blog/moving-to-thread-per-core">Moving a Rust WebRTC SFU to thread-per-core</a></li>
<li><a href="https://abundance.build/blog/2026-07-11-faster-rust-tests-in-ci-with-parallel-steps/">Faster Rust tests in CI with parallel steps</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=fugcSHD-9Jw">The Only Diagram You Need to Understand Rust Ownership</a></li>
<li><a href="https://encore.dev/blog/typescript-parser-wasm">We compiled our TypeScript parser to WASM</a></li>
<li><a href="https://kerkour.com/rust-hype">Understanding the Rust hype for the busy developer</a></li>
<li><a href="https://dev.to/akavlabs_69/i-red-teamed-my-own-llm-security-gateway-in-four-passes-heres-every-gap-i-found-5cl9">I red-teamed my own LLM security gateway (Rust) in four passes — every detection gap and how I closed it</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li>[video] <a href="https://www.youtube.com/watch?v=DJhhy6YQe8k">Backend Concepts in Rust: HTTP Servers</a></li>
<li><a href="https://dystroy.org/blog/picamobile/">Fearless Embedded Rust: A FPV Lego car</a></li>
<li><a href="https://www.aravpanwar.com/writing/building-decayfmt-in-rust/">What I learned building a self-corrupting file format in Rust</a></li>
<li><a href="https://corentin-core.github.io/posts/ruxe-async-runtime-agnostic/">Come Async You Are</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#miscellaneous">Miscellaneous</a></h5>
<ul>
<li><a href="https://blog.theembeddedrustacean.com/oxidize-xiao">Oxidize XIAO — An Embedded Rust Community Program</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://crates.io/crates/dashu">dashu</a>, a pure Rust set of libraries of arbitrary precision numbers.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1628">JacobZ</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>



<ul>
<li><a href="https://github.com/supernovae-st/nika/issues/424">Nika - showcase: CSV → chart PNG → markdown report (nika:chart has no example yet)</a></li>
</ul>


<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>550 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-07-07..2026-07-14">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158931">inline some <code>Symbol</code> functions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157104">predicate/clause cleanups</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158942">remove some AST <code>tokens</code> fields</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159019">resolver: wrap arenas in <code>WorkerLocal</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158794">rework read deduplication with pooled read recorders</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159012">shrink <code>mir::Statement</code> to 40 bytes</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157491">shrink no-op drop elaboration</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158865">specialize common <code>(1, 1)</code> case for arg unification</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158842">use SmallVec for return places in MIR</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/158866">add explicit <code>Iterator::count</code> impl for <code>ChunkBy</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157153">allow <code>Allocator</code>s to be used as <code>#[global_allocator]</code>s</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158876">fix multiple logic bugs in <code>Arc::make_mut</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158940">implement feature <code>char_to_u32</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159092">make volatile operations const</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/158541">move <code>std::io::Write</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/159099">stabilize <code>String::from_utf8_lossy_owned</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/151379">stabilize <code>VecDeque::retain_back</code> from <code>truncate_front</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17199"><code>install</code>: Move --debug to Compilation options</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17204"><code>source</code>: incorrect duplicate package warning</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17202">fix manifest schema generation: <code>TomlDebugInfo</code> enum-variants doesn't renamed</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17198">dont apply host-config gating to stable behavior</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17191">reduce library search path length in new build dir layout</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17168">reduce rustc <code>-L</code> args used in the new <code>build-dir</code> layout</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17149">rename <code>-Zno-embed-metadata</code> to <code>-Zembed-metadata=no</code></a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17203">test: fix race in <code>cargo_compile_with_invalid_code_in_deps</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/15000">add new lints: <code>rest_pattern_accessible_field</code> and <code>unnecessary_rest_pattern</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16965">new lint: <code>definition_in_module_root</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17343"><code>arbitrary_source_item_ordering</code>: add configurable trait impl item ordering modes</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17387"><code>tests_outside_test_module</code>: put code in backticks in the lint message</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17215">count length of the first paragraph by its text</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16980">fix <code>suboptimal_flops</code> false negative with ambiguous float literals</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17416">partly disable <code>unneeded_wildcard_pattern</code> when <code>rest_pattern_accessible_field</code> is enabled</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17404">respect the configured MSRV in <code>implicit_saturating_sub</code>'s <code>if x != 0 { x -= 1 }</code> rewrite</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16513">trigger <code>single_element_loop</code> if the block contains only a final expression</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16808">optimize <code>nonstandard_macro_braces</code> by 99.9683% (1.1b → 351K)</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17381">perf: bail out of the <code>disallowed_methods</code> rule if the disallowed list is empty</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22771">ask for disclosure in AI contributions</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22734">add fixes for array length for <code>type_mismatch</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22741">add parens in transformed dyn type in ref type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22736">avoid panic in merge imports on trailing path separator</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22654">change some things for <code>#[doc = macro!()]</code> expansion</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22770">clamp cttz const-eval result to type width</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22751">correctly handled cfg'ed tail expr, take 2</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22749">crash on code actions when an unresolved module is present</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22707">crash when computing diagnostics with MIR and error types</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22744">don't complete default in default impl</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22283">early late classification of lifetimes</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22583">fix <code>render_const_using_debug_impl</code> constructing outdated std layouts</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22735">fix proc macros <code>TokenStream::from_str()</code> for doc comments</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22464">hide private fields on hover depending on context</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22753">make lsp-server <code>Response</code> type closer aligned to JSON-RPC</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22535">pretty assoc const when trait in macro</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22747">reimplement <code>crate_supports_no_std</code> syntactic heuristic</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22773">resolve non-plain paths in blocks correctly</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22683">support Cargo 1.97.0 lockfile path setting</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22405">hir-ty: walk container exprs for <code>unused_must_use</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22768">fix onEnter erroneously deleting/interpreting <code>$foo</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22726">suggest code action fixes produced from diagnostics under cursor, even if they have effects elsewhere</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22777">treat library files as truly client immutable</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22534">turn <code>BlockLoc</code> into a tracked struct, take 3</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week many new optimizations landed, making this a very good week for performance.
The only real regression was a fix for a miscompile that will likely be re-landed in the future.</p>
<p>Triage done by <strong>@JonathanBrouwer</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=3659db0d3e2cd634c766fcda79ed118eca31a9fd&amp;end=5503df87342a73d0c29126a7e08dc9c1255c46ad&amp;absolute=false&amp;stat=instructions%3Au">3659db0d..5503df87</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.3%</td>
<td>[0.2%, 0.4%]</td>
<td>3</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>0.9%</td>
<td>[0.1%, 2.5%]</td>
<td>25</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-1.2%</td>
<td>[-9.9%, -0.2%]</td>
<td>195</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-3.4%</td>
<td>[-92.1%, -0.1%]</td>
<td>174</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-1.2%</td>
<td>[-9.9%, 0.4%]</td>
<td>198</td>
</tr>
</tbody>
</table>
<p>2 Regressions, 10 Improvements, 10 Mixed; 7 of them in rollups
36 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/212da2d63f1edf2ab22293547a99f0fbf8cb68a8/triage/2026/2026-07-13.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3955">Named <code>Fn</code> trait parameters</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/159179">enable <code>unreachable_cfg_select_predicates</code> lint as part of <code>unused</code> lint group</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/156906">Stabilize <code>dyn Allocator</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/146954">Tracking Issue for vec_try_remove</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157226">Partially stabilize <code>box_vec_non_null</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/152761">Never break between empty parens</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1015">Enable <code>-Zpolonius=next</code> on nightly</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1014">Enable <code>-Znext-solver</code> on nightly by default for testing</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1012">Stabilizing the state of the debuginfo test suite</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/922">Optimize <code>repr(Rust)</code> enums by omitting tags in more cases involving uninhabited variants.</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/841">Proposal for Adapt Stack Protector for Rust</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>,
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3983">bf16 primitive type</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-07-15 - 2026-08-12 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-07-15 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/21k797xr"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045926/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-19 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329045/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315102297/"><strong>Lunch &amp; Learn: Learning Rust as First Programming Language</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (Tel Aviv-yafo, IL) | <a href="https://www.meetup.com/rust-tlv/events/">Rust 🦀 TLV</a><ul>
<li><a href="https://www.meetup.com/rust-tlv/events/315676843/"><strong>שיחה חופשית ווירטואלית על ראסט</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/315279653/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/hd8mlw56"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/315418155/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-07-28 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254777/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-29 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/uo5ek1f4"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/312045928/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-08-02 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095294/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Virtual (London, GB) | <a href="https://www.meetup.com/women-in-rust/events/">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315213885/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-08-05 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/f2hnzrug"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-08-05 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs/events/">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210367/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-08-11 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254776/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-08-12 | Virtual (Girona, ES) | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/f2hnzrug"><strong>Sessió setmanal de codificació / Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-07-19 | Virtual (Bangalore, IN) | <a href="https://discord.gg/VJyv3NfVdw">Embedded Rust Discord</a><ul>
<li><a href="https://discord.gg/6gwCNpFP?event=1526087936234225814"><strong>Silicon Sundays</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-07-18 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a><ul>
<li><a href="https://hasgeek.com/rustbangalore/july-2026-rustacean-meetup/"><strong>July 2026 Rustacean Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-19 | Virtual (Bangalore, IN) | <a href="https://discord.gg/VJyv3NfVdw">Embedded Rust Discord</a><ul>
<li><a href="https://discord.gg/6gwCNpFP?event=1526087936234225814"><strong>Silicon Sundays</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Mumbai, IN | <a href="https://luma.com/mumbai">Rust Mumbai</a><ul>
<li><a href="https://luma.com/7ksabwbm/"><strong>​Rust Mumbai — July Meetup 🦀</strong></a></li>
</ul>
</li>
<li>2026-07-26 | Pune, MA, IN | <a href="https://www.meetup.com/rust-pune/events/">Rust Pune</a><ul>
<li><a href="https://www.meetup.com/rust-pune/events/315651505/"><strong>Rust Pune: July 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-07-15 | Dortmund, DE | <a href="https://www.meetup.com/rust-dortmund/events/">Rust Dortmund</a><ul>
<li><a href="https://www.meetup.com/rust-dortmund/events/315496876/"><strong>Teach and Hack at Projektspeicher</strong></a></li>
</ul>
</li>
<li>2026-07-21 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313816470/"><strong>Supercharge Rust funcs with implicit arguments and context-generic programming</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/315484101/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/london-rust-project-group">London Rust Project Group</a><ul>
<li><a href="https://www.meetup.com/london-rust-project-group/events/315366453/"><strong>Rama modular service framework for Rust</strong></a></li>
</ul>
</li>
<li>2026-07-23 | London, UK | <a href="https://www.meetup.com/rust-london-user-group/events/">Rust London User Group</a><ul>
<li><a href="https://www.meetup.com/rust-london-user-group/events/315612916/"><strong>LDN Talks: July 2026 Antithesis Takeover</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315309633/"><strong>Rust meetup #87</strong></a></li>
</ul>
</li>
<li>2026-07-29 | Poland, PL | <a href="https://www.meetup.com/rust-poland-meetup">Rust Poland</a><ul>
<li><a href="https://www.meetup.com/rust-poland-meetup/events/315582674/"><strong>Rust Poland x Kraków #10</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Manchester, GB | <a href="https://www.meetup.com/rust-manchester/events/">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315037685/"><strong>Rust Manchester July Code Night</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-07-15 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-07-16 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314520812/"><strong>July, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-18 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225872/"><strong>North End Rust Lunch, July 18</strong></a></li>
</ul>
</li>
<li>2026-07-21 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314997214/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjckbdc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-07-22 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/315376271/"><strong>Rust LA: Rust in Distributed Systems with Flight Science!</strong></a></li>
</ul>
</li>
<li>2026-07-22 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc/events/">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/315636854/"><strong>Rust NYC: Write A Custom Coding Agent and wasm_zero</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582650/"><strong>Porter Square Rust Lunch, July 25</strong></a></li>
</ul>
</li>
<li>2026-07-25 | Brooklyn, NY, US | <a href="https://flowercomputer.com/">Flower</a><ul>
<li><a href="https://partiful.com/e/Vq9fyDNCMSO7ia4ulK5b"><strong>BOG-A-THON 2</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl/events/">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539329/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-08-01 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315582653/"><strong>Chinatown Rust Lunch, Aug 1</strong></a></li>
</ul>
</li>
<li>2026-08-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314660176/"><strong>Evening Boston Rust Meetup at Red Hat, Aug 4</strong></a></li>
</ul>
</li>
<li>2026-08-06 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust/events/">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/314701905/"><strong>Shipping Temporal: How a Global Rust Ecosystem Built Chrome’s Newest Web API</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-08-08 | São Paulo, SP | <a href="https://luma.com/calendar/cal-bif2oHITU1aVvsr">Rust-SP</a><ul>
<li><a href="https://luma.com/41oiyhtk"><strong>Rust SP - Aug/2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-07-21 | Barton, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a><ul>
<li><a href="https://www.meetup.com/rust-canberra/events/315307280/"><strong>July Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-23 | Perth, AU | <a href="https://www.meetup.com/perth-rust-meetup-group">Rust Perth Meetup Group</a><ul>
<li><a href="https://www.meetup.com/perth-rust-meetup-group/events/315451138/"><strong>Rust Perth: July Meetup!</strong></a></li>
</ul>
</li>
<li>2026-07-30 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne/events/">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039480/"><strong>Rust Melbourne July 2026</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>Thank you for your PR, but please edit the description like you are a chainsaw-wielding maniac that just discovered the sentences are young adults who came to the lake at summer camp after sunset.</p>
</blockquote>
<p>– <a href="https://github.com/rust-lang/rust/pull/159039#issuecomment-4931084997">workingjubilee on Rust github</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1786">Theemathas</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1uxsigp/this_week_in_rust_660/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026.6.1]]></title>
<description><![CDATA[ImportantThis release applies to self-hosted deployments. Cloud web remains on the previous stable release, and the Cloud Desktop App release is deferred, while the personal-workspace data-loss issue (#6483) is being addressed.

This patch release resolves a Desktop App login loop when signing in...]]></description>
<link>https://tsecurity.de/de/3670447/downloads/202661/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670447/downloads/202661/</guid>
<pubDate>Wed, 15 Jul 2026 13:17:06 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="markdown-alert markdown-alert-important"><p class="markdown-alert-title"><svg data-component="Octicon" class="octicon octicon-report mr-2" viewbox="0 0 16 16" version="1.1" width="16" height="16" aria-hidden="true"><path d="M0 1.75C0 .784.784 0 1.75 0h12.5C15.216 0 16 .784 16 1.75v9.5A1.75 1.75 0 0 1 14.25 13H8.06l-2.573 2.573A1.458 1.458 0 0 1 3 14.543V13H1.75A1.75 1.75 0 0 1 0 11.25Zm1.75-.25a.25.25 0 0 0-.25.25v9.5c0 .138.112.25.25.25h2a.75.75 0 0 1 .75.75v2.19l2.72-2.72a.749.749 0 0 1 .53-.22h6.5a.25.25 0 0 0 .25-.25v-9.5a.25.25 0 0 0-.25-.25Zm7 2.25v2.5a.75.75 0 0 1-1.5 0v-2.5a.75.75 0 0 1 1.5 0ZM9 9a1 1 0 1 1-2 0 1 1 0 0 1 2 0Z"></path></svg>Important</p><p>This release applies to self-hosted deployments. Cloud web remains on the previous stable release, and the Cloud Desktop App release is deferred, while the personal-workspace data-loss issue (<a href="https://github.com/hoppscotch/hoppscotch/issues/6483" data-hovercard-type="issue" data-hovercard-url="/hoppscotch/hoppscotch/issues/6483/hovercard">#6483</a>) is being addressed.</p>
</div>
<p>This patch release resolves a Desktop App login loop when signing in to self-hosted instances, adds support for running containers under arbitrary non-root user IDs, and enables response-cookie capture for Agent-routed requests, alongside a lighter JSON response renderer.</p>
<h2>What's Changed</h2>
<ul>
<li>feat: allow containers to run with arbitrary non-root UIDs by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/mirarifhasan/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/mirarifhasan">@mirarifhasan</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4784576502" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/6481" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/6481/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/6481">#6481</a></li>
<li>fix: desktop login loop caused by empty auth cookies by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CuriousCorrelation/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CuriousCorrelation">@CuriousCorrelation</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4870552739" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/6502" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/6502/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/6502">#6502</a></li>
<li>fix: bump <code>relay</code> for agent response-cookie capture and pin fork revisions by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CuriousCorrelation/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CuriousCorrelation">@CuriousCorrelation</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4836632360" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/6496" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/6496/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/6496">#6496</a></li>
<li>fix(common): lazy-load <code>jq-wasm</code> in the JSON lens renderer by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hassams/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hassams">@hassams</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4730035488" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/6463" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/6463/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/6463">#6463</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/hassams/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/hassams">@hassams</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4730035488" data-permission-text="Title is private" data-url="https://github.com/hoppscotch/hoppscotch/issues/6463" data-hovercard-type="pull_request" data-hovercard-url="/hoppscotch/hoppscotch/pull/6463/hovercard" href="https://github.com/hoppscotch/hoppscotch/pull/6463">#6463</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/hoppscotch/hoppscotch/compare/2026.6.0...2026.6.1"><tt>2026.6.0...2026.6.1</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-48105 | Bytecode Alliance wasm-micro-runtime 1.2.3 wasm_loader.c wasm_loader_prepare_bytecode heap-based overflow (Issue 2726 / EUVD-2023-52186)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Bytecode Alliance wasm-micro-runtime 1.2.3. The affected element is the function wasm_loader_prepare_bytecode of the file core/iwasm/interpreter/wasm_loader.c. Such manipulation leads to heap-based buffer overflow.

This vulnerability is uniqu...]]></description>
<link>https://tsecurity.de/de/3659143/sicherheitsluecken/cve-2023-48105-bytecode-alliance-wasm-micro-runtime-123-wasmloaderc-wasmloaderpreparebytecode-heap-based-overflow-issue-2726-euvd-2023-52186/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659143/sicherheitsluecken/cve-2023-48105-bytecode-alliance-wasm-micro-runtime-123-wasmloaderc-wasmloaderpreparebytecode-heap-based-overflow-issue-2726-euvd-2023-52186/</guid>
<pubDate>Fri, 10 Jul 2026 10:54:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/bytecode_alliance:wasm-micro-runtime">Bytecode Alliance wasm-micro-runtime 1.2.3</a>. The affected element is the function <code>wasm_loader_prepare_bytecode</code> of the file <em>core/iwasm/interpreter/wasm_loader.c</em>. Such manipulation leads to heap-based buffer overflow.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2023-48105">CVE-2023-48105</a>. The attack can be launched remotely. No exploit exists.

Applying a patch is advised to resolve this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kotlin improves compile-time constants]]></title>
<description><![CDATA[Kotlin 2.4.0, an update to JetBrains’s statically typed language for building JVM, native, Wasm, and web applications, introduces experimental improvements to compile-time constants, making support for numeric and string types more consistent and easier to use, JetBrains said. 



Kotlin 2.4.0 wa...]]></description>
<link>https://tsecurity.de/de/3635034/ai-nachrichten/kotlin-improves-compile-time-constants/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635034/ai-nachrichten/kotlin-improves-compile-time-constants/</guid>
<pubDate>Tue, 30 Jun 2026 11:18:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Kotlin 2.4.0, an update to JetBrains’s statically typed language for building JVM, native, Wasm, and web applications, introduces experimental improvements to compile-time constants, making support for numeric and string types more consistent and easier to use, JetBrains said. </p>



<p>Kotlin 2.4.0 was released <a href="https://blog.jetbrains.com/kotlin/2026/06/kotlin-2-4-0-released/">June 3</a>. Its experimental improvements to compile-time constants include support for unsigned type operations; standard library functions for strings, such as the <code>.lowercase()</code>, <code>.uppercase()</code>, and <code>.trim()</code> functions, and evaluation of the <code>.name</code> property of <a href="https://kotlinlang.org/docs/enum-classes.html?_gl=1%2Afehijk%2A_gcl_au%2AMTU3MDQ4ODM0NC4xNzgyNTgwMDg4LjEwMzg2MDE2MzkuMTc4Mjc0OTgwNC4xNzgyNzQ5ODA0%2AFPAU%2AMTc4NTM0NDYwNC4xNzgyNTA0Mzkw%2A_ga%2AMTM5MjU2NDU3OS4xNzgyNTgwMDg4%2A_ga_9J976DJZ68%2AczE3ODI3NDgzODQkbzMkZzEkdDE3ODI3NTEyMTIkajU5JGwwJGgw&amp;_cl=MTsxOzE7aVFoRlVMeXhISDhwV2l2d3lVNmhTMDdKMGdPQzVoMnZBcHI2bWpERjNhRkY5eGpWSWY0bjRNVEJwYzNmdnR1aTs%3D#working-with-enum-constants">enum constants</a> and the <a href="https://kotlinlang.org/api/core/kotlin-stdlib/kotlin.reflect/-k-callable/"><code>KCallable</code> interface</a>. To make it clear which functions are evaluated at compile time, Kotlin 2.4.0 introduces the <code>IntrinsicConstEvaluation</code><strong> </strong>annotation. </p>



<p>JetBrains warned that some functions are evaluated at compile time but do not have the annotation yet. Later releases will add the annotation to the remaining functions.</p>



<p>Also in Kotlin 2.4.0:</p>



<ul class="wp-block-list">
<li>Kotlin 2.4.0 improves export to <a href="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html">JavaScript</a> and <a href="https://www.infoworld.com/article/2257305/what-is-typescript-strongly-typed-javascript.html">TypeScript,</a> including support for exporting value classes, interfaces, and type variance, as well as ES2015 features when inlining JavaScript code.</li>



<li>The Kotlin compiler can generate classes containing <a href="https://www.infoworld.com/article/4168040/whats-new-and-exciting-in-jdk-26.html">Java 26</a> bytecode.</li>



<li>Experimental support is highlighted for the <a href="https://component-model.bytecodealliance.org/">WebAssembly Component Model</a>. The proposal defines a way to build components from Wasm modules through standardized interfaces and types. This approach helps Wasm evolve from a low-level binary instruction format into a system for composing reusable, language-agnostic components.</li>



<li>Kotlin 2.4.0 has been included in the <a href="https://www.jetbrains.com/idea/download/?_cl=MTsxOzE7RVVQYngzTmMwUzNLNmkzTllYbXBVM20xRnFMcG5rdmE5SkxUYmk0emIycXh6Vjg1NThFa2dlZUlNVkdKeGRFZTs%3D&amp;section=mac">IntelliJ IDEA</a> and <a href="https://developer.android.com/studio">Android Studio</a> IDEs. </li>
</ul>



<p>An update to Kotlin 2.4.0 will arrive soon. Beta1 of <a href="https://kotlinlang.org/docs/whatsnew-eap.html">Kotlin 2.4.20</a> was released on June 24, adding the <code>StackTraceRecoverable</code> interface to the standard library. This interface improves integration with the <code>kotlinx.coroutines</code> library because it lets users define how to create exception instances for stack trace recovery without adding a dependency on<code>kotlinx.coroutines</code>, according to JetBrains. </p>



<p>A build tools API in the Kotlin 2.4.20 beta adds support for the Kotlin/JS, Kotlin/Wasm, and Kotlin metadata targets.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anyone can tell me that how a wasm file generates x-signature by app_version, timestamp, session_id,request-id]]></title>
<description><![CDATA[Hey I am a software engineer, working as an reverse engineer but today I found a wasm file on its and it is Swiggy and this one has a x-signature in headers which is generated by passing parameters to getMediaURL function of wasm file but but I am not getting exact x-signature as per my static pa...]]></description>
<link>https://tsecurity.de/de/3623258/malware-trojaner-viren/anyone-can-tell-me-that-how-a-wasm-file-generates-x-signature-by-appversion-timestamp-sessionidrequest-id/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623258/malware-trojaner-viren/anyone-can-tell-me-that-how-a-wasm-file-generates-x-signature-by-appversion-timestamp-sessionidrequest-id/</guid>
<pubDate>Thu, 25 Jun 2026 05:03:05 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey I am a software engineer, working as an reverse engineer but today I found a wasm file on its and it is Swiggy and this one has a x-signature in headers which is generated by passing parameters to getMediaURL function of wasm file but but I am not getting exact x-signature as per my static parameters so anyone tell me that how to deal with this wasm file and also there are lots of obscure code in website have multiple bundles of javascript loaded and it's too hard to understand the code of it. </p> <p>If anyone knows it then please help me that how to solve that and also how to get that x-signature</p> <p>If required I can give all the parameters and wasm file to the chat and if possible then can we get real secret key of this wasm file also to generate Hmac256 ?</p> <p>DM are open to you all </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Sweaty-Medicine3176"> /u/Sweaty-Medicine3176 </a> <br> <span><a href="https://www.reddit.com/r/ExploitDev/comments/1udj2ya/anyone_can_tell_me_that_how_a_wasm_file_generates/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ExploitDev/comments/1udj2ya/anyone_can_tell_me_that_how_a_wasm_file_generates/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Write cleaner and faster Python code]]></title>
<description><![CDATA[Meta’s long-awaited Pyrefly linter is out in a 1.0 version, and the forthcoming Python 3.15 has a super-efficient sampling profiler. Plus we have a comprehensive rundown of Python’s indispensable virtual environments — and a warning about a novel breed of malware that exploits Python’s package ec...]]></description>
<link>https://tsecurity.de/de/3609845/ai-nachrichten/write-cleaner-and-faster-python-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609845/ai-nachrichten/write-cleaner-and-faster-python-code/</guid>
<pubDate>Fri, 19 Jun 2026 11:18:47 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Meta’s long-awaited Pyrefly linter is out in a 1.0 version, and the forthcoming <a href="https://www.infoworld.com/article/4166693/the-best-new-features-in-python-3-15.html" data-type="link" data-id="https://www.infoworld.com/article/4166693/the-best-new-features-in-python-3-15.html">Python 3.15</a> has a super-efficient sampling profiler. Plus we have a comprehensive rundown of Python’s indispensable virtual environments — and a warning about a novel breed of malware that exploits Python’s package ecosystem.</p>



<h2 class="wp-block-heading">Top picks for Python readers on InfoWorld</h2>



<p><a href="https://www.infoworld.com/article/2260103/how-to-use-virtual-environments-in-python.html" data-type="link" data-id="https://www.infoworld.com/article/2260103/how-to-use-virtual-environments-in-python.html">How to use virtual environments in Python</a><br>Isolate and protect your Python projects from each other, and empower them to do more, with virtual environments and their native-to-Python tooling.</p>



<p><a href="https://www.infoworld.com/article/4179383/pyrefly-1-0-a-fast-forward-looking-python-linter.html" data-type="link" data-id="https://www.infoworld.com/article/4179383/pyrefly-1-0-a-fast-forward-looking-python-linter.html">Pyrefly 1.0: A fast, forward-looking Python linter</a><br>The first full release of Meta’s long-awaited linting and type checking tool for Python delivers speed and offers advanced features for type-checking PyTorch and Django projects.</p>



<p><a href="https://www.infoworld.com/video/4085906/hands-on-with-the-new-sampling-profiler-in-python-3-15.html" data-type="link" data-id="https://www.infoworld.com/video/4085906/hands-on-with-the-new-sampling-profiler-in-python-3-15.html">Hands-on with the new sampling profiler in Python 3.15</a><br>Among Python 3.15’s best new features is a sampling profiler, for instrumenting your code and finding its bottlenecks with a minimum of performance impact or fuss. See up-close how it works.</p>



<p><a href="https://www.infoworld.com/article/4182692/meet-hades-the-malware-that-lies-to-ai-security-agents.html" data-type="link" data-id="https://www.infoworld.com/article/4182692/meet-hades-the-malware-that-lies-to-ai-security-agents.html">All about Hades, the supply-chain malware that hides in Python packages</a><br>It hides in Python packages. It replicates itself across systems. It fools LLM-based code analysis tools into ignoring it. And there may be a lot more like it to come.</p>



<h2 class="wp-block-heading">More good reads and Python updates elsewhere</h2>



<p><a href="https://discuss.python.org/t/an-announcement-from-the-steering-council-regarding-the-jit-project/107638" data-type="link" data-id="https://discuss.python.org/t/an-announcement-from-the-steering-council-regarding-the-jit-project/107638">Python Steering Council calls for temporary pause on JIT project</a><br>The requested pause stays in place until a proper Standards Track PEP lands for the experimental JIT (just-in-time) compiler, the better to describe how the JIT will be a formal and supported part of Python.</p>



<p><a href="https://blog.pyodide.org/posts/314-release" data-type="link" data-id="https://blog.pyodide.org/posts/314-release">Pyodide 314.0: Pyodide packages on PyPI</a><br>Thanks to PEP 783, Python packages built with Pyodide (Python ported to WebAssembly) can be installed straight from PyPI instead of through Pyodide — another step closer to Py-on-Wasm becoming an everyday thing.</p>



<p><a href="https://theconsensus.dev/p/2026/06/06/python-3-14-garbage-collection-rigamarole.html" data-type="link" data-id="https://theconsensus.dev/p/2026/06/06/python-3-14-garbage-collection-rigamarole.html">All about that Python 3.14 garbage collection rigmarole</a><br>A new garbage collector introduced in Python 3.14 was yanked at the last minute due to reports of higher memory usage. Here’s a deep dive into what changed for the worse and why.</p>



<p><a href="https://pyrefly.org/blog/too-many-type-checkers" data-type="link" data-id="https://pyrefly.org/blog/too-many-type-checkers">Are you really expected to run five type checkers now?</a><br>No, but you should keep your options open. This blog post from a Pyrefly contributor recommends choosing one of the major offerings (Mypy, Pyrefly, Pyright, ty, Zuban, etc.), but also getting to know the others too. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 656]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3606667/tools/this-week-in-rust-this-week-in-rust-656/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3606667/tools/this-week-in-rust-this-week-in-rust-656/</guid>
<pubDate>Thu, 18 Jun 2026 07:08:48 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>

<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://arxiv.org/abs/2606.15991">cuTile Rust - Fearless Concurrency on the GPU, memory-safe, data-race-free GPU kernels, B200 benchmarks</a></li>
<li><a href="https://www.iroh.computer/blog/v1">Iroh 1.0 - Dial Keys, not IPs</a></li>
<li><a href="https://manishearth.github.io/blog/2026/06/14/diplomat-multi-language-ffi-for-rust-libraries/">Diplomat - Multi-language FFI for Rust libraries</a></li>
<li><a href="https://sergey-melnychuk.github.io/2026/05/23/yevm/">I built EVM from scratch. Again.</a></li>
<li><a href="https://zelanton.github.io/processkit/">processkit 1.0 - async process tree management</a></li>
<li><a href="https://github.com/obazin/litchee/releases/tag/v0.1.0">litchee: Rust Lichess API client</a></li>
<li><a href="https://jolars.co/blog/2026-06-10-basin/">Basin - Numerical Optimization in Rust</a></li>
<li><a href="https://github.com/carboxyl-rs/carboxyl/releases/tag/v0.1.0-servo-rc.1">Carboxyl 0.1.0-rc - A servo-based browser for the terminal</a></li>
<li><a href="https://github.com/kunobi-ninja/kache/releases/tag/v0.6.0">kache 0.6.0 - a shareable Rust + C/C++ build cache</a></li>
<li><a href="https://github.com/GianIac/numax/releases/tag/v0.1.0">numax v0.1.0 - first stable release of the numax distributed WASM runtime</a></li>
<li><a href="https://dev.to/etoile_bleu/-i-built-a-sync-engine-for-clinics-that-run-on-2g-and-lose-power-mid-transfer-here-is-why-and-18od">ZamSync - offline-first Rust sync engine</a></li>
<li><a href="https://dev.to/phpcraftdream/ktav-i-got-fed-up-with-every-config-format-so-i-built-one-with-no-quotes-no-commas-no-54an">Ktav - a quote-free config format</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://trifectatech.org/blog/zlib-rs-in-firefox/">zlib-rs in Firefox</a></li>
<li><a href="https://corrode.dev/blog/rust-prevents-data-races-not-race-conditions/">Rust Prevents Data Races, Not Race Conditions</a></li>
<li><a href="https://fnordig.de/2026/06/16/build-your-project-zig-style/">Build your project Zig-style</a></li>
<li><a href="https://kobzol.github.io/rust/2026/06/15/how-memory-safety-cves-differ-between-rust-and-c-cpp.html">How memory safety CVEs differ between Rust and C/C++</a></li>
<li><a href="https://kerkour.com/stdx-cratesio">Why stdx is not on crates.io</a></li>
<li>[videos] <a href="https://www.youtube.com/watch?v=PrfMpCaIh0k&amp;list=PL8Q1w7Ff68DBpmF38rcIAf8Z9Gj2TnlgM">RustWeek 2026 by RustNL, all talks playlist</a></li>
<li><a href="https://www.p2claw.com/blog/2026-06-09-the-ipad-was-on-tailscale/">The iPad was on Tailscale</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://blog.sheerluck.dev/posts/learn-rust-concurrency-by-building-a-thread-pool/">Learn Rust Concurrency By Building a Thread Pool</a></li>
<li><a href="https://grack.com/blog/2026/06/11/life-before-main/">There Is Life Before Main in Rust</a></li>
<li><a href="https://wolfgirl.dev/blog/2026-06-16-async-task-locals-from-scratch/">Async Task Locals From Scratch</a></li>
<li><a href="https://dystroy.org/blog/picomobile/">Fearless Embedded Rust: Driving a Lego Car with a Pico W</a></li>
<li><a href="https://smista.ai/blog/how-we-built-a-provider-agnostic-llm-layer-in-rust-with-rig">Building a provider-agnostic LLM layer in Rust with Rig</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#miscellaneous">Miscellaneous</a></h5>
<ul>
<li>[video] <a href="https://2026.rustweek.org/blog/2026-06-10-rustweek-recordings-published/">RustWeek 2026 talk recordings</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/ArneCode/marser">marser</a>, a parser combinator library with a twist.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1611">Arne Code</a> for the self-suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>


<ul>
<li><a href="https://github.com/satyakwok/solana-infra-doctor/issues/77">solana-infra-doctor - List exit codes in <code>sol-doctor --help</code></a></li>
<li><a href="https://github.com/satyakwok/solana-infra-doctor/issues/78">solana-infra-doctor - Make the invalid-URL error suggest the expected scheme</a></li>
<li><a href="https://github.com/satyakwok/solana-infra-doctor/issues/79">solana-infra-doctor - Add a glossary of RPC readiness terms</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/38">openslate - add unit tests for slugify() in api/src/notes.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/70">openslate - add integration tests for notes CRUD in api/src/notes.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/96">openslate - add integration tests for auth flow in api/src/users.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/89">openslate - add unit tests for build_fts_query() in api/src/search.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/106">openslate - add integration tests for auth middleware and logout in api/src/auth.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/85">openslate - add integration tests for media endpoints (DB layer) in api/src/media.rs</a></li>
<li><a href="https://github.com/MrSheerluck/openslate/issues/40">openslate - add unit tests for ext_from_mime() and filename_from_url() in api/src/media.rs</a></li>
</ul>


<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>527 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-06-09..2026-06-16">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156187"><code>obligations_for_self_ty</code>: skip irrelevant goals (recompute <code>sub_root</code> from <code>stalled_vars)</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157768"><code>codegen_ssa</code>: peel trans. wrappers on scalable vecs</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156934">add a check for impossible predicates to <code>trivial_const</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156816">add unstable loop unrolling hint attributes</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157714">improve polymorphization of raw pointer formatting</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155200">introduce <code>#[diagnostic::on_type_error(message)]</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157781">perf: reuse green-marking's edge walk when promoting a node</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/157355">add <code>or_try_*</code> variants for <code>HashMap</code> and <code>BTreeMap</code> Entry APIs</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/149749">make <code>BorrowedBuf</code> and <code>BorrowedCursor</code> generic over the data</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155527">replace printables table with <code>unicode_data.rs</code> tables</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157876">stabilize <code>#![feature(box_as_ptr)]</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156629">stabilize <code>core::range::{legacy, RangeFull, RangeTo}</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152544">stabilize <code>int_format_into</code> feature</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157877">stabilize <code>nonzero_from_str_radix</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157029">stabilize feature <code>float_algebraic</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17104"><code>trim-paths</code>: emit <code>CARGO_TRIM_PATHS_REMAP</code> for build.rs</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17101"><code>diag</code>: Give diagnostics the same display path behavior as rustc</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17095"><code>diag</code>: Report all errors, in order</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17071"><code>publish</code>: avoid false deadlock when <code>to_confirm</code> is non-empty</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17083"><code>resolver</code>: move yank policy to resolver layer</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/141000">also run lint <code>unused_doc_comments</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157874">cleanup and (micro-)optimize <code>print_where_clause</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157740">correct doctest span for trailing semicolon after item</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157838">don't strip hidden items in <code>AliasedNonLocalStripper</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/157796">some more lazy formatting</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustfmt">Rustfmt</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rustfmt/pull/6616">add <code>doc_comment_code_block_small_heuristics</code>, to override <code>use_small_heuristics</code> in doc code</a></li>
<li><a href="https://github.com/rust-lang/rustfmt/pull/6935">stabilize <code>hex_literal_case</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17042">new <code>by_ref_peekable_peek</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17192">add <code>with_capacity_zero</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17191"><code>mem_replace_with_default</code>: also emit inside macros</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17175"><code>infallible_destructuring_match</code>: clean-up, split off the suggestion from the main message</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17184"><code>manual_is_variant_and</code>: lint <code>result.ok().is_some_and(f)</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17171"><code>needless_borrow</code>: same-name methods false positive</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17216"><code>unnecessary_lazy_evaluations</code>: handle closure <code>-&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17208">deprecate the <code>from_iter_instead_of_collect</code> lint</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17204">remove <code>is_integer_const</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17250">do not trigger <code>ref_patterns</code> lint on automatically derived code</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17145">enhance never loop</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/15779">add profile-specific configuration for disallowed methods and types</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16749">fix <code>collapsible_match</code> suggests wrongly when match body has no braces</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16868">fix <code>unnecessary_sort_by</code> reverse suggestion using wrong closure parameter name</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17107">fix redundant closure call async false positive</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17218">perf: check <code>is_in_test</code> last in <code>incompatible_msrv</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17219">perf: check the token kind before extracting source in early literal lints</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17220">perf: match expression shape before MSRV check in <code>cloned_ref_to_slice_refs</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17217">perf: skip <code>doc_markdown</code> text collection and word scan when the lint is allowed</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17225">perf: skip <code>single_component_path_imports</code> module walk when nothing to lint</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22562">create directory for <code>cargo xtask metrics rustc_tests</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22575">don't count C-variadic <code>...</code> as a parameter for fn pointers</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22549">support flyimport exclude variants</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22566">fix destructuring assignments not introducing moves</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22584">offer inline macro in macro call and proc macro</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22591">prefer bench command when target is bench to avoid cargo run</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22551">supports inline variable in macro</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22574">use package id as argument to <code>--package</code> if package is not unique</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22545">assist <code>inline_type_alias</code> work on ADT definitions</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22579">perf: defer initial workspace flycheck until cache priming completes</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22561">remove docs about removed <code>analysis-bench</code> command</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22571">remove unnecessary feature flags from tests</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22585">use ASCII lowercase for dylib extensions check</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week we had quite a lot of changes, a few small regressions that were a bit tough to diagnose, but the week is largely positive, overall.
Notably, we got one massive improvement on the next-solver benchmark in #<a href="https://github.com/rust-lang/rust/pull/156187">156187</a>,
and a nice speedup for incremental in <a href="https://github.com/rust-lang/rust/pull/157781">#157781</a>.</p>
<p>Triage done by <strong>@panstromek</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=f3ef3bd882dd24a275a60701a67c3bb330edd8c1&amp;end=b5d46ecb51c3e4134b82570cfe718f093daa6390&amp;absolute=false&amp;stat=instructions%3Au">f3ef3bd8..b5d46ecb</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.4%</td>
<td>[0.2%, 0.6%]</td>
<td>22</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>0.5%</td>
<td>[0.1%, 2.0%]</td>
<td>40</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-1.8%</td>
<td>[-5.9%, -0.1%]</td>
<td>125</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-3.8%</td>
<td>[-69.4%, -0.1%]</td>
<td>90</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-1.5%</td>
<td>[-5.9%, 0.6%]</td>
<td>147</td>
</tr>
</tbody>
</table>
<p>1 Regression, 4 Improvements, 8 Mixed; 5 of them in rollups
28 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/d36b1ad8679b65efbb98252fbb93f72a7d90d4c6/triage/2026/2026-06-16.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><em>No RFCs were approved this week.</em></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156047">Fix trait method resolution on an adjusted never type</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/76314">Tracking Issue for atomic_from_mut</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155499">stabilize never type</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/153563">Lint against iterator functions that panic when N is zero</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1002">Single-byte counter support in coverage instrumentation</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/1003">Rename the compiler files containing struct diagnostics to <code>diagnostics.rs</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#leadership-council"></a><a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>
<ul>
<li><a href="https://github.com/rust-lang/leadership-council/issues/301">Delegate Project Grants to the Funding team</a></li>
<li><a href="https://github.com/rust-lang/leadership-council/issues/304">Allocate budget to the Funding team</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-rfcs"></a><a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3955">Named Fn trait parameters</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#language-reference"></a><a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>
<ul>
<li><a href="https://github.com/rust-lang/reference/pull/2262">Structs with no fields or all-ZST fields are ZSTs</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><em>No New or Updated RFCs were created this week.</em></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-06-17 - 2026-07-15 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-06-17 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314000478/"><strong>Rust Study/Hack/Hang-out</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ekws5nr4"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314236370/"><strong>June, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455931/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-06-21 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329044/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254779/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/313767883/"><strong>Lunch &amp; Learn: What the heck are monads - and how do we fake them in Rust</strong></a></li>
</ul>
</li>
<li>2026-07-01 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/315210366/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455932/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Charlottesville, VA, US) | <a href="https://www.meetup.com/charlottesville-rust-meetup/events/">Charlottesville Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/charlottesville-rust-meetup/events/315211402/"><strong>Learning Game Development the Hard Way with Rust and Bevy</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris/events/">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345243/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-07-05 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095287/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-07-07 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust/events/">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/315060981/"><strong>👋 Community Catch Up</strong></a></li>
</ul>
</li>
<li>2026-07-14 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254778/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-07-15 | Virtual (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust/events/">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314233743/"><strong>Jiff</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-06-18 | Aarhus, DK | <a href="https://www.meetup.com/rust-aarhus">Rust Aarhus</a><ul>
<li><a href="https://www.meetup.com/rust-aarhus/events/314965238/"><strong>Talk Night at Danske Commodities</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Edinburgh, GB | <a href="https://www.meetup.com/rust-edi/events/">Rust and Friends</a><ul>
<li><a href="https://www.meetup.com/rust-and-friends/events/315093492/"><strong>Rust and Friends comes to Glasgow! (daytime coffee)</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Edinburgh, GB | <a href="https://www.meetup.com/rust-edi/events/">Rust and Friends</a><ul>
<li><a href="https://www.meetup.com/rust-and-friends/events/315093500/"><strong>Rust and Friends comes to Glasgow! (evening pub)</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Barcelona, ES | <a href="https://www.meetup.com/bcnrust/events/">BcnRust</a><ul>
<li><a href="https://www.meetup.com/bcnrust/events/315094938/"><strong>21st BcnRust Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-19 | Dresden, DE | <a href="https://github.com/rust-dresden">Rust Dresden</a><ul>
<li><a href="https://pretix.eu/rust-dresden/on-location-2"><strong>Second Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Paris, FR | <a href="https://www.meetup.com/rust-paris">Rust Paris</a><ul>
<li><a href="https://www.meetup.com/rust-paris/events/315040676/"><strong>Rust meetup #86</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Warsaw, PL | <a href="https://luma.com/rust.in.warsaw">Rust Warsaw</a><ul>
<li><a href="https://luma.com/djs7ntfx"><strong>Rust Warsaw Meetup: June 2026</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Manchester, GB | <a href="https://www.meetup.com/rust-manchester/events/">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/315200163/"><strong>Rust Manchester June Talks</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/314396600/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Copenhagen, DK | <a href="https://www.meetup.com/copenhagen-rust-community/events/">Copenhagen Rust Community</a><ul>
<li><a href="https://www.meetup.com/copenhagen-rust-community/events/315214426/"><strong>Rust meetup #69</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Edinburgh, GB | <a href="https://www.meetup.com/rust-edi/events/">Rust and Friends</a><ul>
<li><a href="https://www.meetup.com/rust-and-friends/events/314941098/"><strong>Bevy, Bits, &amp; Cats (Rust July Talks)</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Enschede, OV, NL | <a href="https://www.meetup.com/dutch-rust-meetup/events/">Baseflow Tech Meetups</a><ul>
<li><a href="https://www.meetup.com/baseflow-tech-meetups/events/315099547/"><strong>AI Summit</strong></a></li>
</ul>
</li>
<li>2026-07-08 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin/events/">Rust Dublin</a><ul>
<li><a href="https://www.meetup.com/rust-dublin/events/315150327/"><strong>Join us live and INPERSON for Rust 261</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-06-17 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314000478/"><strong>Rust Study/Hack/Hang-out</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314236370/"><strong>June, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Nashville, TN, US | <a href="https://www.meetup.com/music-city-rust-developers/events/">Music City Rust Developers</a><ul>
<li><a href="https://www.meetup.com/music-city-rust-developers/events/315213927/"><strong>Community Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-20 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225854/"><strong>Northeastern Rust Lunch, June 20</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx/events/">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/315105633/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/314386080/"><strong>Rust LA: Rust-Based Constraint Solvers in 2D Sketching with Zoo Technologies</strong></a></li>
</ul>
</li>
<li>2026-06-25 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539326/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-06-26 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/315014582/"><strong>Rust NYC's Big Summer Social</strong></a></li>
</ul>
</li>
<li>2026-06-27 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225857/"><strong>Somerville Union Square Rust Lunch, June 27</strong></a></li>
</ul>
</li>
<li>2026-07-02 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust/events/">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/315103359/"><strong>Git is easy?</strong></a></li>
</ul>
</li>
<li>2026-07-04 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225861/"><strong>Boston University Rust Lunch, July 4</strong></a></li>
</ul>
</li>
<li>2026-07-09 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust/events/">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696647/"><strong>Utah Rust July Meetup</strong></a></li>
</ul>
</li>
<li>2026-07-11 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/315225865/"><strong>MIT Rust Lunch, July 11</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-06-25 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/315039461/"><strong>Rust Melbourne June 2026</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-06-18 | Florianópolis, BR | <a href="https://luma.com/rust-sc">Rust SC</a><ul>
<li><a href="https://luma.com/acinctdf"><strong>Rust Floripa</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1ttbtf5/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>"The never type is named after the date of its stabilization" was a good joke while it lasted.</p>
</blockquote>
<p>– <a href="https://www.reddit.com/r/rust/comments/1u1v53c/the_never_type_is_likely_to_stabilize_soon/oqss8ii/">Sergey "Shnatsel" Davidoff on /r/rust</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1780">Dos Moonen</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://this-week-in-rust.org/REDDIT_LINK_HERE">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v16.0.2]]></title>
<description><![CDATA[@oh-my-pi/pi-ai
Added

Added UMANS_WEBSEARCH_PROVIDER=native|exa support for routing Umans gateway-owned web search requests.

Fixed

A single MCP tool whose input schema can't be emitted as a valid strict tool schema for the active provider no longer fails the whole turn with HTTP 400. convertTo...]]></description>
<link>https://tsecurity.de/de/3602045/tools/v1602/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3602045/tools/v1602/</guid>
<pubDate>Tue, 16 Jun 2026 15:54:19 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>@oh-my-pi/pi-ai</h2>
<h3>Added</h3>
<ul>
<li>Added <code>UMANS_WEBSEARCH_PROVIDER=native|exa</code> support for routing Umans gateway-owned web search requests.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>A single MCP tool whose input schema can't be emitted as a valid strict tool schema for the active provider no longer fails the whole turn with HTTP 400. <code>convertTools</code> (openai-responses) now validates each tool's emitted parameter schema for <code>enum</code>/<code>const</code>-vs-<code>type</code> contradictions that pass structural JSON-Schema validation but the provider rejects — e.g. a non-null <code>enum</code> on a <code>type: "null"</code> node, or an <code>enum</code> on an <code>array</code> node — and quarantines just the offending tool with a <code>logger.warn</code> naming the tool and schema path, keeping every other tool usable. Adds <code>findStrictToolSchemaViolation</code> to <code>@oh-my-pi/pi-ai/utils/schema</code> (<a href="https://github.com/can1357/oh-my-pi/issues/2652" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2652/hovercard">#2652</a>)</li>
<li>Fixed OpenAI Responses-compatible streams from Ollama/local hosts dropping arguments for parallel tool calls whose deltas use <code>fc_&lt;call_id&gt;</code> item ids, which left earlier <code>ast_grep</code> calls with <code>{}</code> and failed validation. (<a href="https://github.com/can1357/oh-my-pi/issues/2715" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2715/hovercard">#2715</a>)</li>
<li>Fixed dialect transcript rendering so literal thinking envelopes are unwrapped before adding the dialect's own thinking tags, preventing nested <code>&lt;thinking&gt;</code> output in advisor raw dumps (<a href="https://github.com/can1357/oh-my-pi/issues/2700" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2700/hovercard">#2700</a>).</li>
<li>Fixed Anthropic-compatible Umans requests escaping client tool names and forwarding gateway web search headers so Kimi answers normally instead of returning raw gateway search results.</li>
<li>Fixed Google Gemini tool calls with <code>toolChoice: "auto"</code> serializing an explicit <code>toolConfig</code> AUTO mode, which can cause Gemini-3 models to leak raw planning JSON instead of executing tools. (<a href="https://github.com/can1357/oh-my-pi/issues/2776" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2776/hovercard">#2776</a>)</li>
<li>Fixed OpenAI-compatible Ollama completions that return empty <code>finish_reason:length</code> after filling <code>num_ctx</code> so they surface an actionable context-window error instead of an empty length stop. (<a href="https://github.com/can1357/oh-my-pi/issues/2774" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2774/hovercard">#2774</a>)</li>
<li>Fixed Codex browser login issuing credentials for the <code>opencode</code> OAuth originator while OMP requests identify as <code>pi</code>, which could make the first authenticated Codex request return 401 (<a href="https://github.com/can1357/oh-my-pi/issues/2696" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2696/hovercard">#2696</a>).</li>
</ul>
<h2>@oh-my-pi/pi-catalog</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed Kimi output caps for Umans AI Coding Plan and Venice so discovery metadata cannot use context-sized token ceilings as request caps.</li>
<li>Marked Umans Anthropic-compatible models as client-tool escaped so cached and bundled metadata do not expose <code>web_search</code> as a provider server tool.</li>
</ul>
<h2>@oh-my-pi/pi-coding-agent</h2>
<h3>Added</h3>
<ul>
<li>Added the <code>UMANS_WEBSEARCH_PROVIDER</code> environment variable to CLI help for Umans gateway web search backend selection.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>The eager <code>task</code> (<code>task.eager: always</code>) and eager <code>todo</code> (<code>todo.eager: preferred</code>/<code>always</code>) hidden reminders now re-fire on the auto-continuation turn after a compaction (context-full / snapcompact / handoff / shake). Compaction summarizes away the first-message prelude, so the agent would otherwise silently lose the delegate-via-tasks / phased-todo guidance mid-work; the post-compaction todo nudge is reminder-only and never forces the <code>todo</code> tool onto the resumed turn.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed edit-tool block operations on Emacs Lisp files: <code>.el</code> and <code>.emacs</code> paths now resolve top-level forms for <code>SWAP.BLK</code>, <code>DEL.BLK</code>, and <code>INS.BLK.POST</code> instead of reporting an unsupported-language block-resolution error.</li>
<li>Fixed PDF reads leaking recoverable MuPDF WASM warnings into the terminal TUI by routing MuPDF output through the file logger before <code>markit-ai</code> loads it (<a href="https://github.com/can1357/oh-my-pi/issues/2766" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2766/hovercard">#2766</a>).</li>
<li>Fixed <code>/exit</code> and <code>/quit</code> waiting one shutdown timeout per hanging extension by running <code>session_shutdown</code> handlers within a shared shutdown window (<a href="https://github.com/can1357/oh-my-pi/issues/2736" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2736/hovercard">#2736</a>).</li>
<li>Fixed GitHub Copilot <code>.github/instructions/*.instructions.md</code> discovery by loading those files as rules that honor <code>applyTo</code> scoping, including always-apply <code>**</code> files and <code>rule://&lt;name&gt;</code> access for glob-scoped entries (<a href="https://github.com/can1357/oh-my-pi/issues/2731" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2731/hovercard">#2731</a>).</li>
<li>Fixed Windows bash-tool child processes defaulting interpreter pipe I/O to the ANSI codepage by adding UTF-8 encoding defaults when the inherited environment is unset (<a href="https://github.com/can1357/oh-my-pi/issues/2701" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2701/hovercard">#2701</a>).</li>
<li>Fixed <code>/advisor dump raw</code> so Opus 4.5 thinking content that already includes literal <code>&lt;thinking&gt;</code> tags is not rendered with nested thinking tags (<a href="https://github.com/can1357/oh-my-pi/issues/2700" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2700/hovercard">#2700</a>).</li>
<li>The <code>plugin-extensions-discovery</code> test suite no longer writes fixtures into — and <code>rm -rf</code>s the <code>node_modules</code> of — the developer's real <code>~/.omp/plugins</code>. Its <code>XDG_DATA_HOME</code> isolation was a no-op on Windows (XDG is gated to Linux/macOS) and was bypassed in XDG-migrated Linux/macOS environments, so a local run could delete installed plugins. The suite now isolates the whole config root via an <code>os.homedir()</code> mock plus cleared <code>XDG_*</code> vars, with a pre-write guard that fails if resolution escapes the temp home (<a href="https://github.com/can1357/oh-my-pi/issues/2721" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2721/hovercard">#2721</a>).</li>
<li>Installed plugins whose <code>extensions</code> manifest entry points at a directory of sub-extensions (the standard pi <code>extensions/&lt;name&gt;/index.ts</code> layout, e.g. <code>pi.extensions: ["./extensions"]</code>) are no longer rejected at install (<code>declared extension entry not found on disk</code>) or silently dropped at load. The plugin manifest resolver now resolves a directory the same way as the configured-directory (<code>-e</code>) extension loader: the directory's own <code>package.json</code> <code>omp</code>/<code>pi</code> <code>extensions</code> (authoritative — a missing declared entry is reported instead of falling back to a decoy <code>index</code>), then a direct <code>index.{ts,js,mjs,cjs}</code>, then a one-level scan of sub-extensions (<a href="https://github.com/can1357/oh-my-pi/issues/2713" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2713/hovercard">#2713</a>).</li>
<li>Fixed OpenRouter <code>@upstream</code> routing selectors whose upstream slug also appears in the model id, so <code>openrouter/...@deepseek:high</code> keeps <code>openRouterRouting.only</code> instead of being consumed by provider-scoped fuzzy matching (<a href="https://github.com/can1357/oh-my-pi/issues/2708" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2708/hovercard">#2708</a>).</li>
<li>Fixed <code>omp plugin list --json</code> omitting locally linked plugins that exist only in <code>omp-plugins.lock.json</code> and <code>node_modules</code> symlinks. (<a href="https://github.com/can1357/oh-my-pi/issues/2742" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2742/hovercard">#2742</a>)</li>
<li>Fixed task subagents to install their configured ordered model candidates as child-session retry fallback chains, so retryable provider failures can advance to the next subagent model instead of failing the worker (<a href="https://github.com/can1357/oh-my-pi/issues/2750" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2750/hovercard">#2750</a>).</li>
<li>Fixed empty reasonless aborted assistant turns to auto-retry without switching model fallback, so transient provider-side aborts after tool results do not end headless sessions (<a href="https://github.com/can1357/oh-my-pi/issues/2685" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2685/hovercard">#2685</a>).</li>
</ul>
<h2>@oh-my-pi/hashline</h2>
<h3>Fixed</h3>
<ul>
<li>Auto-repaired duplicated JSX/XML closing boundary lines at the end of single-line replacement expansions. (<a href="https://github.com/can1357/oh-my-pi/issues/2705" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2705/hovercard">#2705</a>)</li>
</ul>
<h2>@oh-my-pi/pi-natives</h2>
<h3>Added</h3>
<ul>
<li>Added Emacs Lisp (<code>.el</code>, <code>.emacs</code>, <code>emacs-lisp</code>/<code>elisp</code>) support to native tree-sitter language inference, enabling astGrep/astEdit, summarizeCode, and blockRangeAt on Emacs Lisp source.</li>
</ul>
<h2>@oh-my-pi/pi-tui</h2>
<h3>Fixed</h3>
<ul>
<li>Fixed VS Code integrated terminal keypad digit CSI-u input being handled as navigation instead of text.</li>
<li>Fixed xterm-compatible terminals scrolling the native viewport to the bottom on prompt-editor keypresses by disabling <code>?1010</code>/<code>?1011</code> while the TUI owns the TTY and restoring the prior set modes on exit (<a href="https://github.com/can1357/oh-my-pi/issues/2732" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2732/hovercard">#2732</a>).</li>
<li>Fixed CMUX sessions being treated as direct terminals during resize/reset because they do not set <code>TMUX</code>/<code>STY</code>/<code>ZELLIJ</code> and may run with <code>TERM=dumb</code>; the renderer now treats CMUX workspace/surface env markers as multiplexer signals and preserves pane scrollback instead of emitting ED3 (<code>CSI 3 J</code>).</li>
<li>Fixed a self-sustaining resize-redraw storm in Warp: the non-multiplexer resize fast path borrows the alternate screen, and Warp re-reports a one-row-different size whenever the alt buffer is toggled, so each drag frame fed back a fresh resize event and the TUI flooded ED3 full repaints with stable geometry. Resize now repaints in place (no alt-screen borrow, no ED3 rewrap) on terminals that re-report size on alt-screen toggles, matching the multiplexer path. Overridable with <code>PI_TUI_RESIZE_IN_PLACE=1|0</code>.</li>
</ul>
<h2>What's Changed</h2>
<ul>
<li>fix(ai): route prefixed Responses tool deltas by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669710676" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2719" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2719/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2719">#2719</a></li>
<li>test(plugins): isolate discovery test from real ~/.omp on all platforms by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AsafMah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AsafMah">@AsafMah</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669729057" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2722" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2722/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2722">#2722</a></li>
<li>fix(coding-agent): load GitHub Copilot instruction rules by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4670507607" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2734" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2734/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2734">#2734</a></li>
<li>fix(tui): stop Warp resize feedback-loop redraw storm by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sorphwer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sorphwer">@sorphwer</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671065904" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2741" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2741/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2741">#2741</a></li>
<li>fix(cli): speed up exit shutdown handlers by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671164530" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2745" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2745/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2745">#2745</a></li>
<li>fix(cli): list linked local plugins by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671230064" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2746" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2746/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2746">#2746</a></li>
<li>fix(providers): handle Umans Kimi output caps and web search by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/oldschoola/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/oldschoola">@oldschoola</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671571838" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2751" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2751/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2751">#2751</a></li>
<li>fix(agent): retry subagent model fallback chains by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671783707" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2753" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2753/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2753">#2753</a></li>
<li>fix(tui): detect CMUX as multiplexer by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pathard1128/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pathard1128">@pathard1128</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4672246682" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2755" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2755/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2755">#2755</a></li>
<li>fix(coding-agent): route MuPDF warnings to logger by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4673746131" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2772" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2772/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2772">#2772</a></li>
<li>fix(ai): omit Google AUTO toolConfig by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4674509706" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2782" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2782/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2782">#2782</a></li>
<li>feat(ast): add Emacs Lisp tree-sitter support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ryjm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ryjm">@ryjm</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4667318103" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2693" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2693/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2693">#2693</a></li>
<li>fix(ai): unwrap thinking envelopes in raw dumps by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4668789863" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2702" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2702/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2702">#2702</a></li>
<li>fix(tool): default Windows bash children to UTF-8 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4668993321" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2704" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2704/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2704">#2704</a></li>
<li>fix(hashline): drop duplicated JSX boundary echoes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669256053" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2709" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2709/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2709">#2709</a></li>
<li>fix(providers): preserve OpenRouter upstream routing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669299033" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2710" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2710/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2710">#2710</a></li>
<li>fix(openai-responses): quarantine invalid tool schemas instead of failing the whole turn (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4665238895" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2652" data-hovercard-type="issue" data-hovercard-url="/can1357/oh-my-pi/issues/2652/hovercard" href="https://github.com/can1357/oh-my-pi/issues/2652">#2652</a>) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AsafMah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AsafMah">@AsafMah</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669341536" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2711" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2711/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2711">#2711</a></li>
<li>fix(plugins): resolve directory extension manifest entries one level deep by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/AsafMah/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/AsafMah">@AsafMah</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4669526068" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2714" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2714/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2714">#2714</a></li>
<li>fix(tui): preserve scrollback while editing by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/roboomp/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/roboomp">@roboomp</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4670384480" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2733" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2733/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2733">#2733</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/sorphwer/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/sorphwer">@sorphwer</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4671065904" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2741" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2741/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2741">#2741</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/pathard1128/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/pathard1128">@pathard1128</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4672246682" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2755" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2755/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2755">#2755</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ryjm/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ryjm">@ryjm</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4667318103" data-permission-text="Title is private" data-url="https://github.com/can1357/oh-my-pi/issues/2693" data-hovercard-type="pull_request" data-hovercard-url="/can1357/oh-my-pi/pull/2693/hovercard" href="https://github.com/can1357/oh-my-pi/pull/2693">#2693</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://github.com/can1357/oh-my-pi/compare/v16.0.1...v16.0.2"><tt>v16.0.1...v16.0.2</tt></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Web Development Tools – 8 innovative Optionen]]></title>
<description><![CDATA[Neue Wege in Sachen Web Development beschreiten? Mit diesen acht Tools klappt das bestens.dotshock | shutterstock.com



In der Webentwicklung gibt es keinen vorgegebenen Weg. In einer Sache sind sich jedoch alle einig: Es ist höchste Zeit für ein „Great Unbloating“: Das Web Development muss von ...]]></description>
<link>https://tsecurity.de/de/3600602/it-security-nachrichten/web-development-tools-8-innovative-optionen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600602/it-security-nachrichten/web-development-tools-8-innovative-optionen/</guid>
<pubDate>Tue, 16 Jun 2026 06:05:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2024/08/0_dotshock_shutterstock_2312374465_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="App Developer Testing 16z9 SHUTTERSTOCK EDITORIAL GERMANY ONLY" class="wp-image-3497299" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Neue Wege in Sachen Web Development beschreiten? Mit diesen acht Tools klappt das bestens.</figcaption></figure><p class="imageCredit">dotshock | shutterstock.com</p></div>



<p>In der <a href="https://www.computerwoche.de/article/2802920/was-macht-ein-web-developer.html" target="_blank">Webentwicklung</a> gibt es keinen vorgegebenen Weg. In einer Sache sind sich jedoch alle einig: Es ist höchste Zeit für ein „Great Unbloating“: Das Web Development muss von schwerfälliger Komplexität befreit werden. Wie das funktionieren kann, zeigen die acht Tools, die wir Ihnen in diesem Beitrag vorstellen.</p>



<p>Diese zeichnet aus, dass sie sich (größtenteils) mit alternativen Ansätzen befassen, die das Bewährte in Frage stellen. Auch wenn Sie die hier vorgestellten Lösungen nicht direkt für Ihre Zwecke einsetzen können, lohnt es sich also dennoch, sie im Auge zu behalten.</p>



<h2 class="wp-block-heading">1. <a href="https://astro.build/" target="_blank" rel="noreferrer noopener">Astro</a></h2>



<p>Wenn man eine Gruppe klassischer Musiker mit Noten in einen Raum setzt und sie einfach spielen lässt, <em>könnte </em>das Ergebnis ein stimmiges Stück sein. Wahrscheinlich braucht es aber einen Dirigenten, der alles koordiniert. In Zusammenhang mit Frontend-Frameworks ist <a href="https://www.computerwoche.de/article/3834789/astro-tutorial-plug-play-webentwicklung.html" target="_blank">Astro</a> genau das – ein Maestro.</p>



<p>Astro kümmert sich um die „<a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html" target="_blank">Hydration</a>“ des Frontends, also den Prozess, die Shell reaktiv zu machen. Beim konventionellen Server-Side Rendering (SSR) sendet der Server nicht nur den HTML-Code, sondern auch die riesige Framework-Runtime über das Netzwerk – nur um der Seite Event-Listener hinzuzufügen. Mit Astro ist es möglich, Komponenten in React, Svelte, Vue oder Solid zu schreiben – der Compiler des Tools entfernt dabei das gesamte JavaScript, bevor es den Browser erreicht. Astro liefert standardmäßig Zero JS aus und verlässt sich auf seine „<a href="https://docs.astro.build/en/concepts/islands/" target="_blank" rel="noreferrer noopener">Island Architecture</a>“, um nur die spezifischen Komponenten zu hydrieren, die Interaktivität erfordern.</p>



<p>Da Astro die Interaktivität in separaten „Inseln“ isoliert, ist es im Vergleich zu einer monolithischen Single-Page-Anwendung grundsätzlich schwieriger, komplexe States (etwa eine komplexe Seitenleiste mit Filterfunktion, die mit einem separaten dynamischen Data Grid kommuniziert) zwischen diesen Inseln zu teilen. Wenn Sie eine hochgradig interaktive, Dashboard-lastige Applikation entwickeln, in der jede Komponente die andere beeinflusst, könnten sich die isolierten Inseln eher nach Zwangsjacke als nach Befreiung anfühlen.</p>



<p><strong>Auch interessant:</strong> <a href="https://www.computerwoche.de/article/2833386/die-besten-javascript-frameworks-im-vergleich.html" target="_blank">Qwik</a>. Während Astro verschlankt, indem es den JavaScript-Code vollständig entfernt, setzt Qwik auf Verzögerung: Es liefert sofort HTML und serialisiert den Anwendungsstatus. Dabei wird nur der für eine bestimmte Interaktion erforderliche JavaScript-Code genau in der Millisekunde heruntergeladen und ausgeführt, in der der User auf die entsprechende Schaltfläche klickt.</p>



<h2 class="wp-block-heading">2. <a href="https://biomejs.dev/" target="_blank" rel="noreferrer noopener">Biome</a></h2>



<p><a href="https://www.computerwoche.de/article/2816993/7-gruende-rust-zu-hassen-und-zu-lieben.html" target="_blank">Rust</a> ersetzt nach und nach die zugrundeliegende Infrastruktur im JavaScript-Ökosystem. Das verleiht dem Biome-Tool seine Hardware-ähnliche Geschwindigkeit. Das Alleinstellungsmerkmal dieses Dev-Werkzeugs ist es allerdings, die weitläufige Webentwicklungs-Toolchain zu vereinheitlichen.  </p>



<p>Wenn die <code>.eslintrc</code>– und <code>.prettierrc</code>-Dateien sowie die Dutzenden zugehörigen Plugins in Ihrem Projekt bereits zu einem dunklen, unzufriedenstellenden Sumpf verkommen sind, ist Biome der Ausweg: Das Tool besteht aus einer einzelnen Binary, die komplett verworrene Foramtierungs- und Linting-Ökosysteme substituiert – und damit einen Weg zu Codequalität eröffnet, der ganz ohne ein weit verzweigtes Netz von Abhängigkeiten auskommt. </p>



<p>Der wohl größte Nachteil von Biome ist dabei gleichzeitig auch das Feature, das das Tool so schlank macht: Die Erweiterbarkeit geht verloren.</p>



<p><strong>Auch interessant:</strong> <a href="https://rspack.rs/" target="_blank" rel="noreferrer noopener">Rspack</a>. Biome bereinigt das Linting, Rspack entschlackt den Build-Schritt. Auch dieses Tool basiert auf Rust für mehr Geschwindigkeit. Dabei nutzt es – etwa im Gegensatz zu Vite – den „bundled“ Dev-Modus.</p>



<h2 class="wp-block-heading">3. <a href="https://bun.com/" target="_blank" rel="noreferrer noopener">Bun</a></h2>



<p>Die meisten gut informierten JavaScript-Enthusiasten dürften längst mit Bun vertraut sein. Wenn Sie die faszinierende Kombination aus All-in-One-Lösung und atemberaubender Geschwindigkeit noch nicht selbst erlebt haben, wird es Zeit. </p>



<p>Wenn Sie an <a href="https://www.infoworld.com/article/2254485/what-is-nodejs-javascript-runtime-explained.html">Node</a> gewöhnt sind und Bun ausprobieren, werden Sie sehr wahrscheinlich sofort davon beeindruckt sein, wie schnell Befehle ausgeführt werden. Das Bun-Team hat zudem über mehrere Jahre hinweg umfangreiche Anstrengungen unternommen, um seine Engine eng an die APIs von Node anzupassen. Das macht Bun zu einer außergewöhnlichen technischen Errungenschaft, die jeder JavaScript-Entwickler zumindest explorieren sollte.</p>



<p>Obwohl Buns <a href="https://www.computerwoche.de/article/2821852/die-moderne-c-alternative.html" target="_blank">Zig</a>-basierte Engine in vielerlei Hinsicht ein direkter Ersatz für Node ist: Sie ist nicht perfekt – insbesondere angesichts der gigantischen Anzahl von Node-Packages, die existieren. Deshalb bleibt Node auch die beste bewährte, konservative, Engine für serverseitiges JavaScript.</p>



<p><strong>Auch interessant:</strong> <a href="https://www.infoworld.com/article/2256205/what-is-deno-a-better-nodejs.html">Deno</a>. Bun hat sich zwar zu Recht einen Ruf als innovatives Tool erarbeitet – allerdings wurde Deno still und leise um eine Reihe attraktiver Enterprise-Funktionen ergänzt – etwa eine integrierte Bereitstellungsplattform und das Frontend-Framework <a href="https://www.infoworld.com/article/3523813/intro-to-deno-fresh-a-fresh-take-on-full-stack-javascript.html" target="_blank">Deno Fresh</a>.</p>



<h2 class="wp-block-heading">4. <a href="https://htmx.org/" target="_blank" rel="noreferrer noopener">HTMX</a></h2>



<p>Wenn es um smarte Wege geht, das Web zu vereinfachen, könnte man <a href="https://www.computerwoche.de/article/2833138/dynamisches-html-ohne-javascript.html" target="_blank">HTMX</a> durchaus als Paradebeispiel anführen. Das Projekt greift die Kernmechanismen moderner Web-Clients wie <a href="https://developer.mozilla.org/en-US/docs/Glossary/AJAX" target="_blank" rel="noreferrer noopener">Ajax</a> sowie partielle Aktualisierungen auf und wandelt diese in einfache HTML-Attribute um. Das hat zur Folge, dass der State ausschließlich auf dem Server gespeichert wird, der dafür zuständig ist, die HTMX-Fragmente zu senden.</p>



<p>Natürlich läuft das nicht ohne Kompromisse ab. Einer ist die extreme Abhängigkeit vom Netzwerk: Da es keine Client-seitige State Machine gibt, ist der Browser ohne Verbindung zum Server hilflos. Es sei denn, Sie wagen sich an Experimente mit einem <a href="https://www.computerwoche.de/article/4142269/der-browser-wird-zur-datenbank.html" target="_blank">„local-first“-Data Store</a>. Kurz gesagt: Wenn Ihre App in den Anwendungsbereich von HTMX fällt, ist HTMX wahrscheinlich der direkteste „<a href="https://www.computerwoche.de/article/2827943/was-ist-rest.html" target="_blank">RESTful</a>-Weg“, um diese zu erstellen.</p>



<p><strong>Auch interessant:</strong> <a href="https://www.infoworld.com/article/4100499/intro-to-hotwire-interactive-javascript-built-from-html.html" target="_blank">Hotwire</a>. Als Tool-Sammlung, um Single-Page-Anwendungen unter Verwendung von HTML über das Netzwerk zu erstellen, verfügt Hotwire über großartige Funktionen wie Page Morphing. Getreu der klassischen „Free as in Speech“-Softwarekultur werden Ideen zwischen den Projektverantwortlichen von HTMX und Hotwire ausgetauscht.</p>



<h2 class="wp-block-heading">5. <a href="https://powersync.com/" target="_blank" rel="noreferrer noopener">PowerSync</a></h2>



<p>Auch wenn die „Local-First“-Datenrevolution, für die <a href="https://www.infoworld.com/article/4163910/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps.html" target="_blank">PowerSync</a> steht, einen ausgiebigen technischen Deepdive erfordert: Der Kernansatz besteht darin, die Art und Weise, wie Daten in der Webarchitektur fließen, grundlegend neu zu gestalten. Das sollte jeder Webentwickler im Blick behalten.  </p>



<p>Normalerweise erstellen Entwickler Architekturen, die eine komplexe Middleware erfordern. Diese fungiert als Vermittler zwischen einem reaktiven Client und dem Data Store. Die radikale Alternative mit PowerSync: Der Broker wird komplett umgangen, indem eine SQLite-Wasm-Datenbank direkt in den Browser integriert wird. Die Benutzeroberfläche arbeitet dabei synchron mit lokalen Daten unter Verwendung von <a href="https://www.computerwoche.de/article/2830650/9-gruende-gegen-sql.html" target="_blank">SQL</a>, die Latenzzeit beträgt null. Der gefürchtete Ladekreisel wird damit vollständig eliminiert. Im Hintergrund gleicht PowerSync den lokalen Speicher automatisch mit der zentralen Postgres-Datenbank ab. Das Tool händelt die komplexen Synchronisierungs-Algorithmen und Netzwerkschwankungen und macht Ihre Anwendung damit effektiv „offline-first“ – per Default.</p>



<p>Der Haken ist dabei, dass ein „Local-First“-Entwicklungsansatz eine massive Umstellung erfordert: Sie müssen Data Slices (ähnlich einer View) definieren, die jeder Client-User vorhält. Die PowerSync-Engine übernimmt zwar auch hierbei den Großteil der Arbeit, aber Dinge wie Schemamigrationen und Konfliktlösungen (wenn zwei Benutzer denselben Datensatz offline bearbeiten) erfordern ein deutlich aufwendigeres Setup als eine Standard-REST-API.</p>



<p><strong>Auch interessant:</strong> <a href="https://rxdb.info/" target="_blank" rel="noreferrer noopener">RxDB</a>. Dieses Tool ist eine etwas andere Variante eines „Local-First“-Datenspeichers. Während PowerSync stark auf Postgres, SQLite und Hintergrund-Daemons setzt, bietet RxDB eine NoSQL-, „Offline-First“- und reaktive Datenbank. Diese behandelt Queries als „observable“ Streams und führt UI-Aktualisierungen genau in der Millisekunde durch, in der sich die lokalen Daten ändern.</p>



<h2 class="wp-block-heading">6. <a href="https://github.com/RooCodeInc/Roo-Code" target="_blank" rel="noreferrer noopener">RooCode</a></h2>



<p>Der wesentliche Vorteil von RooCode ist, dass es sämtliche Ihrer KI-Anbieter koordinieren kann – und zwar kostenlos. Bei dem Tool handelt es sich um eine Erweiterung für <a href="https://www.computerwoche.de/article/2833165/10-tricks-fuer-visual-studio-code.html" target="_blank">Visual Studio Code</a>, die einen „AI Manager Layer“ bereitstellt. Dieser schlägt eine Brücke zwischen den allgemeinen Fähigkeiten des LLM und den Code-spezifischen Strukturen auf Projektebene.</p>



<p>Dabei erreicht RooCode zwar nicht die Performanz von Tools wie Cursor oder <a href="https://www.computerwoche.de/article/4107872/google-antigravity-ide-angetestet.html" target="_blank">Antigravity</a> – ist aber durchaus in der Lage, die meisten kleinen bis mittelgroßen Requests zu bewältigen. Und das mit einem Minimum an unnötigem Overhead: RooCode hält Sie fern von proprietären Ökosystemen und ermöglicht auch, eigene API-Keys einzubinden – von Anthropic, OpenAI oder auch lokalen Modellen, die auf der eigenen Hardware laufen.</p>



<p>Die versteckten Kosten bestehen – wie bei jedem KI-Coding-Assistenten – darin, dass das Tool die Rolle des Entwicklers vom Code-Autor zum -Redakteur verschiebt.</p>



<p><strong>Auch interessant:</strong> <a href="https://antigravity.google/" target="_blank" rel="noreferrer noopener">Antigravity</a>. RooCode ist eine leichtgewichtige Erweiterung, die Ihre bestehende Umgebung aufwertet. Googles Antigravity ist hingegen ein maßgeschneiderter Editor, der von Grund auf mit Fokus auf KI entwickelt wurde und deshalb auch für Agentic-AI-Workflows konzipiert ist.</p>



<h2 class="wp-block-heading">7. <a href="https://tanstack.com/query/latest" target="_blank" rel="noreferrer noopener">TanStack Query</a></h2>



<p>Selbst wenn Client-seitiges State Management kein Problem mehr darstellt (siehe nächstes Tool), bleibt eine große Lücke bestehen: die Synchronisierung über die Servergrenze hinweg. An diesem Punkt kommt TanStack Query ins Spiel. Distributed Computing ist ein notorisch heikles Problem. Standardmäßige reaktive Modelle speichern den State sowohl auf dem Client als auch auf dem Server. Diese inhärente architektonische Reibung versucht TanStack Query abzumildern, indem es als intelligente asynchrone Schicht fungiert.</p>



<p>Anstatt eine Vielzahl manueller Fetches zu verwenden, die an <code>useState</code>-Aktualisierungen geknüpft sind (zusammen mit anfälligen <code>isLoading</code>-Flags und komplexer Logik zur State-Synchronisation), abstrahiert TanStack Query die aufwendige Arbeit, die mit API-Antworten, Hintergrundaktualisierungen und der Duplikatsbereinigung von Anfragen verbunden ist. Übrig bleiben einige wenige, elegante Hooks. Diese teilen TanStack Query mit, woher die Daten bezogen werden sollen. Dabei nutzt das Tool ein Muster namens „stale-while-revalidate“. Soll heißen: Daten werden im Frontend zwischengespeichert, wiederverwendet (wodurch Reload-Wartezeiten entfallen) und im Hintergrund mit dem aktuellen State synchronisiert.</p>



<p>Der Haken daran ist allerdings, dass TanStack Query Sie dazu zwingt, sich einem der hartnäckigsten Informatik-Probleme direkt zu stellen: der <a href="https://medium.com/on-building-software/why-cache-invalidation-is-actually-hard-e8b5e9a83e45" target="_blank" rel="noreferrer noopener">Cache-Invalidierung</a>. Sie werden also Zeit damit verbringen, über „Query Keys“ zu sinnieren und damit, zu entscheiden, wann ein Datenelement als „veraltet“ gelten soll.</p>



<p><strong>Auch interessant:</strong> <a href="https://swr.vercel.app/" target="_blank" rel="noreferrer noopener">SWR</a>. Während TanStack Query ein absolutes Kraftpaket für komplexe Datenmanipulation ist, bleibt SWR ein Vorreiter des API-Minimalismus. Es tut genau das, was sein Name andeutet (stale-while-revalidate) – und das fast ohne lästige Konfiguration.</p>



<h2 class="wp-block-heading">8. <a href="https://zustand.docs.pmnd.rs/learn/getting-started/introduction" target="_blank" rel="noreferrer noopener">Zustand</a></h2>



<p>Falls Sie noch nicht mit dem Albtraum des großangelegten State Managements in einer reaktiven App konfrontiert wurden, ein kleiner Spoiler: Das kann ziemlich unangenehm werden. Oder Sie nutzen <a href="https://zustand.docs.pmnd.rs/learn/getting-started/introduction" target="_blank" rel="noreferrer noopener">Zustand</a> und verzichten einfach auf den zeremoniellen Boilerplate-Code aus Reducern, Providern und unhandlichen Context-Wrappern. Ersetzt wird das durch einen winzigen, brutal simplen, globalen Speicher.</p>



<p>Anstatt Ihren gesamten Anwendungsbaum in einen massiven React-Context-Provider zu zwängen (was manchmal zu einer Kaskade überflüssiger Neu-Renderings im gesamten DOM führt), nutzt Zustand benutzerdefinierte Hooks, um den State direkt an die spezifischen Komponenten zu binden, die ihn benötigen. Dabei strebt das Tool danach, die Spezifität im reaktiven VDOM-Modell zu erreichen (anstatt sie à la <a href="https://www.infoworld.com/article/4129648/reactive-state-management-with-javascript-signals.html" target="_blank">Signals</a> vollständig zu eliminieren). Sie definieren einen Store, rufen ihn auf – und die Reaktivität funktioniert einfach. Der Preis für diese Befreiung ist die Last der Disziplin: Zustand hindert Sie nicht daran, Ihren globalen Speicher in eine überfüllte Deponie zu verwandeln. Entwickler müssen Ihre eigenen Konventionen und Guardrails einziehen, um großangelegte Projekte überschaubar zu halten.</p>



<p><strong>Auch interessant:</strong> <a href="https://jotai.org/" target="_blank" rel="noreferrer noopener">Jotai</a>. Wenn Zustand der schlank gehaltene globale Store ist, dann ist Jotai der schlank gehaltene, atomare Ansatz. Dieses Tool verwaltet den State „von unten nach oben“ und berechnet Änderungen mit chirurgischer Präzision – ohne dabei massive Neu-Renderings im gesamten Application Tree auszulösen. (fm)</p>



<p><strong>Dieser Artikel ist </strong><a href="https://www.infoworld.com/article/4181872/8-cutting-edge-web-development-tools-you-dont-want-to-miss.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation Infoworld.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Niko Matsakis: Only Bounds]]></title>
<description><![CDATA[only bounds are going to be the most impactful change to Rust that you’ve never heard of. They are currently being designed and developed by the Arm team (David Wood, Rémy Rakic, et al.) as part of the Sized Hierarchy and Scalable Vector Extensions project goal.  This post explores the feature an...]]></description>
<link>https://tsecurity.de/de/3584256/tools/niko-matsakis-only-bounds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3584256/tools/niko-matsakis-only-bounds/</guid>
<pubDate>Tue, 09 Jun 2026 13:09:33 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><code>only</code> bounds are going to be the most impactful change to Rust that you’ve never heard of. They are currently being designed and developed by the Arm team (David Wood, Rémy Rakic, et al.) as part of the <a href="https://rust-lang.github.io/rust-project-goals/2026/scalable-vectors.html">Sized Hierarchy and Scalable Vector Extensions</a> project goal.  This post explores the feature and aims to answer a particular question about the design (the scope of bounds, I’ll explain). But before I dive in, I want to give a bit of context.</p>
<h3>Rust generics have a <code>Sized</code> bound by default today</h3>
<p>In today’s Rust, every type parameter (except for <code>Self</code>) has a default bound called <code>Sized</code>:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="c1">// So this function...
</span></span></span><span class="line"><span class="cl"><span class="k">fn</span> <span class="nf">identity</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="p">(</span><span class="n">t</span>: <span class="nc">T</span><span class="p">)</span><span class="w"> </span>-&gt; <span class="nc">T</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="n">t</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="c1">// ...is actually short for
</span></span></span><span class="line"><span class="cl"><span class="k">fn</span> <span class="nf">identity</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="p">(</span><span class="n">t</span>: <span class="nc">T</span><span class="p">)</span><span class="w"> </span>-&gt; <span class="nc">T</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="k">where</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="n">T</span>: <span class="nb">Sized</span><span class="p">,</span><span class="w"> </span><span class="c1">// &lt;-- Added by default!
</span></span></span><span class="line"><span class="cl"><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="n">t</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><p>A type <code>T</code> implements <code>Sized</code> if the compiler can compute the size of a <code>T</code> value at compilation time. This is true for almost every type, with a few notable exceptions. Consider <code>[u32]</code>, which refers to “some number of <code>u32</code> instances”. We know that a single <code>u32</code> is 4 bytes, but without knowing how many <code>u32</code> there are, you can’t know the size of <code>[u32]</code>. This means you can’t have a value of type <code>[u32]</code> on the stack (how big should the stack frame be?).</p>
<h3>You opt out with <code>?Sized</code></h3>
<p>However, if you have a function like <code>by_ref</code>, that just takes the value <em>by reference</em> (i.e., by pointer), you shouldn’t need to know how big the <code>[u32]</code> value is, because you’re not manipulating it directly. You can have a type parameter <code>U</code> that doesn’t require <code>Sized</code>, but you have to explicitly “opt out” from the default bound:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">fn</span> <span class="nf">by_ref</span><span class="o">&lt;</span><span class="n">U</span><span class="o">&gt;</span><span class="p">(</span><span class="n">t</span>: <span class="kp">&amp;</span><span class="nc">U</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="k">where</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="n">U</span>: <span class="o">?</span><span class="nb">Sized</span><span class="p">,</span><span class="w"> </span><span class="c1">// &lt;-- Opt out from the default
</span></span></span><span class="line"><span class="cl"><span class="p">{</span><span class="w"> </span><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><p>As a fun bit of historical trivia, this system was introduced way back in 2014 to accommodate <a href="https://smallcultfollowing.com/babysteps/blog/2014/01/05/dst-take-5/">Dynamically Sized Types</a>. Before that, <code>&amp;[u32]</code> was actually a built-in, indivisible type; we even wrote it like <code>[u32]/&amp;</code> for a time.<sup><a class="footnote-ref" href="https://smallcultfollowing.com/babysteps/atom.xml#fn:1">1</a></sup></p>
<h3>But <code>Sized</code> vs <code>?Sized</code> isn’t enough for everything we need</h3>
<p>The <code>Sized</code> vs <code>?Sized</code> design has served us reasonably well but it is also showing its limits. It turns out that “value has a statically computable size” vs “each value has a distinct size computable at runtime” doesn’t cover all the things you might want. For example, <code>extern</code> types are types whose values have no known size, even at runtime. And then Arm’s Scalable Vector Extensions want to describe SIMD types where every value of the type has the same size (unlike <code>str</code> and <code>[T]</code>, where each value can have a different length) but where that size is not known until runtime.</p>
<h3>A richer <code>Sized</code> hierarchy</h3>
<p>Rather than just <code>Sized</code> or <code>?Sized</code>, what we really want is to have a richer hierarchy. The current plans look something like this:</p>
<pre class="mermaid">flowchart TD
  subgraph S["Sizedness traits"]
      Sized[["Sized (default)"]] -- extends --&gt; MetadataSized
      MetadataSized -- extends --&gt; MaybeSized
  end
  </pre>
<p>where</p>
<ul>
<li><code>trait Sized</code> means that all values have the same size and that size can be computed knowing only the type.</li>
<li><code>trait MetadataSized</code> means that values can have different sizes and that size can be computed given the metadata attached to a reference to the value. Examples include <code>[T]</code> or <code>dyn Trait</code>.</li>
<li><code>trait MaybeSized</code> is implemented for all values and tells you nothing about the value’s size.</li>
</ul>
<p>Two caveats:</p>
<ol>
<li>I’m excluding the way that Arm’s scalable vector extensions fit into this, because it’s orthogonal.</li>
<li>The trait names aren’t settled. I’m using the names I understand the libs-api team to prefer; they’re not my favorites, but that’s ultimately the team who owns stdlib bikesheds, so I defer to them.<sup><a class="footnote-ref" href="https://smallcultfollowing.com/babysteps/atom.xml#fn:2">2</a></sup></li>
</ol>
<h3>Problem: <code>?Sized</code> notation doesn’t scale to this hierarchy</h3>
<p>But now we have a kind of problem. The <code>?Sized</code> notation was predicated<sup><a class="footnote-ref" href="https://smallcultfollowing.com/babysteps/atom.xml#fn:3">3</a></sup> on the idea that users should specify the default bound they are opting out of – i.e., the <code>?</code> is meant to say “I don’t know if this is <code>Sized</code> or not” (unlike the default, where you know it is <code>Sized</code>). But “opting out” from a bound doesn’t work so well with a multi-level hierarchy. When you write <code>?Sized</code>, does that correspond to <code>T: MetadataSized</code> (but not <code>T: Sized</code>)? And what if we want to insert another level in between <code>T: MetadataSized</code> and <code>T: Sized</code> later? Then we either have to change what <code>T: ?Sized</code> means (to refer to the new bound) or we have to have <code>T: ?Sized</code> drop <em>two</em> levels down the hierarchy. Even more annoying, what do we do while that middle rung is unstable? Surely <code>T: ?Sized</code> shouldn’t refer to an unstable trait… what if we decide to remove it</p>
<h3>Solution: <code>only</code> bounds</h3>
<p>The new proposal is to write <code>T: only MetadataSized</code> or <code>T: only UnknownSized</code> instead of <code>T: ?Sized</code>. An <code>only</code> bound combines two things:</p>
<ol>
<li>Like any bound, it includes a “minimum requirement” – i.e., <code>T: only MetadataSized</code> means that <code>T</code> must implement <em>at least</em> <code>MetadataSized</code>.</li>
<li>It additionally disables some <em>default</em> bounds – i.e., we will <em>not</em> add the default <code>T: Sized</code> bound.</li>
</ol>
<p>The name <code>only</code> comes from the fact that <code>T: Sized</code> implies <code>T: MetadataSized</code>. So the default of <code>T: Sized</code> already means that <code>T: MetadataSized</code> for free; but when you write <em>only</em> MetadataSized, you are saying “I don’t need the full hierarchy, just <code>MetadataSized</code> will do”.</p>
<h3><code>only</code> bounds work like normal bounds: ask for what you need</h3>
<p>A nice feature of <code>only</code> bounds is that they work more like a regular bound. Whereas a <code>?</code> bound is saying “I don’t need this”, an <code>only</code> bound is saying what you <em>do</em> need. So e.g. if you are writing a function that just has references to values of type <code>T</code> does not care what their size is, you can write</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">fn</span> <span class="nf">by_ref</span><span class="o">&lt;</span><span class="n">U</span><span class="o">&gt;</span><span class="p">(</span><span class="n">u</span>: <span class="kp">&amp;</span><span class="nc">U</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="k">where</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="n">U</span>: <span class="nc">only</span><span class="w"> </span><span class="n">MaybeSized</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">{}</span><span class="w">
</span></span></span></code></pre></div><p>If you are writing a function that <em>does</em> need to compute the size of values of type <code>V</code>, you can ask for that capability:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">fn</span> <span class="nf">checks_size</span><span class="o">&lt;</span><span class="n">V</span><span class="o">&gt;</span><span class="p">(</span><span class="n">v</span>: <span class="kp">&amp;</span><span class="nc">V</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="k">where</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="n">V</span>: <span class="nc">only</span><span class="w"> </span><span class="n">MetadataSized</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="n">std</span>::<span class="n">mem</span>::<span class="n">size_of_val</span><span class="p">(</span><span class="n">v</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><h3><code>only</code> bounds allow for new levels to be added later</h3>
<p>A nice feature of <code>only</code> bounds is that, later on, we can add new levels to the hierarchy, and they work normally. For example, suppose we wish to add something like <code>Aligned</code> where the <em>size</em> is not known at compilation time but the alignment <em>is</em>. We could change the hierarchy to</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">trait</span><span class="w"> </span><span class="nb">Sized</span>: <span class="nc">Aligned</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="k">trait</span><span class="w"> </span><span class="n">Aligned</span>: <span class="nc">MetadataSized</span><span class="w"> </span><span class="c1">// &lt;-- new!
</span></span></span><span class="line"><span class="cl"><span class="k">trait</span><span class="w"> </span><span class="n">MetadataSized</span>: <span class="nc">MaybeSized</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="k">trait</span><span class="w"> </span><span class="n">MaybeSized</span><span class="w">
</span></span></span></code></pre></div><p>and functions with <code>U: only MaybeSized</code> (like <code>by_ref</code>) and with <code>V: only MetadataSized</code> (with <code>checks_size</code>) would continue to have the same requirements. But new functions could be written with <code>T: only Aligned</code> that would use the new bound. And there is no conflict with stabilization; code that writes <code>T: only Aligned</code> can be considered unstable until that middle hierarchy is finalized.</p>
<h3><code>only</code> bounds compose normally</h3>
<p>Like any other bound, <code>only</code> bounds are combined with other bounds to form the overall requirements. So it is possible to write e.g. <code>T: only MetadataSized + Sized</code>. This is equivalent to <code>T: Sized</code> and therefore equivalent to the default and <em>therefore</em> kind of pointless, but you can write it. Similarly, given that <code>trait Clone: Sized</code>, if you write <code>T: only MetadataSized + Clone</code>, that is kind of pointless too: you might as well write <code>T: Clone</code>, which would be equivalent. We plan to have a warn-by-default lint for that.</p>
<h3>Scaling <code>only</code> to other “default bound families” (speculative)</h3>
<p>The final strength of <code>only</code> bounds is that they allow us to introduce whole new <em>families</em> of default bounds. One example is the idea of <a href="https://smallcultfollowing.com/babysteps/blog/2025/10/21/move-destruct-leak/">introducing a <code>Move</code> bound</a>. Note that this is a distinct feature and is not covered under the <a href="https://github.com/rust-lang/rfcs/pull/3729">current RFC</a>.</p>
<p>All types in Rust today are “movable” and “forgettable”, meaning that you can memcpy the value from place to place so long as you stop using the previous location <em>and</em> you can recycle the memory where it is stored without running the value’s destructor. There is one notable exception – when you pin a value, you it can no longer be moved, and you must run its destructor before its memory is reused – but otherwise this is a hard-and-fast rule. And that’s annoying!</p>
<p>The problem is that not being able to guarantee that a destructor runs blocks a lot of unsafe code patterns. For example, <a href="https://smallcultfollowing.com/babysteps/blog/2016/10/02/observational-equivalence-and-unsafe-code/">scoped tasks a la <code>rayon</code> depend on a destructor for safety</a>. In sync code, this works because we’ve decided it’s UB to unwind a stack frame without running the destructors of values stored there, and so if you put a local variable on the stack, you can be sure its destructor will run. But that doesn’t work in <code>async</code> code! And there are times when unwinding <em>without</em> running destructors would be nice.</p>
<p>The solution is to introduce a second family of default traits. Unlike the <code>Sized</code> family we saw before, this family defines fine-grained capabilities about how values of that type can be used:</p>
<pre class="mermaid">flowchart TD
  subgraph A["Accessability traits"]
      Forget[["Forget (default)"]] -- extends --&gt; Leak
      Leak -- extends --&gt; Destruct
      Destruct -- extends --&gt; Access
      Move[["Move (default)"]] -- extends --&gt; Access
  end
  Copy -- extends --&gt; Move
  </pre>
<p>The meaning of the traits are as follows:</p>
<ul>
<li><code>Forget</code>, the default, says that you can recycle the memory for a value without running its destructor.</li>
<li><code>Leak</code> says that you can skip running a destructor for a value, but only if you never reuse the memory where the value resides.</li>
<li><code>Destruct</code> says that if you have a value of this type, you can reuse the memory where it resides by running its destructor.</li>
<li><code>Copy</code>, which already exists, says that you can memcpy the place and keep using the original place; it’s not really a default, but I included it because it is relevant.</li>
<li><code>Move</code>, another default, says that you can memcpy the value to a new place if you stop using the original.</li>
<li><code>Access</code> is the root of this family. It indicates a value that can be “accessed in place” (basically, any value at all).</li>
</ul>
<p>This introduces new checks into the compiler:</p>
<ul>
<li>When you move a value (i.e., <code>a = b</code> where <code>b</code> is not used later), we will check that the type implements <code>Move</code> (whereas today, it is always allowed).</li>
<li>When you exit a scope, we will check that the values in each local variables have either been moved or have a type that implements <code>Destruct</code>.</li>
</ul>
<p>Some implications:</p>
<ul>
<li>If your function owns a value of type <code>T: only Destruct</code>, then you <em>must</em> destruct it before your function returns. You can’t move it (because you don’t know if it implements <code>Move</code>) and you can’t leak or forget it either.</li>
<li>If your function owns a value of type <code>T: only Move</code>, then the only thing you can do with it is move it somewhere else. You can’t drop it (because you don’t know if it implements <code>Destruct</code>).</li>
<li>No function can own a value of type <code>T: only Access</code>, because you wouldn’t be able to move it nor drop it, and hence you could not return. But you could have such a value (say) in a <code>static</code>.</li>
</ul>
<h3>How <code>only</code> bounds could work in the presence of multiple families</h3>
<p>The spur for writing this blog post was a question in a lang team meeting on how <code>only</code> bounds ought to work given the existence of multiple “families” of default traits, as I described above. Although the <a href="https://github.com/rust-lang/rfcs/pull/3729">current RFC</a> is looking only at the <code>Sized</code> traits, we expect to look at the “access family” in a future RFC, so we want to be sure we are not making any decisions that won’t scale to cover both.</p>
<p>The way I imagine it working is like this. Each default traits is associated with one or more “families”. When you have an only bound, it “opts out” from all default traits in each family that the trait is associated with:</p>
<ul>
<li><code>T: only Move</code> opts out from <code>Forget</code>, <code>Leak</code>, <code>Destruct</code> – but not <code>Sized</code>.</li>
<li><code>T: only Destruct</code> opts out from <code>Forget</code>, <code>Leak</code>, and <code>Move</code> – but not <code>Sized</code>.</li>
<li><code>T: only MetadataSized</code> opts out from <code>Sized</code> – but not <code>Forget</code> or <code>Move</code>.</li>
<li><code>T: only MaybeSized</code> opts out from <code>Sized</code> – but not <code>Forget</code> or <code>Move</code>.</li>
</ul>
<p>You may also want to “opt back in” to some defaults. For example, <code>T: only Move + Destruct</code> is a sensible thing to do. It means values that can be moved and destructed but not leaked or forgotten.</p>
<h3>Examples</h3>
<h4><code>Option::map</code> requires <code>only Move</code></h4>
<p><code>map</code> is an example of a function that only needs <code>Move</code>. You need to be able to destructure <code>self</code> (which <em>moves</em> the optional value out into a local variable <code>v</code> and then invoke the closure <code>op</code>, which again moves the wrapped value <code>v</code>:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">impl</span><span class="o">&lt;</span><span class="n">T</span>: <span class="nc">only</span><span class="w"> </span><span class="n">Move</span><span class="o">&gt;</span><span class="w"> </span><span class="nb">Option</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="k">fn</span> <span class="nf">map</span><span class="o">&lt;</span><span class="n">U</span>: <span class="nc">only</span><span class="w"> </span><span class="n">Move</span><span class="o">&gt;</span><span class="p">(</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="bp">self</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="n">op</span>: <span class="nc">impl</span><span class="w"> </span><span class="nb">FnOnce</span><span class="p">(</span><span class="n">T</span><span class="p">)</span><span class="w"> </span>-&gt; <span class="nc">U</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="p">)</span><span class="w"> </span>-&gt; <span class="nb">Option</span><span class="o">&lt;</span><span class="n">U</span><span class="o">&gt;</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="k">match</span><span class="w"> </span><span class="bp">self</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">            </span><span class="nb">Some</span><span class="p">(</span><span class="n">v</span><span class="p">)</span><span class="w"> </span><span class="o">=&gt;</span><span class="w"> </span><span class="nb">Some</span><span class="p">(</span><span class="n">op</span><span class="p">(</span><span class="n">v</span><span class="p">)),</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">            </span><span class="nb">None</span><span class="w"> </span><span class="o">=&gt;</span><span class="w"> </span><span class="nb">None</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="p">}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="p">}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><p>One interesting thing is the result type <code>U</code>. Using only the stuff I wrote in this blog post, it needs to be <code>only Move</code>, because the result will be moved into the <code>Some</code> value and so forth. But <a href="https://rust-lang.github.io/rust-project-goals/2026/in-place-init.html">in-place-init</a> would allow for this definition to omit the <code>U: only Move</code> bound because we could statically guarantee that the <code>Option</code> will be constructed in place and never moved after that.</p>
<h4><code>Option::or</code> requires <code>only Move + Destruct</code></h4>
<p>The <code>a.or(b)</code> method on <code>Option</code> returns <code>a</code> if it is <code>Some</code> and otherwise returns <code>b</code>. This is an interesting one because the value <code>b</code> may not be used and therefore requires <code>only Move + Destruct</code> bounds.</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">impl</span><span class="o">&lt;</span><span class="n">T</span>: <span class="nc">only</span><span class="w"> </span><span class="n">Move</span><span class="o">&gt;</span><span class="w"> </span><span class="nb">Option</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="k">fn</span> <span class="nf">or</span><span class="p">(</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="bp">self</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="n">alternate</span>: <span class="nb">Option</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="p">)</span><span class="w"> </span>-&gt; <span class="nb">Option</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="k">where</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="n">T</span>: <span class="nc">Destruct</span><span class="p">,</span><span class="w"> </span><span class="c1">// &lt;-- because it may be dropped
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="k">match</span><span class="w"> </span><span class="bp">self</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">            </span><span class="nb">Some</span><span class="p">(</span><span class="n">v</span><span class="p">)</span><span class="w"> </span><span class="o">=&gt;</span><span class="w"> </span><span class="nb">Some</span><span class="p">(</span><span class="n">v</span><span class="p">),</span><span class="w"> </span><span class="c1">// drops `alternate`
</span></span></span><span class="line"><span class="cl"><span class="w">            </span><span class="nb">None</span><span class="w"> </span><span class="o">=&gt;</span><span class="w"> </span><span class="n">alternate</span><span class="p">,</span><span class="w"> </span><span class="c1">// moves `alternate`
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="p">}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="p">}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><h4><code>Rc</code> requires <code>MaybeSized + Leak</code></h4>
<p>The <code>Rc</code> type is an example where we would want to relax bounds from both families:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">struct</span> <span class="nc">Rc</span><span class="o">&lt;</span><span class="n">T</span>: <span class="nc">only</span><span class="w"> </span><span class="n">MaybeSized</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="n">only</span><span class="w"> </span><span class="n">Leak</span><span class="o">&gt;</span><span class="w"> </span><span class="p">{}</span><span class="w">
</span></span></span></code></pre></div><p>I believe the proper minimum bounds for <code>Rc</code> are:</p>
<ul>
<li><code>only MaybeSized</code> because while it can store <code>MetadataSized</code> or <code>Sized</code> things, it doesn’t have to, it can also store things of an non-computable size (although it does raise the question of how they would be freed, but that’s an allocator concern).</li>
<li><code>only Leak</code> because <code>Rc</code> values can form cycles and thus we can’t ever guarantee the destructor will be run. Interestingly, <code>Rc&lt;T&gt;</code> can implement <code>Forget</code> even its contents don’t.</li>
</ul>
<h3>Frequently asked questions</h3>
<h4>What is actually under RFC today?</h4>
<p>The post may be a bit confusing here. The <a href="https://github.com/rust-lang/rfcs/pull/3729"><em>current RFC</em></a> is looking only at the proposed “Sized” traits. The <code>Access</code> family is a speculative future extension that we are exploring but at a much earlier stage.</p>
<h4>Can I use <code>only</code> with <em>any</em> trait?</h4>
<p>In the beginning, the plan would be that <code>only</code> can only be used for well-known, <em>default</em> traits (e.g., <code>Move</code>, <code>Sized</code>, etc). In the future though there are some thoughts to generalizing it.</p>
<h4>Why not opt out from <em>all</em> defaults at once?</h4>
<p>An alternative that was proposed is to have the opt-out be per-type-parameter. So you might write something like</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">fn</span> <span class="nf">foo</span><span class="o">&lt;</span><span class="n">T</span>: <span class="nc">MetadataSized</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="o">?</span><span class="n">default</span><span class="o">&gt;</span><span class="w">
</span></span></span></code></pre></div><p>which would “opt out” from <em>all</em> defaulted bounds. Obviously we’d have to bikeshed the syntax, but ignore that for now. The question is whether opting out of <em>all</em> defaults is better than opting out of a single family. I prefer the per-family option for two reasons:</p>
<ul>
<li>First, things like <code>T: only Move</code> demonstrate that you might very reasonably which to opt out from a single family but retain the default <code>Sized</code> bound. I think it’s likely that there will be many functions that want to opt out of <code>Sized</code> <em>or</em> <code>Forget</code> <em>but not both</em>.
<ul>
<li>You might think that we could make <code>Move: Sized</code> to get the same effect, but I think that would be a mistake. The fact that a value’s size must be computed dynamically doesn’t inherently mean it can’t be moved.</li>
</ul>
</li>
<li>Second, it makes it harder to introduce new families later, if we decide there are other orthogonal properties of values that we’d like to relax.</li>
</ul>
<h4>Why do you think it’s likely that people want to opt out of being <code>Sized</code> <em>xor</em> <code>Forget</code> <em>but not both</em>?</h4>
<p>Because the <code>Forget</code>, <code>Move</code>, and similar traits mostly apply to owned values. The examples we saw with <code>Option&lt;T&gt;</code> were quite typical. And when you are moving values of type <code>T</code> around, you need that <code>T</code> to be <code>Sized</code>.</p>
<h4>But we saw that <code>Rc</code> wanted to opt out of both families with <code>only Leak + only MetadataSized</code>, right?</h4>
<p>Yes, that’s true, and I think that particular combo will be common. I don’t think that’s an argument for the <code>?default</code> approach on its own, though, particularly since that case would not be much cleaner or shorter…</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">impl</span><span class="o">&lt;</span><span class="n">T</span>: <span class="o">?</span><span class="n">default</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="n">Leak</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="n">MetadataSized</span><span class="o">&gt;</span><span class="w"> </span><span class="n">Rc</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="w"> </span><span class="p">{}</span><span class="w">
</span></span></span></code></pre></div><p>…what I think that argues for is actually <em>trait aliases and shorthands</em>.</p>
<h4>Wait, trait aliases and shorthands? Can you elaborate?</h4>
<p>Yes! I think that a future RFC could extend only bounds to allow you to define trait aliases with “only bounds” as supertraits:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">trait</span><span class="w"> </span><span class="n">RefCountable</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="n">only</span><span class="w"> </span><span class="n">Leak</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="n">only</span><span class="w"> </span><span class="n">MetadataSized</span><span class="p">;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="c1">// Equivalent to:
</span></span></span><span class="line"><span class="cl"><span class="c1">// trait RefCountable: only Leak + only MetadataSized {}
</span></span></span><span class="line"><span class="cl"><span class="c1">// impl&lt;T&gt; RefCountable for T where T: only Leak + only MetadataSized {}
</span></span></span></code></pre></div><p>You could then use an <code>only RefCountable</code> bound to define <code>Rc&lt;T&gt;</code>:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">impl</span><span class="o">&lt;</span><span class="n">T</span>: <span class="nc">only</span><span class="w"> </span><span class="n">Refcountable</span><span class="o">&gt;</span><span class="w"> </span><span class="n">Rc</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="w">
</span></span></span></code></pre></div><p><em>Without the <code>only</code>,</em> <code>T: Refcountable</code> would just be a regular trait bound and would not opt-out from any defaults.</p>
<h4>Can we use a “root” trait to opt out of all defaults?</h4>
<p>Yes, we could! You could define an alias like <code>Value</code>:</p>
<div class="highlight"><pre class="chroma" tabindex="0"><code class="language-rust"><span class="line"><span class="cl"><span class="k">trait</span><span class="w"> </span><span class="n">Value</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="n">only</span><span class="w"> </span><span class="n">Access</span><span class="w"> </span><span class="o">+</span><span class="w"> </span><span class="n">only</span><span class="w"> </span><span class="n">MaybeSized</span><span class="p">;</span><span class="w">
</span></span></span></code></pre></div><p>Since <code>Access</code> and <code>MaybeSized</code> are both implemented for all types, this effectively becomes part of both families:</p>
<pre class="mermaid">flowchart TD
  subgraph All["All default families"]
  subgraph A["Access family"]
    Forget[["Forget (default)"]] -- extends --&gt; Leak
    Leak -- extends --&gt; Destruct
    Destruct -- extends --&gt; Access
    Move[["Move (default)"]] -- extends --&gt; Access
  end

  subgraph S["MaybeSized family"]
    Sized[["Sized (default)"]] -- extends --&gt; MetadataSized
    MetadataSized -- extends --&gt; MaybeSized
  end

  Access -- extends --&gt; Value
  MaybeSized -- extends --&gt; Value
  end
  </pre>
<p>Then you can do <code>T: only Value</code> and opt out from both families at once.</p>
<h4>If we did that, what would happen if we wanted to add a new family in the future?</h4>
<p>Ay, there’s the rub. If we wish to add a new family in the future, let’s say for values that don’t live in the same memory space (<code>T: only Distributed</code>…?), then <code>Value</code> would be “out of date” because code written against <code>Value</code> would still be assuming uni-memory-space values. But we could make <code>Value</code> into an edition-dependent alias or something like that, as has been discussed.</p>
<h4>Can we decide whether we want <code>Value</code> later?</h4>
<p>Yes! We can introduce a root trait at any time. So we can add the <code>Sized</code>-ness family first, then the <code>Access</code> family, and then see how we feel. Maybe we find people are very commonly opting out of both– in which case, some aliases are useful, or perhaps a <code>Value</code> variant.</p>
<p>The only way we might “regret” it is if, in practice, people usually just opted out of both and then opted back in to what they want specifically. But we already know that <code>T: only Move</code> will be common and clearly <code>T: only Value + Move + Sized</code> is more awkward in that case, so I don’t consider that very likely.</p>
<h4>Why the name <code>Destruct</code> and not <code>Drop</code>?</h4>
<p>That name comes from the <code>const trait</code> RFC. There are a few reasons to move away from <code>Drop</code>. The first is that it is possible to have a destructor even if you don’t implement <code>Drop</code>: <code>Drop</code> really refers to <em>user-provided logic</em> in the destructor, but the compiler adds its own logic (“drop glue”, it’s sometimes called) to drop all the fields in the value. The second reason is that the <code>Drop</code> trait itself needs some revision, so moving away from that name lets us have other ways to specify custom logic (e.g., pinned self, or by-value, etc etc).</p>
<h4>How does this interact with <code>const</code> traits anyway?</h4>
<p>Quite beautifully! In fact, the proposal from Arm for SVE is to introduce the idea of <code>T: const Sized</code> being “a type whose size can be computed at compilation time”, which I find quite elegant. Similarly <code>T: const Destruct</code> was proposed by the const RFC as a way to say that a value has a constant destructor.</p>
<h4>It’s annoying to write <code>T: only Move + Destruct</code>. Couldn’t we have <code>Destruct</code> imply <code>Move</code> so that I can just write <code>T: only Destruct</code>?</h4>
<p>My original proposal for introducing linear types had <code>Destruct</code> extending <code>Move</code>. This would mean that the <code>Option::or</code> proposal could simply do <code>U: only Destruct</code> and not <code>U: only Move + Destruct</code>. However, Alice Ryhl and others pointed out that there are immovable types that must nonetheless be destructed, so it doesn’t make sense to combine those.</p>
<h4>Where can I learn more?</h4>
<p>The <a href="https://rust-lang.github.io/rust-project-goals/2026/scalable-vectors.html">Project Goal</a> has a lot of details. The latest updates are available on the <a href="https://github.com/rust-lang/rust/issues/144404">tracking issue</a>. If you like watching videos, I recommend David Wood’s <a href="https://youtu.be/dngSPnu-B10">Rust Nation talk</a>.</p>
<h3>Conclusion</h3>
<p>I want to close with a meta-observation and a big shout-out to the Arm team. I think they are showing how awesome open-source can be. The Arm team’s primary motivation is adding support for Scalable Vector Extensions. This helps Rust make full use of Arm processors. This is, in and of itself, a laudable goal, and valuable to Rust: One of Rust’s assets, in my view, is that it gives you access to all the power your processor has to provide, and that should include unique extensions.</p>
<p>But rather than add the feature as a kind of special-case extension to Rust, the Arm team is going further and driving a general purpose improvement, one that will unlock a bunch of other features (extern types and, to some extent, guaranteed destructors; guaranteed destructores themselves unlock scoped async threads and better Wasm integration). I love that.</p>
<div class="footnotes">
<hr>
<ol>
<li>
<p>In fact, I recall that in one of my blog posts I proposed writing <code>""</code> as the way to spell <code>&amp;str</code>. I kinda wish we had done that just for the sheer wackiness of it (<code>fn foo(name: "")</code>). <a class="footnote-backref" href="https://smallcultfollowing.com/babysteps/atom.xml#fnref:1">↩︎</a></p>
</li>
<li>
<p>I prefer names that refer to the <em>operations</em> that can be performed on the values, so e.g. instead of <code>MetadataSized</code> I would prefer <code>SizeOfVal</code>, since it means that you can invoke the <code>std::mem::size_of_val</code> function on it. <a class="footnote-backref" href="https://smallcultfollowing.com/babysteps/atom.xml#fnref:2">↩︎</a></p>
</li>
<li>
<p>Little logic pun there for you. <a class="footnote-backref" href="https://smallcultfollowing.com/babysteps/atom.xml#fnref:3">↩︎</a></p>
</li>
</ol>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[8 cutting-edge web development tools you don’t want to miss]]></title>
<description><![CDATA[There is no ordained path. The hope that we were converging on some kind of consensus in web development has been eradicated by recent, ingenious developments that point in almost every direction. Yet, if there is a central theme uniting these efforts, it is the desire to mitigate the layers of l...]]></description>
<link>https://tsecurity.de/de/3583920/ai-nachrichten/8-cutting-edge-web-development-tools-you-dont-want-to-miss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3583920/ai-nachrichten/8-cutting-edge-web-development-tools-you-dont-want-to-miss/</guid>
<pubDate>Tue, 09 Jun 2026 11:03:29 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>There is no ordained path. The hope that we were converging on some kind of consensus in web development has been eradicated by recent, ingenious developments that point in almost every direction. Yet, if there is a central theme uniting these efforts, it is the desire to mitigate the layers of liturgical embellishment that have grown up around the reactive canon. How can we look at things differently to attain the power that we need, without the heavy intricacy?</p>



<p>Here are eight cutting-edge web development tools that point the way. </p>



<h2 class="wp-block-heading">Front-end maestro</h2>



<p>If you put a bunch of classical musicians in a room together with sheet music and let them run, you <em>might </em>get to a cohesive piece—but you <em>probably </em>want a conductor, a maestro who coordinates all of the parts. That is <a href="https://www.infoworld.com/article/3842325/designing-a-dynamic-web-application-with-astro-js.html">Astro</a> for your front-end frameworks.</p>



<p>Astro addresses the “<a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">hydration</a>” of the front end, that is to say, the process of making the shell reactive. In conventional server-side rendering (SSR), like Next.js or Nuxt, the server not only sends the HTML, but also sends the massive framework runtime down the wire, just to attach event listeners to the page. Astro allows you to write components in React, Svelte, Vue, or Solid, and its compiler strips away all of the JavaScript before it reaches the browser. Astro ships zero JS by default, relying on its <a href="https://docs.astro.build/en/concepts/islands/" data-type="link" data-id="https://docs.astro.build/en/concepts/islands/">islands architecture</a> to hydrate only the specific components that demand interactivity. </p>



<p>Because Astro isolates interactivity into distinct islands, sharing complex state between those islands (e.g., a complex filtering sidebar communicating with a separate dynamic data grid) is fundamentally harder than it is in a monolithic single-page application. If you are building a highly interactive, dashboard-heavy app where every component affects every other component, Astro’s isolated islands might begin to feel more like a straitjacket than a liberation.</p>



<p>See also: <a href="https://www.infoworld.com/article/2337044/intro-to-qwik-a-superfast-javascript-framework.html" data-type="link" data-id="https://www.infoworld.com/article/2337044/intro-to-qwik-a-superfast-javascript-framework.html">Qwik</a>. If Astro unbloats by stripping away the JavaScript entirely, Qwik unbloats by delaying it. Qwik delivers instant HTML and serializes the application state, downloading and executing only the JavaScript code required for a specific interaction at the exact millisecond the user clicks a button.</p>



<h2 class="wp-block-heading">Biome: Lint like it’s 2026</h2>



<p><a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html" data-type="link" data-id="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">Rust</a> is gradually replacing the underlying infrastructure in the JavaScript ecosystem. But while Rust gives <a href="https://biomejs.dev/">Biome</a> its close-to-the-metal speed, Biome’s true calling card is its unification of the sprawling toolchain under a cohesive umbrella.</p>



<p>The .eslintrc and .prettierrc files and the dozen associated plugins can become a dark and unhappy bog in a project. Biome is the way out of the mire. It is a single, blazingly fast binary that replaces your entire tangled formatting and linting ecosystem, providing a path to code quality that doesn’t require a sprawling web of dependencies.</p>



<p>Probably the biggest drawback to Biome is that you lose the wide-open extensibility—which is exactly the same feature that makes Biome lean.</p>



<p>See also: <a href="https://rspack.rs/">Rspack</a>. Biome cleans up the linting. Rspack unbloats the build step. Also built on Rust for speed, Rspack challenges the new “unbundled” esbuild-based dev mode championed by Vite and uses bundled dev mode.</p>



<h2 class="wp-block-heading">Bun: Fast and integrated back-end JavaScript</h2>



<p>Most cutting-edge JavaScript enthusiasts are already well-aware of <a href="https://www.infoworld.com/article/2338008/explore-bunjs-the-all-in-one-javascript-runtime.html">Bun</a>. For those who haven’t yet experienced Bun’s enthralling blend of one-stop shopping and blistering speed first-hand, it’s a virtually irrefutable must-try.</p>



<p>Fast is probably an understatement. If you are used to <a href="https://www.infoworld.com/article/2254485/what-is-nodejs-javascript-runtime-explained.html">Node</a> and you try out Bun, you will likely be immediately impressed with the speed at which commands execute. The Bun team has also made an extensive, multi-year effort to bring its engine into close compatibility with Node’s APIs. Overall, Bun is an extraordinary engineering effort that every JS developer should explore. </p>



<p>However, while Bun’s <a href="https://www.infoworld.com/article/2338081/meet-the-zig-programming-language.html">Zig</a>-based engine is in most respects a drop-in for Node, it isn’t perfect, especially when considering the gargantuan landscape of Node packages out there. Node remains the conservative, happy-path engine for server-side JavaScript. </p>



<p>See also: <a href="https://www.infoworld.com/article/2256205/what-is-deno-a-better-nodejs.html" data-type="link" data-id="https://www.infoworld.com/article/2256205/what-is-deno-a-better-nodejs.html">Deno</a>. Although Bun has justifiably earned a reputation for bleeding-edge innovation, Deno has quietly pressed ahead with an appealing set of enterprise features like an integrated deployment platform and a front-end framework (<a href="https://www.infoworld.com/article/3523813/intro-to-deno-fresh-a-fresh-take-on-full-stack-javascript.html">Deno Fresh</a>).</p>



<p>The Bun curious also may want to check out my interview with Bun creator <a href="https://www.infoworld.com/article/2338698/interview-with-jarred-sumner-buns-creator-talks-tech-funding-and-startups.html">Jared Sumner</a>.</p>



<h2 class="wp-block-heading">HTMX: Ajax KISS</h2>



<p>If we are talking about clever ways to de-complexify the web, <a href="https://www.infoworld.com/article/4150864/htmx-4-0-hypermedia-finds-a-new-gear.html">HTMX</a> could reasonably be considered the poster-child. It takes the core mechanisms of the modern web client, like <a href="https://developer.mozilla.org/en-US/docs/Glossary/AJAX" data-type="link" data-id="https://developer.mozilla.org/en-US/docs/Glossary/AJAX">Ajax</a> and partial updates, and turns them into simple HTML attributes. That means the state lives exclusively on the server, which is responsible for sending HTMX fragments.</p>



<p>Of course, there are trade-offs. Perhaps most unavoidable is the extreme dependence on the network. Because there is no client-side state machine, the browser will be orphaned and helpless without a connection to the server. That is, unless you <a href="https://www.infoworld.com/article/4163910/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps.html" data-type="link" data-id="https://www.infoworld.com/article/4163910/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps.html">get experimental</a> with a <a href="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html" data-type="link" data-id="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html">local-first datastore</a>.</p>



<p>Long story short: if your app falls into the realm of HTMX’s ability, HTMX is likely to be the most direct <a href="https://www.infoworld.com/article/2334742/what-is-rest-the-de-facto-web-architecture-standard.html">RESTful</a> way to build it. And HTMX can in fact handle quite a lot.</p>



<p>See also: <a href="https://www.infoworld.com/article/4100499/intro-to-hotwire-interactive-javascript-built-from-html.html" data-type="link" data-id="https://www.infoworld.com/article/4100499/intro-to-hotwire-interactive-javascript-built-from-html.html">Hotwire</a>. A collection of tools for building single-page-style applications using HTML over the wire, Hotwire has great features like page morphing, which can diff HTML instead of cold-loading it, with a simple import. True to classic “free as in speech” software culture, the HTMX and Hotwire projects freely exchange ideas. </p>



<h2 class="wp-block-heading">PowerSync: Data layer redo</h2>



<p>Although the local-first data revolution that <a href="https://www.infoworld.com/article/4163910/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps.html">PowerSync</a> represents implies a fairly serious engineering deep dive, its core proposal — to entirely reshape the way data moves in web architecture — is something a web developer needs to be aware of.</p>



<p>Usually, we create architectures that require a complex middleware to broker between a reactive client and the datastore. PowerSync proposes a radical alternative: bypass the middleman entirely by dropping a robust SQLite Wasm database directly into the browser.</p>



<p>The UI works on local data using <a href="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html" data-type="link" data-id="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html">familiar SQL</a>, synchronously. Latency is zero. The dreaded loading spinner vanishes entirely. In the background, PowerSync automatically reconciles your local store with your central Postgres database. It handles the complex syncing algorithms and network drops, effectively making your application offline-first by default.</p>



<p>The catch, of course, is that local-first development forces a massive mental shift. You have to define data slices (similar to a view) that each client user holds. The PowerSync engine does most of the hard work, but things like schema migrations and conflict resolution (when two users edit the same record while offline) require a significantly steeper initial setup than a standard REST API.</p>



<p>See also: <a href="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html" data-type="link" data-id="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html">RxDB</a>. RxDB is a slightly different flavor of local-first datastore. Whereas PowerSync relies heavily on Postgres, SQLite, and background daemons, RxDB provides a NoSQL, offline-first, reactive database that treats queries as observable streams, pushing UI updates the exact millisecond the local data changes. </p>



<h2 class="wp-block-heading">RooCode: Use any AI you want</h2>



<p>The beauty of <a href="https://www.infoworld.com/article/4019646/roo-code-review-a-first-look-at-autonomous-ai-powered-development-in-the-ide.html">RooCode</a> lies in its ability to orchestrate whatever AI providers you have—for free. RooCode is an extension to <a href="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html" data-type="link" data-id="https://www.infoworld.com/article/2335960/what-is-visual-studio-code-microsofts-extensible-code-editor.html">Visual Studio Code</a> that provides an AI manager layer. This layer bridges between the general abilities of the LLM and your code-specific, project-level structures.</p>



<p>RooCode is strong enough to be somewhat agentic in its capabilities. It doesn’t reach the powerhouse abilities of something like Cursor or Antigravity, but it is quite able to handle most small to medium-sized requests. And it does so with a minimum of unnecessary overhead. I find myself often using RooCode alongside my AI-assisted IDE to knock out lesser requirements, for less cost and without interrupting the flow of ongoing epics.</p>



<p>RooCode keeps you free of proprietary ecosystems. It allows you to plug in your own API keys—whether that is Claude, OpenAI, or even a local model running on your own hardware. </p>



<p>The hidden tax of any AI coding assistant, however, is that it fundamentally shifts your job description from “writer” to “editor.” The unbloating of keystrokes can paradoxically lead to massively bloated codebases if developers blindly accept AI-generated boilerplate without actively reviewing its architectural impact. It is incredibly easy to let an agent spin up 500 lines of complex React when 50 lines of plain JavaScript would have done.</p>



<p>See also: <a href="https://antigravity.google/" data-type="link" data-id="https://antigravity.google/">Antigravity</a>. RooCode is a lightweight extension that supercharges your existing environment. Google’s Antigravity is a custom-built editor designed from the ground up around AI, geared for agentic development workflows.</p>



<h2 class="wp-block-heading">TanStack Query: Syncing made simple(r)</h2>



<p>Even when client-side state management is addressed (see Zustand below), there is still a big, gaping hole in the plot: syncing across the server boundary. That is where <a href="https://tanstack.com/query/latest">TanStack Query</a> steps into the breach.</p>



<p>Distributed computing is a notoriously thorny problem, and in fact our standard reactive model walks right into these thorns by holding the same state in two different places: on the client and the server.  Tanstack Query tries to make this inherent architectural friction as painless as possible by acting as an intelligent asynchronous layer. </p>



<p>Instead of using a bunch of manual fetches tied to <code>useState</code> updates, along with fragile <code>isLoading</code> flags and complex state synchronization logic, TanStack Query abstracts the heavy lifting of API responses, background updates, and request deduplication into a few elegant hooks. You tell TanStack Query where to get the data, and it uses a pattern known as “stale-while-revalidate,” which means it will cache and reuse data on the front end (eliminating reload waits) and sync to the latest state in the background. </p>



<p>The catch, however, is that cache invalidation remains one of the hardest problems in computer science—and TanStack Query forces you to face it head-on. You will spend time thinking about “query keys” and deciding when a piece of data should be considered “stale.” No free lunches in software.</p>



<p>See also: <a href="https://swr.vercel.app/">SWR</a>. While TanStack Query is an absolute powerhouse for complex data manipulation, SWR remains a champion of API minimalism, doing exactly what its name implies (stale-while-revalidate) with almost zero configuration.</p>



<h2 class="wp-block-heading">Zustand: Minimalist state</h2>



<p>If you have yet to encounter the monstrosity of large-scale state management in a reactive app, then spoiler alert: it can be nasty. <a href="https://zustand.docs.pmnd.rs/learn/getting-started/introduction">Zustand</a> proposes to dispense with the ceremonial boilerplate of reducers, providers, and unwieldy context wrappers in favor of a tiny, brutally simple global store.</p>



<p>Instead of forcing your entire application tree into a massive React context provider (sometimes leading to cascades of superfluous re-renders across the DOM), Zustand uses custom hooks to tie state directly to the specific components that need it. Zustand strives to achieve the specificity in the VDOM reactive model (instead of eliminating it entirely a la <a href="https://www.infoworld.com/article/4129648/reactive-state-management-with-javascript-signals.html">Signals</a>).</p>



<p>You define a store, you call it, and the reactivity just works. It is an expression of the KISS philosophy applied to front-end architecture, scraping away the intricacies of Flux-like patterns. The trade-off for this liberation is the burden of discipline. Because Zustand is unopinionated, it won’t stop you from turning your global store into a cluttered junk drawer. You’ll need to impose your own conventions and guardrails to keep a large-scale project manageable.</p>



<p>See also: <a href="https://jotai.org/" data-type="link" data-id="https://jotai.org/">Jotai</a>. If Zustand is the unbloated global store, Jotai is the unbloated atomic approach. Jotai manages state from the bottom up, calculating changes with surgical precision without triggering massive re-renders across the application tree.</p>



<h2 class="wp-block-heading">New directions in web development</h2>



<p>The most remarkable thing about these eight tools is that they deal in large part with alternative approaches that challenge the familiar. Although you may not be able to adopt them immediately, you will want to keep an eye on them. They are key factors that will continue to influence the shape of web applications and how we build them.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ILSpy 9.0]]></title>
<description><![CDATA[ILSpy 9.x is based on .NET 8.0. All artifacts except the self-contained distribution are built framework-dependent, which means .NET 8.0.x or later must be installed prior to starting ILSpy.
Generic themes of this release were refactoring the old WPF code base and moving away from platform-depend...]]></description>
<link>https://tsecurity.de/de/3582635/it-security-tools/ilspy-90/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3582635/it-security-tools/ilspy-90/</guid>
<pubDate>Mon, 08 Jun 2026 21:19:02 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>ILSpy 9.x is based on .NET 8.0. All artifacts <strong>except</strong> the self-contained distribution are built framework-dependent, which means <a href="https://dotnet.microsoft.com/en-us/download/dotnet/8.0" rel="nofollow">.NET 8.0.x or later</a> must be installed prior to starting ILSpy.</p>
<p>Generic themes of this release were refactoring the old WPF code base and moving away from platform-dependent implementations to make reuse easier via our ILSpyX package.</p>
<p>A few notable picks from the "What's new" department for you to check out: WebCIL and standalone ECMA-335 metadata support, as well as diagramming (either via ilspycmd or assembly context menu). And in general quality-of-life improvements like the ability to disable automatic assembly loading, performance improvements via DATAS and future-proofing for .NET 10.</p>
<h1>New Language Features</h1>
<ul>
<li>Add support for C# 12 primary constructors.</li>
<li>Add support for C# 12 'ref readonly' parameters</li>
<li>Added support for switch on <code>(ReadOnly)Span&lt;char&gt;</code> using a compiler-generated hash function.</li>
<li>Added new <code>a.GetValueOrDefault(b) -&gt; a ?? b</code> transform for side-effect-free default values.</li>
<li>Support types that provide DisposeAsync without implementing IAsyncDisposable.</li>
<li>Updated pattern detection to Roslyn 4.12</li>
</ul>
<h1>Enhancements</h1>
<ul>
<li>Added support for reading WebCIL assemblies (IL embedded in WASM) (see <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2204384363" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3184" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3184/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3184">#3184</a>)</li>
<li>Added support for reading standalone ECMA-335 metadata (portable PDB and other metadata blobs) (see <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2061163292" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3149" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3149/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3149">#3149</a>)</li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1995962610" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3118" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3118/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3118">#3118</a>: Add "Clear assembly list" menu item.</li>
<li><a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1574763001" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/2893" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/2893/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/2893">#2893</a>: Add option to disable automatic assembly loading.</li>
<li>Allow implicit conversions in switch</li>
<li>IL output: Add indentation level to make it easier to see custom attributes belonging to interface implementations.</li>
<li>IL output: Print metadata token of custom attribute.</li>
<li>Replace native interop CommandLineToArgvW with parsing in Process.Unix.cs from System.Diagnostics.Process <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2267420136" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3201" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3201/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3201">#3201</a></li>
<li>Natural Sort without interop <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2243620298" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3196" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3196/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3196">#3196</a></li>
<li>AOT and x-plat changes <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2269160759" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3203" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3203/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3203">#3203</a></li>
<li>Allow running tests on ARM64 (see <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2403206895" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3231" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3231/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3231">#3231</a>)</li>
<li>Alow collecting analyzers annotated with <code>ExportAnalyzerAttribute</code> (see <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2420122647" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3239" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3239/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3239">#3239</a>)</li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2418519616" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3237" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3237/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3237">#3237</a>: Use ref readonly locals for <code>readonly.ldelema</code></li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1748803724" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3001" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3001/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3001">#3001</a>: Support new resources format in ResourcesFile/ResXResourceWriter</li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2022768109" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3134" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3134/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3134">#3134</a>: Include <code>newobj</code>, <code>initobj</code> and <code>call</code> instructions in <code>TypeInstantiatedByAnalyzer</code></li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1910610165" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3089" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3089/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3089">#3089</a>: Add comment regarding .constraint prefix expressed as cast in C#</li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2792200427" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3372" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3372/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3372">#3372</a>: Fix loading a DLL that contains byte sequences matching ZIP central directory</li>
<li>Use Microsoft.Sbom.Targets in NuGets <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2718494465" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3346" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3346/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3346">#3346</a></li>
</ul>
<h1>Contributions</h1>
<ul>
<li><a href="https://github.com/icsharpcode/ILSpy/wiki/Diagramming">Diagramming</a> feature by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/h0lg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/h0lg">@h0lg</a> (see <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2642551760" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3324" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3324/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3324">#3324</a>)</li>
<li>Various WPF-related refactorings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tom-englert/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tom-englert">@tom-englert</a> (see <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2459639214" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3257" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3257/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3257">#3257</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2478027220" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3266" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3266/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3266">#3266</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2501989801" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3274" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3274/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3274">#3274</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2540438078" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3283" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3283/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3283">#3283</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2542205149" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3285" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3285/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3285">#3285</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2552132107" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3291" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3291/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3291">#3291</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2552907396" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3292" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3292/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3292">#3292</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2554108972" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3294" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3294/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3294">#3294</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2554131413" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3295" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3295/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3295">#3295</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2566649422" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3297" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3297/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3297">#3297</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2568578632" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3298" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3298/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3298">#3298</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2568630108" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3299" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3299/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3299">#3299</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2578907752" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3302" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3302/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3302">#3302</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2599270610" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3308" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3308/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3308">#3308</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2616668330" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3314" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3314/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3314">#3314</a>, <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2647310681" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3325" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3325/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3325">#3325</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2665654262" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3335" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3335/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3335">#3335</a>)</li>
<li>High DPI fixes by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/CreateAndInject/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/CreateAndInject">@CreateAndInject</a> (see <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2725488309" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3348" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3348/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3348">#3348</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2744777945" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3350" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3350/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3350">#3350</a>)</li>
<li>TreeView: Add referenced types, members and exported types under references (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1928319534" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3092" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3092/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3092">#3092</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/fowl2/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/fowl2">@fowl2</a>)</li>
<li>Adjust colors of AvalonEdit built-in highlightings for dark themes (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2044916470" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3138" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3138/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3138">#3138</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ltrzesniewski/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ltrzesniewski">@ltrzesniewski</a>)</li>
<li>Add support for <code>Mono C# compiler 2.6.4</code> pinned region with array variable (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1977493862" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3110" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3110/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3110">#3110</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ElektroKill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ElektroKill">@ElektroKill</a>)</li>
<li>Add smooth scrolling to settings panels and DecompilerTextView (see <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2433475189" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3244" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3244/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3244">#3244</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tom-englert/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tom-englert">@tom-englert</a>)</li>
<li>Ignore empty version directories of dotnet (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2472757410" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3265" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3265/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3265">#3265</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Herrmel/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Herrmel">@Herrmel</a>)</li>
<li>Missing DecompilerSettings by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/naratteu/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/naratteu">@naratteu</a> (see <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2764918863" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3356" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3356/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3356">#3356</a>)</li>
<li>Fix metadata display of <code>DynamicLocalVariable</code> and <code>DefaultNamespace</code> custom debug information (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1979991239" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3111" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3111/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3111">#3111</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ElektroKill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ElektroKill">@ElektroKill</a>)</li>
<li>Read and use tuple element names and dynamic type information from PDBs (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1982196071" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3114" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3114/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3114">#3114</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/ElektroKill/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/ElektroKill">@ElektroKill</a>)</li>
<li>Bugfix: infinite loop in <code>DetermineEffectiveAccessibility</code> (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2135438142" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3164" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3164/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3164">#3164</a>, <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/yzdeveloper/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/yzdeveloper">@yzdeveloper</a>)</li>
<li>Decompiler Settings: Checkbox in group header does not reflect state of the group (see <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2446364743" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3252" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3252/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3252">#3252</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/tom-englert/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/tom-englert">@tom-englert</a>)</li>
<li>Fix Derived Types Node always being empty (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2539265446" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3280" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3280/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3280">#3280</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Applesauce314/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/Applesauce314">@Applesauce314</a>)</li>
</ul>
<h1>Performance</h1>
<ul>
<li>Activate Dynamic Adaptation To Application Sizes (DATAS) (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2000830581" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3122" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3122/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3122">#3122</a>).</li>
<li>RDP hardware acceleration (<a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2000830581" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3122" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3122/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3122">#3122</a>): Enabling hardware acceleration for Remote Desktop Protocol (RDP) to boost performance.</li>
<li>Performance: Initialize ToolPanes in <code>DockWorkspace.InitializeLayout()</code> instead of the property getter to avoid WPF seeing them in <code>InitializeComponent()</code> and rendering all panes docked at the right before the layout is properly initialized.</li>
</ul>
<h1>Breaking Changes</h1>
<ul>
<li>ICSharpCode.Decompiler: Added <code>MetadataFile</code> base class for <code>PEFile</code></li>
<li>ICSharpCode.Decompiler: <code>IModule.PEFile</code> is now named <code>IModule.MetadataFile</code></li>
<li>ICSharpCode.Decompiler/ILSpyX: Added <code>IFileLoader</code> API to allow for easier extensibility of supported file formats (see <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2216851618" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3191" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3191/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3191">#3191</a>)</li>
<li>ILSpy: Split BAML decompiler into library and add-in (see <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2192742726" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3178" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3178/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3178">#3178</a>)</li>
<li>ILSpy/ILSpyX: Moved non-UI analyzer API to ILSpyX (see <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2214959706" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3186" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3186/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3186">#3186</a>)</li>
<li>ICSharpCode.Decompiler: <code>IProjectFileWriter</code> and <code>IProjectInfoProvider</code> APIs are now public (see <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2061798282" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3151" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3151/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3151">#3151</a> and <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2216851618" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3191" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3191/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3191">#3191</a>)</li>
<li><code>@file</code> support with breaking changes to command line options <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2278186895" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3205" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3205/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3205">#3205</a></li>
<li>New single instance handling <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2317630357" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3212" data-hovercard-type="pull_request" data-hovercard-url="/icsharpcode/ILSpy/pull/3212/hovercard" href="https://github.com/icsharpcode/ILSpy/pull/3212">#3212</a></li>
<li>Remove <code>IsRef</code>, <code>IsOut</code> and <code>IsIn</code> flags from <code>IParameter</code></li>
<li>Replace <code>ParameterModifiers</code> with <code>ReferenceKind</code>.</li>
</ul>
<h1>Bug fixes</h1>
<ul>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1873293639" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3072" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3072/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3072">#3072</a>: Ignoring resources with the same name as a namespace.</li>
<li>Fix bug in <code>UnknownType</code>: Ensuring that the FullName of nested unknown types contains the outer type name(s), not just the namespace and nested type name.</li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2073393861" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3153" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3153/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3153">#3153</a>: Always using SHA1 for public key tokens.</li>
<li>Fix ILSpy for ZIP files/VSIX with bundle signatures: Enabling ILSpy to open ZIP files and VSIX packages containing bundle signatures.</li>
<li>Omit package entries from the treeview that denote the directory.</li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2054048190" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3142" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3142/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3142">#3142</a>: Exception when analyzing source of library with global assembly attributes</li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1982099939" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3113" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3113/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3113">#3113</a>: Remove GetAlternativeName and instead reuse existing names, if there are no conflicts.</li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2247347374" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3197" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3197/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3197">#3197</a>: Bug when trying to read a bundle/archive file</li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2216447886" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3189" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3189/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3189">#3189</a>: Support primitive types in Expression.Constant(object) pattern in Expression Trees</li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2293398964" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3209" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3209/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3209">#3209</a>: Ensure using directives are added for extension methods in higher level patterns such as: foreach -&gt; <code>GetEnumerator()</code>, collection initializer -&gt; <code>Add()</code> and deconstruction -&gt; <code>Deconstruct()</code>.</li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2457227113" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3255" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3255/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3255">#3255</a>: Ignore exceptions while decoding sequence point blobs.</li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="704993580" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/2166" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/2166/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/2166">#2166</a>: Unnecessary uint casts/conversions for certain bitwise operations</li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2608512672" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3310" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3310/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3310">#3310</a>: Filter out copy-constructor only if it's an actual record type.</li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2629145697" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3319" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3319/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3319">#3319</a>: KeyDownEvent field reference was replaced with KeyDown event reference.</li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2737107393" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3349" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3349/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3349">#3349</a>: Make ILSpy ready for .NET 10</li>
<li>Fix <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="2768351497" data-permission-text="Title is private" data-url="https://github.com/icsharpcode/ILSpy/issues/3361" data-hovercard-type="issue" data-hovercard-url="/icsharpcode/ILSpy/issues/3361/hovercard" href="https://github.com/icsharpcode/ILSpy/issues/3361">#3361</a>: switch-value conversion was losing its target type.</li>
</ul>
<p>And many other fixes, for a full list click <a href="https://github.com/icsharpcode/ILSpy/compare/v8.2...v9.0">here</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[v0.163.0]]></title>
<description><![CDATA[Improvements

resources/jsconfig: Remove deprecated baseUrl setting ff2903a @bep #14991 #14996
all: Adjust tests for deprecated link and image render hook settings ca68936 @jmooring
all: Run go fix ./... 781fabf @bep
pagesfromdata: Use relative path for content adapter template metrics 1d018ef @a...]]></description>
<link>https://tsecurity.de/de/3581800/downloads/v01630/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581800/downloads/v01630/</guid>
<pubDate>Mon, 08 Jun 2026 16:46:31 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Improvements</h2>
<ul>
<li>resources/jsconfig: Remove deprecated baseUrl setting <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/ff2903a9317ba45a65f9963f837c66cc6bce3c0e/hovercard" href="https://github.com/gohugoio/hugo/commit/ff2903a9317ba45a65f9963f837c66cc6bce3c0e"><tt>ff2903a</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4590563931" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14991" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14991/hovercard" href="https://github.com/gohugoio/hugo/issues/14991">#14991</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4591979030" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14996" data-hovercard-type="pull_request" data-hovercard-url="/gohugoio/hugo/pull/14996/hovercard" href="https://github.com/gohugoio/hugo/pull/14996">#14996</a></li>
<li>all: Adjust tests for deprecated link and image render hook settings <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/ca68936d61b4cf0c1d3a45f5d4eb0a564a3c78ef/hovercard" href="https://github.com/gohugoio/hugo/commit/ca68936d61b4cf0c1d3a45f5d4eb0a564a3c78ef"><tt>ca68936</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmooring/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmooring">@jmooring</a></li>
<li>all: Run go fix ./... <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/781fabf4e406aae6b888d4f9f68331e7f13e89aa/hovercard" href="https://github.com/gohugoio/hugo/commit/781fabf4e406aae6b888d4f9f68331e7f13e89aa"><tt>781fabf</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a></li>
<li>pagesfromdata: Use relative path for content adapter template metrics <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/1d018ef8573e1cbeca6c05b6df0792cb5f672541/hovercard" href="https://github.com/gohugoio/hugo/commit/1d018ef8573e1cbeca6c05b6df0792cb5f672541"><tt>1d018ef</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/anupamojha-eng/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/anupamojha-eng">@anupamojha-eng</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4602160535" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14999" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14999/hovercard" href="https://github.com/gohugoio/hugo/issues/14999">#14999</a></li>
<li>ci: Re-add macos-latest to the test matrix <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/121bc6ceb232effd98a85a5fec357181be8ff01e/hovercard" href="https://github.com/gohugoio/hugo/commit/121bc6ceb232effd98a85a5fec357181be8ff01e"><tt>121bc6c</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a></li>
<li>images: Deprecate Imaging.Compression and move it down to webp and avif configs <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/cf18b827e2bebe95f87b36bff9937218348a55ca/hovercard" href="https://github.com/gohugoio/hugo/commit/cf18b827e2bebe95f87b36bff9937218348a55ca"><tt>cf18b82</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4598625710" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14998" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14998/hovercard" href="https://github.com/gohugoio/hugo/issues/14998">#14998</a></li>
<li>Only support the latest Go version <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/98ad9b3c03278d0af3ebd13f8ec9fc1a71d46745/hovercard" href="https://github.com/gohugoio/hugo/commit/98ad9b3c03278d0af3ebd13f8ec9fc1a71d46745"><tt>98ad9b3</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4595941848" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14997" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14997/hovercard" href="https://github.com/gohugoio/hugo/issues/14997">#14997</a></li>
<li>page: Add IsBranch and deprecate IsNode <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/b89e7fe675457e2ca54548d57958df7d2cd8658c/hovercard" href="https://github.com/gohugoio/hugo/commit/b89e7fe675457e2ca54548d57958df7d2cd8658c"><tt>b89e7fe</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="1949125590" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/11574" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/11574/hovercard" href="https://github.com/gohugoio/hugo/issues/11574">#11574</a></li>
<li>images: Force cache invalidation for AVIF target <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/e8fefc8388e2f8c03f441a4f3d9c658edba90d00/hovercard" href="https://github.com/gohugoio/hugo/commit/e8fefc8388e2f8c03f441a4f3d9c658edba90d00"><tt>e8fefc8</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4589577076" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14990" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14990/hovercard" href="https://github.com/gohugoio/hugo/issues/14990">#14990</a></li>
<li>images: Add a per-format AVIF hint setting <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/a043d3ec6323d9eb97db128c9fc710612708fa7a/hovercard" href="https://github.com/gohugoio/hugo/commit/a043d3ec6323d9eb97db128c9fc710612708fa7a"><tt>a043d3e</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4590662849" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14992" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14992/hovercard" href="https://github.com/gohugoio/hugo/issues/14992">#14992</a></li>
<li>images: Make AVIF chroma subsampling content-aware via the hint <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/341f575d2db6abce3e9fbce871b9251f649e6e14/hovercard" href="https://github.com/gohugoio/hugo/commit/341f575d2db6abce3e9fbce871b9251f649e6e14"><tt>341f575</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4587656335" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14987" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14987/hovercard" href="https://github.com/gohugoio/hugo/issues/14987">#14987</a></li>
<li>Cap AVIF lossy quality at 99 <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/248241b6e18ecf0d9cb2706419952ae933ad78d8/hovercard" href="https://github.com/gohugoio/hugo/commit/248241b6e18ecf0d9cb2706419952ae933ad78d8"><tt>248241b</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4566435184" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14981" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14981/hovercard" href="https://github.com/gohugoio/hugo/issues/14981">#14981</a></li>
<li>config: Deprecate the glogal imaging quality setting <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/4e47d95db97292c46553c14af646873666f3a56b/hovercard" href="https://github.com/gohugoio/hugo/commit/4e47d95db97292c46553c14af646873666f3a56b"><tt>4e47d95</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565517391" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14979" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14979/hovercard" href="https://github.com/gohugoio/hugo/issues/14979">#14979</a></li>
<li>images: Make 60 the default quality for AVIF <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/03b4b54220d03716396df254d69a88a8a0b066a6/hovercard" href="https://github.com/gohugoio/hugo/commit/03b4b54220d03716396df254d69a88a8a0b066a6"><tt>03b4b54</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4565517391" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14979" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14979/hovercard" href="https://github.com/gohugoio/hugo/issues/14979">#14979</a></li>
<li>livereload: Disconnect from websocket server on pageswap <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/79be0532f1243f2e52b46c5ba0148880947be143/hovercard" href="https://github.com/gohugoio/hugo/commit/79be0532f1243f2e52b46c5ba0148880947be143"><tt>79be053</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4572172768" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14983" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14983/hovercard" href="https://github.com/gohugoio/hugo/issues/14983">#14983</a></li>
<li>tpl/tplimpl/embedded: Prevent leading newline in sitemap template <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/0f440460c861d3576579bf4074069b4045e7ddce/hovercard" href="https://github.com/gohugoio/hugo/commit/0f440460c861d3576579bf4074069b4045e7ddce"><tt>0f44046</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4562698047" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14977" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14977/hovercard" href="https://github.com/gohugoio/hugo/issues/14977">#14977</a></li>
<li>images: Recover from memory alloc errors in WASM image processors <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/4e17421ec25fb067b22cafaff15785e1d52c04f3/hovercard" href="https://github.com/gohugoio/hugo/commit/4e17421ec25fb067b22cafaff15785e1d52c04f3"><tt>4e17421</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4582444694" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14985" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14985/hovercard" href="https://github.com/gohugoio/hugo/issues/14985">#14985</a></li>
<li>images: Add quality setting per image format <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/b01ecd4cd4377921efe427fed8a16326b85f2ace/hovercard" href="https://github.com/gohugoio/hugo/commit/b01ecd4cd4377921efe427fed8a16326b85f2ace"><tt>b01ecd4</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4534244824" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14957" data-hovercard-type="issue" data-hovercard-url="/gohugoio/hugo/issues/14957/hovercard" href="https://github.com/gohugoio/hugo/issues/14957">#14957</a></li>
<li>misc: Remove duplicate words in comments <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/45c00b7c162b55ca9bcdd9a664bcf1294aa5d266/hovercard" href="https://github.com/gohugoio/hugo/commit/45c00b7c162b55ca9bcdd9a664bcf1294aa5d266"><tt>45c00b7</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/jmooring/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/jmooring">@jmooring</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4511708817" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14936" data-hovercard-type="pull_request" data-hovercard-url="/gohugoio/hugo/pull/14936/hovercard" href="https://github.com/gohugoio/hugo/pull/14936">#14936</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4530465237" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14950" data-hovercard-type="pull_request" data-hovercard-url="/gohugoio/hugo/pull/14950/hovercard" href="https://github.com/gohugoio/hugo/pull/14950">#14950</a> <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4542402306" data-permission-text="Title is private" data-url="https://github.com/gohugoio/hugo/issues/14965" data-hovercard-type="pull_request" data-hovercard-url="/gohugoio/hugo/pull/14965/hovercard" href="https://github.com/gohugoio/hugo/pull/14965">#14965</a></li>
<li>Add some PNG to AVIF golden test cases <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/28d882ab704e5060687a61210ae20b0027595705/hovercard" href="https://github.com/gohugoio/hugo/commit/28d882ab704e5060687a61210ae20b0027595705"><tt>28d882a</tt></a> <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/bep/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/bep">@bep</a></li>
</ul>
<h2>Dependency Updates</h2>
<ul>
<li>build(deps): bump github.com/bits-and-blooms/bitset <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/0d29fc81bb559750644bc163ec67f21f3c36ed1b/hovercard" href="https://github.com/gohugoio/hugo/commit/0d29fc81bb559750644bc163ec67f21f3c36ed1b"><tt>0d29fc8</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
<li>build(deps): bump github.com/tetratelabs/wazero <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/bb57404f3d93cd588e98f34c742b8b7c2741a4c7/hovercard" href="https://github.com/gohugoio/hugo/commit/bb57404f3d93cd588e98f34c742b8b7c2741a4c7"><tt>bb57404</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
<li>build(deps): bump github.com/rogpeppe/go-internal from 1.14.1 to 1.15.0 <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/7d1b1fb33dd7bdbb0d16dde9509ce15d93f7d894/hovercard" href="https://github.com/gohugoio/hugo/commit/7d1b1fb33dd7bdbb0d16dde9509ce15d93f7d894"><tt>7d1b1fb</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
<li>build(deps): bump github.com/getkin/kin-openapi from 0.138.0 to 0.139.0 <a class="commit-link" data-hovercard-type="commit" data-hovercard-url="https://github.com/gohugoio/hugo/commit/77a1147056b465f0bb87f9293b63a7ac5b81ab9e/hovercard" href="https://github.com/gohugoio/hugo/commit/77a1147056b465f0bb87f9293b63a7ac5b81ab9e"><tt>77a1147</tt></a> <a class="user-mention notranslate" data-hovercard-type="organization" data-hovercard-url="/orgs/dependabot/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://github.com/dependabot">@dependabot</a>[bot]</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vibe-Coding-Tools – 19 empfehlenswerte Optionen]]></title>
<description><![CDATA[Vibe-Coding-Tools können dazu beitragen, die App-Entwicklung zu demokratisieren.BalanceFormCreative | shutterstock.com



Vibe Coding verspricht zwar seit seinem Aufkommen, die Softwareentwicklung wesentlich zu beschleunigen und zu demokratisieren, ist aber – insbesondere in einem professionellen...]]></description>
<link>https://tsecurity.de/de/3568348/it-security-nachrichten/vibe-coding-tools-19-empfehlenswerte-optionen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3568348/it-security-nachrichten/vibe-coding-tools-19-empfehlenswerte-optionen/</guid>
<pubDate>Wed, 03 Jun 2026 07:23:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/BalanceFormCreative_shutterstock_2269128885_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Coding Demokratisierung 16z9" class="wp-image-4176431" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Vibe-Coding-Tools können dazu beitragen, die App-Entwicklung zu demokratisieren.</figcaption></figure><p class="imageCredit">BalanceFormCreative | shutterstock.com</p></div>



<p>Vibe Coding verspricht zwar seit <a href="https://www.computerwoche.de/article/4086780/vibe-coding-erklart.html" target="_blank">seinem Aufkommen</a>, die Softwareentwicklung wesentlich zu beschleunigen und zu demokratisieren, ist aber – insbesondere in <a href="https://www.computerwoche.de/article/4152349/so-wird-ki-zum-compiler.html" target="_blank">einem professionellen Umfeld</a> – nicht unumstritten.</p>



<p>Inzwischen sind die Tools in diesem Bereich allerdings reif genug, um die anfänglichen Versprechen auch einzulösen. Zumindest, wenn es um Prototypen oder ein Minimum Viable Product (<a href="https://www.computerwoche.de/article/2772171/5-fragen-zum-mvp.html" target="_blank">MVP</a>) geht. Nur ein paar Textanweisungen, schon entspringt der KI etwas, das früher Wochen in Anspruch genommen hätte. Ganz zu schweigen vom damit verbundenen bürokratischen Aufwand für Business-Anwender.</p>



<p>Natürlich kann es beim Vibe Coding weiterhin zu <a href="https://www.computerwoche.de/article/4034385/9-wege-mit-vibe-coding-zu-scheitern.html" target="_blank">Fehlern und Versäumnissen</a> kommen. Dabei stellt sich allerdings die Frage, ob das schlimmer ist als das, was ein menschliches Team versehentlich verbocken oder übersehen könnte, wenn es das gleiche erstellt.</p>



<p>In diesem Artikel stellen wir Ihnen in aller Kürze 19 empfehlenswerte Vibe-Coding-Tools vor.</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper youtube-video">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">Vibe coding now has an official illustrative GIF! <a href="https://t.co/dHKuJwTBzj">https://t.co/dHKuJwTBzj</a></p>— Simon Willison (@simonw) <a href="https://x.com/simonw/status/1903872293438406885?ref_src=twsrc%5Etfw">March 23, 2025</a></blockquote>
</div></figure>



<h2 class="wp-block-heading"><a href="https://base44.com/" target="_blank" rel="noreferrer noopener">Base44/Wix</a></h2>



<p>Im Fall von Base44 (inzwischen im Besitz <a href="https://www.wix.com/press-room/home/post/wix-further-expands-into-vibe-coding-with-acquisition-of-base44-a-hyper-growth-startup-that-simplif" target="_blank" rel="noreferrer noopener">von Wix</a>), beginnt mit einem „Builder Chat“, der die Datenarchitektur fokussiert. Davon ausgehend erstellt das Vibe-Coding-Tool auf Basis natürlichsprachlicher Anweisungen React- und Tailwind-Code für das Frontend, die in einem Deno-Backend zusammengeführt werden.</p>



<p>Um den Entwicklungsprozess zusätzlich zu beschleunigen, stehen diverse Templates für gängige Anwendungsfälle zur Verfügung, etwa in den Bereichen E-Commerce, Content-Management und Produktivität. Die <a href="https://www.computerwoche.de/article/3990415/wird-ki-das-neue-ui.html" target="_blank">Benutzeroberfläche</a> dieser Lösung lässt sich dabei über einen visuellen Editor im Drag-und-Drop-Verfahren anpassen.</p>



<h2 class="wp-block-heading"><a href="https://www.bettyblocks.com/" target="_blank" rel="noreferrer noopener">Betty Blocks</a></h2>



<p>Die Macher hinter der <a href="https://www.computerwoche.de/article/2802722/was-sie-ueber-no-code-plattformen-wissen-muessen.html" target="_blank">No-Code-Lösung</a> Betty Blocks wollen in erster Linie „Citizen Developer“ ansprechen – also Nicht-Programmierer, die jedoch wissen, welche Art von Anwendung ihr Fachbereich benötigt.</p>



<p>Aus der natürlichsprachlichen Beschreibung dieser Applikation erzeugt die Betty-Blocks-Plattform <a href="https://www.computerwoche.de/article/4144312/react-ein-tutorial.html" target="_blank">React-Code</a>. Dieser wird zur „Weiterverarbeitung“ in ein Code Repository exportiert – kann jedoch auch für zukünftige Deployment-Zwecke auf <a href="https://www.computerwoche.de/article/3968392/6-webassembly-fahige-sprachen.html" target="_blank">WASM</a>-Ebene kompiliert werden. Darüber hinaus bietet die Lösung auch einen Low-Code-Ansatz an, der eine visuelle Oberfläche für weitere Anpassungen und Verfeinerungen bereitstellt.</p>



<h2 class="wp-block-heading"><a href="https://blink.new/" target="_blank" rel="noreferrer noopener">Blink</a></h2>



<p>Der Code-Agent von Blink erstellt TypeScript-React-Anwendungen und bietet zwei Modi: den Agent-Modus (zum Erstellen) und den Chat-Modus (zum Planen).</p>



<p>Blink hostet jede Anwendung über sein internes <a href="https://www.computerwoche.de/article/2750121/was-sie-ueber-content-delivery-networks-wissen-muessen.html" target="_blank">Content Delivery Network</a>, ermöglicht es aber auch, diese auf eigene Server oder in die Cloud zu exportieren.</p>



<h2 class="wp-block-heading"><a href="https://bolt.new/" target="_blank" rel="noreferrer noopener">Bolt</a></h2>



<p>Der No-Code-Service von Bolt wurde mit dem Ziel entwickelt, ein singuläres visuelles Interface zu verschiedenen Backend-Coding-KIs bereitzustellen. Entsprechend ist es möglich, mit diversen verschiedenen Agenten zu arbeiten, darunter etwa Claude und Gemini.  </p>



<p>Weil das Tool über einen eigenständigen Design-Layer verfügt, lassen sich Standard-Designs erstellen, die dann von jeder App genutzt werden können, die die KI erzeugt. Bolt steht zudem als <a href="https://github.com/stackblitz/bolt.new" target="_blank" rel="noreferrer noopener">Open-Source-Version</a> zur Verfügung, die unter der MIT-Lizenz veröffentlicht wurde.</p>



<h2 class="wp-block-heading"><a href="http://bubble.io/" target="_blank" rel="noreferrer noopener">Bubble</a></h2>



<p>Auch bei Bubble handelt es sich um ein No-Code-Tool. Dieses umfasst verschiedene Funktionen, die weit über einen bloßen Chat hinausgehen. Ein visueller Editor ist ebenfalls mit an Bord, um die Benutzeroberfläche schnell und einfach auf die eigenen Bedürfnisse anzupassen.</p>



<p>Eine Workflow-Ansicht verschafft zudem Überblick über vieles, was im Hintergrund abläuft – und schafft damit Transparenz für die Benutzer. Die Zielsetzung dieses Tools besteht darin, den Menschen stärker als <a href="https://www.computerwoche.de/article/4086726/der-wahre-hebel-fur-ki-ist-der-mensch.html" target="_blank">Partner der KI</a> einzubinden.</p>



<h2 class="wp-block-heading"><a href="https://claude.com/product/claude-code" target="_blank" rel="noreferrer noopener">Claude Code</a></h2>



<p>Anthropics Vorzeige-LLM <a href="https://www.computerwoche.de/article/4141035/claude-code-im-praxistest.html" target="_blank">Claude</a> kann diverse Programmieraufgaben übernehmen – beispielsweise neue Applikationen erstellen oder alte reparieren. Das Backend lässt sich mit vielen traditionellen IDEs wie <a href="https://www.computerwoche.de/article/4123522/visual-studio-code-langweilig-aber-noch-on-top.html" target="_blank">Visual Studio Code</a> verbinden – oder auch mit einem Slack-Kanal.</p>



<p>Eine populärer Anwendungsfall für Claude Code ist, große Codebasen zu durchsuchen, um Probleme zu finden und zu beheben. Anwender loben außerdem, dass sich Claude sehr gut auf lokale Codierungsstandards ausrichten lässt.</p>



<h2 class="wp-block-heading"><a href="https://github.com/continuedev/continue" target="_blank" rel="noreferrer noopener">Continue</a></h2>



<p>Der quelloffene KI-Agent von Continue eignet sich am besten für <a href="https://www.computerwoche.de/article/4133885/darum-werden-ihre-besten-entwickler-langsamer.html" target="_blank">professionelle Entwickler</a>, die bei ihrer Arbeit zusätzliche Unterstützung wünschen. Das Tool überwacht Codebasen auf spezifische Trigger, beispielsweise neue Pull-Releases – und schaltet dann KI-Agenten ein, um diverse Routineaufgaben zu erledigen.</p>



<p>Die Zielsetzung bei diesem Tool besteht darin, menschlichen Profis die langweiligsten Tasks zu ersparen, damit diese sich darauf konzentrieren können, kreativ zu sein. Continue lässt sich in diverse IDEs und <a href="https://www.computerwoche.de/article/4004872/die-besten-apis-um-ki-zu-integrieren.html" target="_blank">KI-APIs</a> integrieren.</p>



<h2 class="wp-block-heading"><a href="http://create.xyz/" target="_blank" rel="noreferrer noopener">Create.xyz</a></h2>



<p>Das Tool von Create.xyz heißt “Anything” und soll jede erdenkliche React/Tailwind-App aus einem simplen Text-<a href="https://www.computerwoche.de/article/4042963/5-tipps-um-besser-zu-prompten.html" target="_blank">Prompt</a> erstellen können.</p>



<p>Die Ergebnisse werden aus vielen stilisierten Komponenten für Tasks, die sowohl im Browser als auch auf mobilen Plattformen gut laufen (etwa <a href="https://www.computerwoche.de/article/3497295/datenbank-how-to-fur-app-entwickler.html" target="_blank">Datenbankzugriff</a>) generiert. Entwickler können sich dann tiefgehend mit dem Code auseinandersetzen und persönliche Akzente setzen.</p>



<h2 class="wp-block-heading"><a href="https://cursor.com/" target="_blank" rel="noreferrer noopener">Cursor</a></h2>



<p>Vor allem Entwickler der alten Schule finden häufig Gefallen an Cursor. Dieses Tool generiert neuen Code, überprüft alten und trackt entstehende Probleme – zum Beispiel über <a href="https://www.computerwoche.de/article/3842841/7-slack-apps-fur-teamarbeiter.html" target="_blank">Slack</a>.</p>



<p>Zudem ist diese Lösung in der Lage, mehrere Dateien gleichzeitig zu bearbeiten und komplette Codebasen zu analysieren, bevor sie einen Aktionsplan vorschlägt. Cursor ist vor allem für den Einsatz in traditionellen Entwicklungsumgebungen konzipiert.</p>



<h2 class="wp-block-heading"><a href="http://emergent.sh/" target="_blank" rel="noreferrer noopener">Emergent</a></h2>



<p>Die Webanwendung von Emergent ist ein Frontend für <a href="https://www.computerwoche.de/article/4157192/multi-agenten-systeme-die-neuen-microservices.html" target="_blank">KI-Agenten-Teams</a>. Aus einer einfachen Text-Beschreibung entsteht ein Frontend (React), ein Backend (Node.js), Datenbanken (<a href="https://www.computerwoche.de/article/4128783/4-self-contained-datenbanken-fur-entwickler.html" target="_blank">MongoDB</a>) sowie eine Sammlung von APIs mit vollständiger Integration (Stripe und Co.).</p>



<p>Die Zielsetzung ist es, die gesamte Development-Komplexität zu abstrahieren. Das soll Nicht-Entwicklern ermöglichen, alles zu erstellen, was sie wollen. Entwickler können es beispielsweise für  Prototypen nutzen – die <a href="https://www.computerwoche.de/article/4124442/ki-prototypen-in-die-produktion-uberfuhren-so-gehts.html" target="_blank">nahezu produktionsreif</a> sind.</p>



<h2 class="wp-block-heading"><a href="https://kilo.ai/" target="_blank" rel="noreferrer noopener">Kilo Code</a></h2>



<p>Der Open-Source-Agent von Kilo verfügt über eine Reihe von Funktionen, die für Programmierer interessant sind. Insbesondere solche, die regelmäßig größere Codebasen <a href="https://www.computerwoche.de/article/2824308/so-entwickeln-sie-besser.html" target="_blank">pflegen und erweitern</a>. Der Orchestrator-Modus hilft beispielsweise dabei, Arbeitspläne zu erstellen, die Code-Review-Funktion überprüft auf Fehler.</p>



<p>Eine Memory Bank speichert dabei übergeordnete Details zur Architektur des Projekts. Durch die Anbindung an mehr als 500 KI-Modelle dürften Anwender keine Probleme damit haben, <a href="https://www.computerwoche.de/article/4155050/25-fragen-die-zum-richtigen-llm-fuhren.html" target="_blank">das richtige für ihre Zwecke</a> zu integrieren. Zudem wird so die Bindung an einen (LLM-)Anbieter vermieden.</p>



<h2 class="wp-block-heading"><a href="https://www.lindy.ai/" target="_blank" rel="noreferrer noopener">Lindy</a></h2>



<p>Das Tool von Lindy ist darauf ausgelegt, „Agenten“ zu erstellen, bei denen es sich in der Regel um Code-Schnipsel handelt, die im Hintergrund arbeiten. Diese reagieren auf bestimmte Trigger wie eine Slack-Nachricht oder einen neuen Commit in einem Repository.</p>



<p>Diese Events lassen sich durch Hunderte verschiedene Webanwendungen auslösen, darunter auch die aller großen Cloud-Anbieter und Office-Organisationsplattformen wie Jira oder Zoho. Standardanwendungen lassen sich mit Lindy zudem über vordefinierte Templates noch schneller erstellen. Ein gängiger Anwendungsfall für dieses Tool ist beispielsweise ein KI-Agent für den <a href="https://www.computerwoche.de/article/3980070/ki-tutorial-fur-bessere-helpdesks.html" target="_blank">IT-Support</a>.</p>



<h2 class="wp-block-heading"><a href="https://lovable.dev/" target="_blank" rel="noreferrer noopener">Lovable</a></h2>



<p>Die No-Code-Oberfläche von Lovable erstellt Anwendungen per Chat-Anweisung und stellt sie über die Lovable-Cloud bereit. Das Tool kümmert sich um die Benutzeroberfläche (React plus Tailwind), die Business-Logik und die Datenbank (hauptsächlich Supabase).</p>



<p>Im Ergebnis ist Lovable eines der besten Werkzeuge, um besonders schnell zu Enterprise-reifen Prototypen mit ausgefeilten <a href="https://www.computerwoche.de/article/2834420/der-niedergang-des-user-interface.html" target="_blank">Benutzeroberflächen</a> zu kommen – und diverse Sicherheits- und Zugriffskontrollfunktionen zu erstellen, die für größere Umgebungen erforderlich sind.</p>



<h2 class="wp-block-heading"><a href="https://replit.com/" target="_blank" rel="noreferrer noopener">Replit</a></h2>



<p>Die No-Code-Lösung von Replit liefert Code in bis zu 30 <a href="https://www.computerwoche.de/article/2820140/8-sprachen-die-programmierer-zur-weissglut-treiben.html" target="_blank">Programmiersprachen</a> – darunter alle gängigen und auch weniger verbreitete. Das Haupt-Interface ist ein No-Code-Chatbot, anschließend wird der Code jedoch in ein Repository übertragen, wo er mit traditionellen Methoden weiter verfeinert werden kann.</p>



<p>Der Datenbank-Layer ist bei dieser Lösung ausgegliedert. Dadurch stehen etwa Optionen wie getrennte Datenbanken für Produktion und Testing zur Verfügung. Zudem beinhaltet Replit auch Enterprise-Funktionen – zum Beispiel für Teams, die gemeinsam per Chat eine App optimieren möchten.</p>



<h2 class="wp-block-heading"><a href="https://softgen.ai/" target="_blank" rel="noreferrer noopener">Softgen</a></h2>



<p>Das Softgen-Tool erstellt vollständige Next.js-Webanwendungen als MVP aus einfachen Textbeschreibungen und funktioniert mit den wichtigsten KI-Modellen wie Claude 4.5 oder <a href="https://www.computerwoche.de/article/4028024/gemini-cli-im-praxistest.html" target="_blank">Gemini</a>.</p>



<p>Dank einer <a href="https://softgen.ai/pricing" target="_blank" rel="noreferrer noopener">Pay-as-you-go-Option</a> bezahlen Anwender bei diesem Vibe-Coding-Tool nur für die Token, die sie für ihre Anwendung benötigen.</p>



<h2 class="wp-block-heading"><a href="https://trysolid.com/" target="_blank" rel="noreferrer noopener">Solid</a></h2>



<p>Solid legt den Schwerpunkt auf die Erstellung von“Enterprise Grade“- Apps, inklusive erstklassigen Security-Modellen und verteilter Bereitstellung.</p>



<p>Die Dokumentation betont die iterative Zusammenarbeit mit der KI und die Nutzung ihrer Stärken – nämlich ein React/Tailwind-Frontend mit einer Vielzahl von Backends zu generieren.</p>



<h2 class="wp-block-heading"><a href="https://www.tempo.new/" target="_blank" rel="noreferrer noopener">Tempo Labs</a></h2>



<p>Der visuelle Editor von Tempo Labs zielt darauf ab, menschliche Benutzer dazu zu befähigen, React-Apps schneller zu erstellen – um den Faktor Zehn. Einfache visuelle Aufgaben lassen sich dabei auch ganz <a href="https://www.computerwoche.de/article/4170715/so-integrieren-sie-ki-ohne-benutzer-zu-verprellen.html" target="_blank">ohne KI</a> ausführen.</p>



<p>Das Tool legt den Schwerpunkt auf Design und unterhält eine Bibliothek mit Standardelementen für jedes Projekt. Jede React-Codebasis kann importiert und mit vorgefertigten Komponenten und Vorlagen erweitert werden. Es ist ein Editor, der inspirieren kann.</p>



<h2 class="wp-block-heading"><a href="https://v0.app/" target="_blank" rel="noreferrer noopener">Vercel</a></h2>



<p>Die v0-Plattform von Vercel bietet eine ausgedehnte Template-Kollektion als Grundlage, um Anwendungen zu designen. Auch bei dieser Lösung ist das Haupt-Interface ein Chat-Fenster, über das sich jedes erdenkliche Design umsetzen lässt. Allerdings dienen die Templates hier sowohl als Inspiration als auch als gemeinsame Sprache, um die Spezifikationen zu verfassen.</p>



<p>Die Lösung bietet auch Designvorlagen, die die Harmonisierung verschiedener Anwendungen vereinfachen. Dazu definiert sie einmalig einen Look und verwendet diesen dann wieder. Ein Schwerpunkt liegt dabei auf mobilen Browsern, was es vereinfacht, Webseiten zu erstellen, die für Mobilgeräte optimiert sind.</p>



<h2 class="wp-block-heading"><a href="https://windsurf.com/" target="_blank" rel="noreferrer noopener">Windsurf</a></h2>



<p>Windsurf ist eine integrierte Entwicklungsumgebung mit eingebetteter KI. Sie ist darauf ausgelegt, längere mehrstufige Pläne („Cascades“) zu generieren – etwa, um <a href="https://www.computerwoche.de/article/4032752/5-tipps-fur-bessere-bug-reports.html" target="_blank">Bugs</a> zu beheben oder eine Codebasis um Funktionen zu erweitern. Anders ausgedrückt: Windsurf ermöglicht Vibe Coding, das darauf ausgerichtet ist, traditionelle Dev-Techniken zu unterstützen.</p>



<p>Die Tabulatortaste ist innerhalb der Windsurf-IDE dabei besonders leistungsstark: Bei Betätigung springt die KI von einem vorgeschlagenen Fix zum nächsten. Ihre Zustimmung signalisieren die Benutzer dabei durch einen erneuten Tab-Tastendruck. (fm)</p>



<p><strong>Dieser Artikel ist </strong><a href="https://www.cio.com/article/4165921/19-vibe-coding-tools-for-democratizing-app-development.html" target="_blank"><strong>im Original</strong></a><strong> bei unserer Schwesterpublikation CIO.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[NSDI '26 - Hierarchical Integration of WebAssembly in Serverless for Efficiency and Interoperability]]></title>
<description><![CDATA[Author: USENIX - Bewertung: 0x - Views:1 Hierarchical Integration of WebAssembly in Serverless for Efficiency and Interoperability

Mohammadamin Baqershahi, Changyuan Lin, and Visal Saosuo, University of British Columbia; Paul Chen, Huawei Technologies Canada; Mohammad Shahrad, University of Brit...]]></description>
<link>https://tsecurity.de/de/3564525/it-security-video/nsdi-26-hierarchical-integration-of-webassembly-in-serverless-for-efficiency-and-interoperability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3564525/it-security-video/nsdi-26-hierarchical-integration-of-webassembly-in-serverless-for-efficiency-and-interoperability/</guid>
<pubDate>Tue, 02 Jun 2026 01:02:56 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: USENIX - Bewertung: 0x - Views:1 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/87jUDykMtXU?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Hierarchical Integration of WebAssembly in Serverless for Efficiency and Interoperability<br />
<br />
Mohammadamin Baqershahi, Changyuan Lin, and Visal Saosuo, University of British Columbia; Paul Chen, Huawei Technologies Canada; Mohammad Shahrad, University of British Columbia<br />
<br />
Modern serverless systems suffer from low resource efficiency, which maps to high per-unit costs.<br />
This comes from the high isolation overhead (e.g., low resource sharing, slow startup, etc.), as well as resource wastage incurred by conservative resource scaling (e.g., keep-alive). Language runtimes such as WebAssembly (Wasm) can reduce isolation overhead without compromising security. Existing Wasm-based serverless approaches fall into one of these categories: supporting only Wasm workloads, failing to leverage existing capabilities of modern serverless and cloud platforms, or falling short of leveraging Wasm’s true potential. This work introduces a dense hierarchical architecture to securely co-locate Wasm-based applications from different customers within the same container sandbox. We show how this design preserves the container-based serving model, which allows leveraging existing platform capabilities and supporting non-Wasm-based workloads. Our system, Wasabi, leverages this architecture alongside resource-aware scaling, queuing, and overbooking to offer much higher density than state-of-the-art serverless systems with similar or better performance.<br />
<br />
View the full NSDI '26 program at https://www.usenix.org/conference/nsdi26/technical-sessions<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nick Fitzgerald: A Structure-Aware Fuzzing Experiment]]></title>
<description><![CDATA[Structure-aware fuzzing can better exercise the system under test (SUT) by
crafting inputs in the format expected by the SUT, rather than throwing
pseudorandom bytes against it. That is, it avoids “shallow” inputs that the SUT
will reject early (for example, syntactically invalid source text when...]]></description>
<link>https://tsecurity.de/de/3563869/tools/nick-fitzgerald-a-structure-aware-fuzzing-experiment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563869/tools/nick-fitzgerald-a-structure-aware-fuzzing-experiment/</guid>
<pubDate>Mon, 01 Jun 2026 19:24:02 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Structure-aware fuzzing can better exercise the system under test (SUT) by
crafting inputs in the format expected by the SUT, rather than throwing
pseudorandom bytes against it. That is, it avoids “shallow” inputs that the SUT
will reject early (for example, syntactically invalid source text when fuzzing a
programming language’s compiler) and only produces inputs that go “deep” into
the SUT (e.g. programs that type-check and exercise the mid-end optimizer and
backend code generator). The Rust fuzzing ecosystem is largely built around
<a href="https://github.com/rust-fuzz/cargo-fuzz"><code class="language-plaintext highlighter-rouge">cargo-fuzz</code></a> and the <a href="https://github.com/rust-fuzz/libfuzzer"><code class="language-plaintext highlighter-rouge">libfuzzer-sys</code></a> crate, which provides two methods for
structure-aware fuzzing:</p>

<ol>
  <li>
    <p><em>Generating</em> structured inputs from scratch with the <a href="https://github.com/rust-fuzz/arbitrary"><code class="language-plaintext highlighter-rouge">arbitrary</code></a> crate</p>
  </li>
  <li>
    <p><em>Mutating</em> existing inputs from the fuzzer’s corpus in a structure-aware
manner, thereby producing new structured inputs, via the
<a href="https://docs.rs/libfuzzer-sys/0.4.12/libfuzzer_sys/macro.fuzz_mutator.html"><code class="language-plaintext highlighter-rouge">fuzz_mutator!</code></a> hook</p>
  </li>
</ol>

<p>While the two methods are not technically mutually exclusive, combining the two
can be difficult and engineering resources are finite. So:</p>

<blockquote>
  <p><strong><em>If we are only implementing one approach, is generation or mutation better?</em></strong></p>
</blockquote>

<p>To help answer this question, I implemented structure-aware generation and
mutation of guaranteed-valid <a href="https://webassembly.org/">WebAssembly</a> (Wasm) instruction sequences. This
task is small enough to be easily understandable but large enough and real
enough to (hopefully) be representative and applicable to other domains, or, at
the very least, interesting.<sup><a class="footnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fn:applicable" rel="footnote">1</a></sup> To evaluate their effectiveness, I
used <a href="https://wasmtime.dev/">Wasmtime</a> as the SUT, <code class="language-plaintext highlighter-rouge">libfuzzer-sys</code> as the fuzzing engine driving
everything, and then compared code coverage over time when using mutation-based
fuzzing versus generation-based fuzzing.</p>

<p>Additionally, there are many ways we can generate pseudorandom WebAssembly
instruction sequences. In this experiment, I’ve evaluated three methods:</p>

<ol>
  <li>
    <p>Unconstrained instruction sequence generation followed by a fixup pass to
ensure validity</p>
  </li>
  <li>
    <p>Generating valid instructions in a forwards, bottom-up
manner (from operands to operators)</p>
  </li>
  <li>
    <p>Generating valid instructions in a backwards, top-down manner (from operators
to operands)</p>
  </li>
</ol>

<p>In contrast, while there are surely many ways to mutate a given WebAssembly
instruction sequence into a new, valid instruction sequence, I’ve only
implemented one method: perform an arbitrary instruction insertion, deletion, or
replacement, producing a new but probably-invalid instruction sequence, and then
run the same fixup pass mentioned previously to ensure validity. This is the
direct mutation-based equivalent of the first generation-based method.</p>

<p><em>Before continuing further, I want to disclose that I am the author of
<code class="language-plaintext highlighter-rouge">wasm-smith</code> and <code class="language-plaintext highlighter-rouge">mutatis</code>, and a maintainer of Wasmtime, <code class="language-plaintext highlighter-rouge">arbitrary</code>,
<code class="language-plaintext highlighter-rouge">libfuzzer-sys</code>, and <code class="language-plaintext highlighter-rouge">cargo-fuzz</code>. That is, while I am familiar with Wasm,
fuzzing, fuzzing Wasm, and both the <code class="language-plaintext highlighter-rouge">arbitrary</code> and <code class="language-plaintext highlighter-rouge">mutatis</code> crates, I may also
be propagating my own biases into these implementations.</em></p>

<h3>Background</h3>

<h4>Generation-Based and Mutation-Based Fuzzing</h4>

<p>A generation-based fuzzer uses a <em>generator</em> to create a pseudo-random test
cases from scratch, feeds these into the system under test, and reports any
failures to the user:</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">fn</span> <span class="n">generation_based_fuzzing</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="p">(</span>
    <span class="c1">// A test-case generator.</span>
    <span class="n">generator</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">Fn</span><span class="p">()</span> <span class="k">-&gt;</span> <span class="n">T</span><span class="p">,</span>
    <span class="c1">// A function to run the system under test with a</span>
    <span class="c1">// generated test case, returning a result that</span>
    <span class="c1">// describes whether the run was successful or</span>
    <span class="c1">// not.</span>
    <span class="n">run_system_under_test</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">Fn</span><span class="p">(</span><span class="o">&amp;</span><span class="n">T</span><span class="p">)</span> <span class="k">-&gt;</span> <span class="n">FuzzResult</span><span class="p">,</span>
<span class="p">)</span> <span class="p">{</span>
    <span class="k">loop</span> <span class="p">{</span>
        <span class="c1">// Generate an input.</span>
        <span class="k">let</span> <span class="n">input</span> <span class="o">=</span> <span class="nf">generator</span><span class="p">();</span>

        <span class="c1">// Run the input through the system under test.</span>
        <span class="k">let</span> <span class="n">result</span> <span class="o">=</span> <span class="nf">run_system_under_test</span><span class="p">(</span><span class="o">&amp;</span><span class="n">input</span><span class="p">);</span>

        <span class="c1">// If the system crashed, panicked, failed an</span>
        <span class="c1">// assertion, violated an invariant, or etc...</span>
        <span class="c1">// then report that to the user.</span>
        <span class="k">if</span> <span class="k">let</span> <span class="nf">Err</span><span class="p">(</span><span class="n">failure</span><span class="p">)</span> <span class="o">=</span> <span class="n">result</span> <span class="p">{</span>
            <span class="nf">report_to_user</span><span class="p">(</span><span class="o">&amp;</span><span class="n">input</span><span class="p">,</span> <span class="n">failure</span><span class="p">);</span>
        <span class="p">}</span>
    <span class="p">}</span>
<span class="p">}</span>
</code></pre></div></div>

<p>On the other hand, mutation-based fuzzers are given an initial corpus of inputs
and create new inputs by mutating existing corpus members. They run each new
input through the SUT, report failures the same as before, and if the new input
was “interesting” (for example, exercised new code paths in the SUT that weren’t
previously covered in any other input’s execution) then the new input is added
into the corpus for use in future test iterations:</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">fn</span> <span class="n">mutation_based_fuzzing</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="p">(</span>
    <span class="c1">// A corpus of test cases.</span>
    <span class="n">corpus</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">Corpus</span><span class="o">&lt;</span><span class="n">T</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="c1">// A function to pseudo-randomly mutate an existing</span>
    <span class="c1">// input into a new input.</span>
    <span class="n">mutate</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">Fn</span><span class="p">(</span><span class="o">&amp;</span><span class="n">T</span><span class="p">)</span> <span class="k">-&gt;</span> <span class="n">T</span><span class="p">,</span>
    <span class="c1">// A function to run an input in the system under</span>
    <span class="c1">// test, returning a result that describes whether</span>
    <span class="c1">// the run was successful or not.</span>
    <span class="n">run_system_under_test</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">Fn</span><span class="p">(</span><span class="o">&amp;</span><span class="n">T</span><span class="p">)</span> <span class="k">-&gt;</span> <span class="n">FuzzResult</span><span class="p">,</span>
<span class="p">)</span> <span class="p">{</span>
    <span class="k">loop</span> <span class="p">{</span>
        <span class="c1">// Choose an old test case from the corpus.</span>
        <span class="k">let</span> <span class="n">old_input</span> <span class="o">=</span> <span class="n">corpus</span><span class="nf">.choose_one</span><span class="p">();</span>

        <span class="c1">// Pseudo-randomly mutate that old test case,</span>
        <span class="c1">// creating a new one.</span>
        <span class="k">let</span> <span class="n">input</span> <span class="o">=</span> <span class="nf">mutate</span><span class="p">(</span><span class="n">old_input</span><span class="p">);</span>

        <span class="c1">// Run the input through the system under test.</span>
        <span class="k">let</span> <span class="n">result</span> <span class="o">=</span> <span class="nf">run_system_under_test</span><span class="p">(</span><span class="o">&amp;</span><span class="n">input</span><span class="p">);</span>

        <span class="c1">// If the system crashed, panicked, failed an</span>
        <span class="c1">// assertion, violated an invariant, or etc...</span>
        <span class="c1">// then report that to the user.</span>
        <span class="k">if</span> <span class="k">let</span> <span class="nf">Err</span><span class="p">(</span><span class="n">failure</span><span class="p">)</span> <span class="o">=</span> <span class="n">result</span> <span class="p">{</span>
            <span class="nf">report_to_user</span><span class="p">(</span><span class="o">&amp;</span><span class="n">input</span><span class="p">,</span> <span class="n">failure</span><span class="p">);</span>
        <span class="p">}</span>

        <span class="c1">// If the input was interesting, for example if</span>
        <span class="c1">// it executed previously-unknown code paths,</span>
        <span class="c1">// then add it into the corpus for use in a</span>
        <span class="c1">// future iteration.</span>
        <span class="k">if</span> <span class="n">result</span><span class="nf">.input_was_interesting</span><span class="p">()</span> <span class="p">{</span>
            <span class="n">corpus</span><span class="nf">.insert</span><span class="p">(</span><span class="n">input</span><span class="p">);</span>
        <span class="p">}</span>
    <span class="p">}</span>
<span class="p">}</span>
</code></pre></div></div>

<p>The two approaches are not mutually exclusive and hybrid generation- and
mutation-based fuzzers exist.</p>

<p>More resources:</p>

<ul>
  <li><a href="https://en.wikipedia.org/wiki/Fuzzing#Reuse_of_existing_input_seeds">Wikipedia’s “Fuzzing” article’s “Reuse of existing input seeds”
section</a></li>
  <li><a href="https://www.fuzzingbook.org/html/MutationFuzzer.html">The Fuzzing Book’s Mutation-Based Fuzzing
chapter</a></li>
  <li><a href="https://fitzgen.com/2020/08/24/writing-a-test-case-generator.html">Writing a Test Case Generator for a Programming
Language</a></li>
</ul>

<h4>Structure-Aware Fuzzing</h4>

<p>Structure-<em>unaware</em> fuzzing will generate pseudorandom byte sequences and pass
them directly to the SUT. If the SUT expects some sort of structured input,
e.g. the source text for a programming language, it is likely that these byte
sequences are invalid and will be rejected early by the SUT’s frontend. For
example, when fuzzing a compiler, the input is rejected as syntactically invalid
by the parser or rejected as semantically invalid by the type checker. This can
be useful when hardening a tokenizer, parser, or type checker, but is less
useful when hunting for misoptimization in the mid-end or bad instruction
encoding in the backend because the inputs are unlikely to make it that far
through the compiler’s pipeline.</p>

<p>Structure-<em>aware</em> fuzzing will produce inputs that match the SUT’s expected
input format. Returning to the compiler-fuzzing example, structure-aware fuzzing
lets us generate valid programs for the compiler, so we can exercise more of the
mid-end and backend, rather than just the frontend.</p>

<p>Structure-aware fuzzing is often generation-based: for example using
<a href="https://www.fuzzingbook.org/html/Grammars.html">grammar-based fuzzing</a> to generate pseudorandom strings from a given language
grammar or language-specific tools like <a href="https://github.com/csmith-project/csmith"><code class="language-plaintext highlighter-rouge">csmith</code></a> and <a href="https://docs.rs/wasm-smith"><code class="language-plaintext highlighter-rouge">wasm-smith</code></a> that
generate C and WebAssembly programs respectively. But structure-aware fuzzing
can also be mutation-based: <a href="https://github.com/llvm/llvm-project/blob/192601e8b3ad8b5f73cf27f2093fef5a8c9f4cb6/compiler-rt/test/fuzzer/CompressedTest.cpp#L33-L59"><code class="language-plaintext highlighter-rouge">libFuzzer</code>’s custom mutator
example</a>
implements a structure-aware mutator for zlib-compressed strings, where the raw
input is decompressed, the decompressed data is mutated, and then the mutated
data is recompressed to provide the new raw input. The mutator is aware of the
SUT’s zlib-compressed input structure.</p>

<p>More resources:</p>

<ul>
  <li><a href="https://en.wikipedia.org/wiki/Fuzzing#Aware_of_input_structure">Wikipedia’s “Fuzzing” article’s “Aware of input structure”
section</a></li>
  <li><a href="https://github.com/google/fuzzing/blob/master/docs/structure-aware-fuzzing.md"><code class="language-plaintext highlighter-rouge">google/fuzzing</code> on structure-aware
fuzzing</a></li>
  <li><a href="https://rust-fuzz.github.io/book/cargo-fuzz/structure-aware-fuzzing.html">The <code class="language-plaintext highlighter-rouge">rust-fuzz</code> book on structure-aware
fuzzing</a></li>
</ul>

<h4>The <code class="language-plaintext highlighter-rouge">arbitrary</code> Crate</h4>

<p>The <a href="https://github.com/rust-fuzz/arbitrary"><code class="language-plaintext highlighter-rouge">arbitrary</code></a> crate helps Rust developers write custom structure-aware
generators for fuzzing. It provides building blocks and abstractions for
translating a raw byte sequence (usually from a fuzzing engine) into a
structured type, effectively interpreting the raw bytes as a “DNA string” or set
of predetermined choices for its decision tree. The library also provides a
<code class="language-plaintext highlighter-rouge">derive(Arbitrary)</code> macro to automatically implement its functionality for a
given type.</p>

<p>Because <code class="language-plaintext highlighter-rouge">arbitrary</code> is effectively implemented by combining decision trees, it
is extremely easy to create imbalanced trees and unintentionally <a href="https://blog.regehr.org/archives/1700">bias the
distribution of generated test cases</a>.</p>

<h4>The <code class="language-plaintext highlighter-rouge">mutatis</code> Crate</h4>

<p>The <a href="https://docs.rs/mutatis"><code class="language-plaintext highlighter-rouge">mutatis</code></a> crate is, at a high-level, performing the same role for
authoring structure-aware mutators that <code class="language-plaintext highlighter-rouge">arbitrary</code> plays for generators. That
is, it provides Rust developers with abstractions and combinators for creating
custom structure-aware mutators. It also provides a <code class="language-plaintext highlighter-rouge">derive(Mutate)</code> macro to
automatically implement its functionality for a given type.</p>

<p><code class="language-plaintext highlighter-rouge">mutatis</code> is designed to resist bias via a two-phase design: first, it
enumerates all of the candidate mutations that could be applied to a test case,
and only afterwards chooses a particular random mutation from the candidate set
to actually apply.</p>

<h4>WebAssembly</h4>

<p><a href="https://webassembly.org/">WebAssembly</a> is a virtual instruction set designed to be safe, portable, and
fast. It is a stack machine where an instruction’s operands are popped off a
stack during execution and results pushed. It has sandboxed linear memories,
global variables, and local variables (the latter two effectively being two
kinds of virtual registers). The following instruction sequence computes <code class="language-plaintext highlighter-rouge">a * 3</code>
and stores the result into memory at address <code class="language-plaintext highlighter-rouge">p</code>:</p>

<div class="language-nasm highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c1">;; []</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">p</span>
<span class="c1">;; [p]</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">a</span>
<span class="c1">;; [p, a]</span>
<span class="nf">i32.const</span> <span class="mi">3</span>
<span class="c1">;; [p, a, 3]</span>
<span class="nf">i32.mul</span>
<span class="c1">;; [p, a*3]</span>
<span class="nf">i32.store</span>
<span class="c1">;; []</span>
</code></pre></div></div>

<h3>Generator and Mutator Implementation</h3>

<p>The range of all three generators and the mutator is the same universe of
WebAssembly programs. They are all implemented on top of the same <code class="language-plaintext highlighter-rouge">Module</code> and
<code class="language-plaintext highlighter-rouge">Inst</code> types, and, given enough time, none is capable of producing an
instruction sequence that another cannot. This helps ensure that our comparison
is apples-to-apples. However, due to their different implementation techniques,
they do produce different distributions of WebAssembly programs within that
universe, and produce test cases at different speeds from one another, which
ultimately affects how efficiently they exercise the SUT.</p>

<p>All of the generators are built on top of the <a href="https://github.com/rust-fuzz/arbitrary"><code class="language-plaintext highlighter-rouge">arbitrary</code></a> crate. The mutator
is built on top of the <a href="https://docs.rs/mutatis"><code class="language-plaintext highlighter-rouge">mutatis</code></a> crate.</p>

<p>The <code class="language-plaintext highlighter-rouge">Module</code> type is our structured fuzzing input. It describes a WebAssembly
module containing a variable number of linear memories, a variable number and
type of globals, and one function with a variable number and type of parameters
and results and a variable instruction sequence:</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="cd">/// A WebAssembly module of the shape:</span>
<span class="cd">///</span>
<span class="cd">///     (module</span>
<span class="cd">///       (memory ...)</span>
<span class="cd">///       (memory ...)</span>
<span class="cd">///       ...</span>
<span class="cd">///</span>
<span class="cd">///       (global ...)</span>
<span class="cd">///       (global ...)</span>
<span class="cd">///       ...</span>
<span class="cd">///</span>
<span class="cd">///       (func (export "run") (param ...) (result ...)</span>
<span class="cd">///         ...</span>
<span class="cd">///       )</span>
<span class="cd">///     )</span>
<span class="k">pub</span> <span class="k">struct</span> <span class="n">Module</span> <span class="p">{</span>
    <span class="n">num_memories</span><span class="p">:</span> <span class="nb">u32</span><span class="p">,</span>
    <span class="n">globals</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Global</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">param_types</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">result_types</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">instructions</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span><span class="p">,</span>
<span class="p">}</span>
</code></pre></div></div>

<p>The <code class="language-plaintext highlighter-rouge">Inst</code> type is an <code class="language-plaintext highlighter-rouge">enum</code> of all the WebAssembly instructions the
implementations support, which is all of the integer, float, SIMD, memory,
local, and global instructions. Control-flow, threading, table, and GC
instructions are not supported. Here is a subset of <code class="language-plaintext highlighter-rouge">Inst</code>’s definition:</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="cd">/// A WebAssembly instruction.</span>
<span class="k">pub</span> <span class="k">enum</span> <span class="n">Inst</span> <span class="p">{</span>
    <span class="nb">Drop</span><span class="p">,</span>
    <span class="nf">LocalGet</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>
    <span class="nf">GlobalGet</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>

    <span class="c1">// ...</span>

    <span class="nf">I32Const</span><span class="p">(</span><span class="nb">i32</span><span class="p">),</span>
    <span class="n">I32Add</span><span class="p">,</span>
    <span class="n">I32Sub</span><span class="p">,</span>
    <span class="n">I32Mul</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="nf">I64Const</span><span class="p">(</span><span class="nb">i64</span><span class="p">),</span>
    <span class="n">I64Add</span><span class="p">,</span>
    <span class="n">I64Sub</span><span class="p">,</span>
    <span class="n">I64Mul</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="nf">F32Const</span><span class="p">(</span><span class="nb">f32</span><span class="p">),</span>
    <span class="n">F32Add</span><span class="p">,</span>
    <span class="n">F32Sub</span><span class="p">,</span>
    <span class="n">F32Mul</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="nf">F64Const</span><span class="p">(</span><span class="nb">f64</span><span class="p">),</span>
    <span class="n">F64Add</span><span class="p">,</span>
    <span class="n">F64Sub</span><span class="p">,</span>
    <span class="n">F64Mul</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="n">I32WrapI64</span><span class="p">,</span>
    <span class="n">I64ExtendI32S</span><span class="p">,</span>
    <span class="n">I64ExtendI32U</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="nf">V128Const</span><span class="p">(</span><span class="nb">i128</span><span class="p">),</span>
    <span class="n">I8x16Add</span><span class="p">,</span>
    <span class="n">I8x16Sub</span><span class="p">,</span>

    <span class="c1">// ...</span>

    <span class="nf">I32Load</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>
    <span class="nf">I64Load</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>

    <span class="c1">// ...</span>

    <span class="nf">I32Store</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>
    <span class="nf">I64Store</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>

    <span class="c1">// ...</span>

    <span class="nf">MemorySize</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>
    <span class="nf">MemoryGrow</span><span class="p">(</span><span class="nb">u32</span><span class="p">),</span>
<span class="p">}</span>
</code></pre></div></div>

<p>There is an <code class="language-plaintext highlighter-rouge">Inst::operand_types</code> method that returns the types that the
instruction pops from the stack, and an <code class="language-plaintext highlighter-rouge">Inst::result_type</code> method that returns
the type of the value that the instruction pushes onto the stack, if
any. Finally, the <code class="language-plaintext highlighter-rouge">Module::to_wasm_binary</code> method encodes the module into
WebAssembly’s binary format, so it can be fed into Wasmtime. These methods are
used, directly or indirectly, in every generator and mutator implementation.</p>

<h4><code class="language-plaintext highlighter-rouge">arb</code></h4>

<p>The <code class="language-plaintext highlighter-rouge">arb</code> generator leverages <code class="language-plaintext highlighter-rouge">derive(arbitrary::Arbitrary)</code> on our structured
input types to generate a pseudorandom instance of <code class="language-plaintext highlighter-rouge">Module</code>, unconstrained by
validity. The module’s instruction sequence is almost certainly not valid at
this point: it likely is missing operands for instructions, producing more
results than the function’s signature describes, producing results of types that
don’t match the function signature, accessing globals and locals that don’t
exist, etc… Having produced an instance of <code class="language-plaintext highlighter-rouge">Module</code>, it next calls the
<code class="language-plaintext highlighter-rouge">Module::fixup</code> method to mutate the <code class="language-plaintext highlighter-rouge">Module</code> so that it is valid.</p>

<p>The <code class="language-plaintext highlighter-rouge">fixup</code> method works by abstractly interpreting the instruction sequence to
track the types of each value on the stack at every program point. Whenever an
instruction’s operand types don’t match the types on top of the stack, it
generates dummy values of the correct type. When the instructions produce more
values than the function’s signature proscribes, it emits <code class="language-plaintext highlighter-rouge">drop</code> instructions.</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">impl</span> <span class="n">Module</span> <span class="p">{</span>
    <span class="k">pub</span> <span class="k">fn</span> <span class="nf">fixup</span><span class="p">(</span><span class="o">&amp;</span><span class="k">mut</span> <span class="k">self</span><span class="p">,</span> <span class="k">mut</span> <span class="n">make_value</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">FnMut</span><span class="p">()</span> <span class="k">-&gt;</span> <span class="nb">i64</span><span class="p">)</span> <span class="p">{</span>
        <span class="c1">// ...</span>

        <span class="c1">// The fixed-up instructions.</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">fixed</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">with_capacity</span><span class="p">(</span>
            <span class="k">self</span><span class="py">.instructions</span><span class="nf">.len</span><span class="p">(),</span>
        <span class="p">);</span>

        <span class="c1">// The types on the stack at any given program</span>
        <span class="c1">// point. Similar to the Wasm spec's appendix's</span>
        <span class="c1">// validation algorithm.</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">stack</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>

        <span class="k">for</span> <span class="n">inst</span> <span class="k">in</span> <span class="nn">mem</span><span class="p">::</span><span class="nf">take</span><span class="p">(</span><span class="o">&amp;</span><span class="k">mut</span> <span class="k">self</span><span class="py">.instructions</span><span class="p">)</span> <span class="p">{</span>
            <span class="c1">// Special-case `drop` because it is</span>
            <span class="c1">// polymorphic.</span>
            <span class="k">if</span> <span class="nd">matches!</span><span class="p">(</span><span class="n">inst</span><span class="p">,</span> <span class="nn">Inst</span><span class="p">::</span><span class="nb">Drop</span><span class="p">)</span> <span class="p">{</span>
                <span class="k">if</span> <span class="n">stack</span><span class="nf">.is_empty</span><span class="p">()</span> <span class="p">{</span>
                    <span class="n">fixed</span><span class="nf">.push</span><span class="p">(</span>
                        <span class="nn">ValType</span><span class="p">::</span><span class="n">I32</span><span class="nf">.make_const</span><span class="p">(</span><span class="nf">make_value</span><span class="p">()),</span>
                    <span class="p">);</span>
                <span class="p">}</span> <span class="k">else</span> <span class="p">{</span>
                    <span class="n">stack</span><span class="nf">.pop</span><span class="p">();</span>
                <span class="p">}</span>
                <span class="n">fixed</span><span class="nf">.push</span><span class="p">(</span><span class="n">inst</span><span class="p">);</span>
                <span class="k">continue</span><span class="p">;</span>
            <span class="p">}</span>

            <span class="c1">// First clamp entity indices to valid</span>
            <span class="c1">// ranges.</span>
            <span class="k">let</span> <span class="nf">Some</span><span class="p">(</span><span class="n">inst</span><span class="p">)</span> <span class="o">=</span> <span class="k">self</span><span class="nf">.fixup_inst_immediates</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="k">mut</span> <span class="n">make_value</span><span class="p">,</span>
                <span class="n">has_mutable_global</span><span class="p">,</span>
                <span class="n">inst</span><span class="p">,</span>
            <span class="p">)</span> <span class="k">else</span> <span class="p">{</span>
                <span class="k">continue</span>
            <span class="p">};</span>

            <span class="c1">// Then make sure that the stack has</span>
            <span class="c1">// operands of the correct types for this</span>
            <span class="c1">// instruction.</span>
            <span class="k">self</span><span class="nf">.fixup_stack</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="k">mut</span> <span class="n">make_value</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="k">mut</span> <span class="n">fixed</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="k">mut</span> <span class="n">stack</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">inst</span><span class="p">,</span>
            <span class="p">);</span>

            <span class="c1">// Finally, apply the effects to the stack.</span>
            <span class="k">let</span> <span class="n">len_operands</span> <span class="o">=</span> <span class="n">inst</span><span class="nf">.operand_types</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="k">self</span><span class="py">.globals</span><span class="p">,</span>
            <span class="p">)</span><span class="nf">.len</span><span class="p">();</span>
            <span class="n">stack</span><span class="nf">.truncate</span><span class="p">(</span><span class="n">stack</span><span class="nf">.len</span><span class="p">()</span> <span class="o">-</span> <span class="n">len_operands</span><span class="p">);</span>
            <span class="n">stack</span><span class="nf">.extend</span><span class="p">(</span><span class="n">inst</span><span class="nf">.result_type</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="k">self</span><span class="py">.param_types</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="k">self</span><span class="py">.globals</span><span class="p">,</span>
            <span class="p">));</span>

            <span class="n">fixed</span><span class="nf">.push</span><span class="p">(</span><span class="n">inst</span><span class="p">);</span>
        <span class="p">}</span>

        <span class="c1">// ...</span>

        <span class="k">self</span><span class="py">.instructions</span> <span class="o">=</span> <span class="n">fixed</span><span class="p">;</span>
    <span class="p">}</span>

    <span class="k">fn</span> <span class="nf">fixup_stack</span><span class="p">(</span>
        <span class="o">&amp;</span><span class="k">mut</span> <span class="k">self</span><span class="p">,</span>
        <span class="k">mut</span> <span class="n">make_value</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">FnMut</span><span class="p">()</span> <span class="k">-&gt;</span> <span class="nb">i64</span><span class="p">,</span>
        <span class="n">fixed</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span><span class="p">,</span>
        <span class="n">stack</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span><span class="p">,</span>
        <span class="n">inst</span><span class="p">:</span> <span class="o">&amp;</span><span class="n">Inst</span><span class="p">,</span>
    <span class="p">)</span> <span class="p">{</span>
        <span class="k">let</span> <span class="n">needed</span> <span class="o">=</span> <span class="n">inst</span><span class="nf">.operand_types</span><span class="p">(</span><span class="o">&amp;</span><span class="k">self</span><span class="py">.globals</span><span class="p">);</span>
        <span class="k">let</span> <span class="n">n</span> <span class="o">=</span> <span class="n">needed</span><span class="nf">.len</span><span class="p">();</span>

        <span class="k">if</span> <span class="n">stack</span><span class="nf">.len</span><span class="p">()</span> <span class="o">&gt;=</span> <span class="n">n</span> <span class="p">{</span>
            <span class="k">if</span> <span class="p">(</span><span class="mi">0</span><span class="o">..</span><span class="n">n</span><span class="p">)</span><span class="nf">.all</span><span class="p">(|</span><span class="n">i</span><span class="p">|</span> <span class="p">{</span>
                <span class="n">stack</span><span class="p">[</span><span class="n">stack</span><span class="nf">.len</span><span class="p">()</span> <span class="o">-</span> <span class="n">n</span> <span class="o">+</span> <span class="n">i</span><span class="p">]</span> <span class="o">==</span> <span class="n">needed</span><span class="p">[</span><span class="n">i</span><span class="p">]</span>
            <span class="p">})</span> <span class="p">{</span>
                <span class="c1">// All needed operands are on the stack.</span>
                <span class="k">return</span><span class="p">;</span>
            <span class="p">}</span>
        <span class="p">}</span> <span class="k">else</span> <span class="p">{</span>
            <span class="k">if</span> <span class="n">stack</span><span class="nf">.iter</span><span class="p">()</span><span class="nf">.enumerate</span><span class="p">()</span><span class="nf">.all</span><span class="p">(|(</span><span class="n">i</span><span class="p">,</span> <span class="n">ty</span><span class="p">)|</span> <span class="p">{</span>
                <span class="o">*</span><span class="n">ty</span> <span class="o">==</span> <span class="n">needed</span><span class="p">[</span><span class="n">i</span><span class="p">]</span>
            <span class="p">})</span> <span class="p">{</span>
                <span class="c1">// A prefix of needed operands are on the</span>
                <span class="c1">// stack; make constants for the tail that</span>
                <span class="c1">// are missing.</span>
                <span class="k">for</span> <span class="n">ty</span> <span class="k">in</span> <span class="o">&amp;</span><span class="n">needed</span><span class="p">[</span><span class="n">stack</span><span class="nf">.len</span><span class="p">()</span><span class="o">..</span><span class="p">]</span> <span class="p">{</span>
                    <span class="n">fixed</span><span class="nf">.push</span><span class="p">(</span><span class="n">ty</span><span class="nf">.make_const</span><span class="p">(</span><span class="nf">make_value</span><span class="p">()));</span>
                    <span class="n">stack</span><span class="nf">.push</span><span class="p">(</span><span class="o">*</span><span class="n">ty</span><span class="p">);</span>
                <span class="p">}</span>
                <span class="k">return</span><span class="p">;</span>
            <span class="p">}</span>
        <span class="p">}</span>

        <span class="c1">// Otherwise, just make constants for all the</span>
        <span class="c1">// needed operands.</span>
        <span class="k">for</span> <span class="n">ty</span> <span class="k">in</span> <span class="n">needed</span> <span class="p">{</span>
            <span class="n">fixed</span><span class="nf">.push</span><span class="p">(</span><span class="n">ty</span><span class="nf">.make_const</span><span class="p">(</span><span class="nf">make_value</span><span class="p">()));</span>
            <span class="n">stack</span><span class="nf">.push</span><span class="p">(</span><span class="o">*</span><span class="n">ty</span><span class="p">);</span>
        <span class="p">}</span>
    <span class="p">}</span>

    <span class="c1">// ...</span>
<span class="p">}</span>
</code></pre></div></div>

<p>The <code class="language-plaintext highlighter-rouge">fixup</code> method also makes sure that for all instructions that have an
immediate referencing some entity, the referenced entity is valid. For example,
for a <code class="language-plaintext highlighter-rouge">local.get $l</code> instruction, it ensures that local <code class="language-plaintext highlighter-rouge">$l</code> actually exists or
else rewrites the local to one that does exist.</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">impl</span> <span class="n">Module</span> <span class="p">{</span>
    <span class="c1">// ...</span>

    <span class="k">fn</span> <span class="nf">fixup_inst_immediates</span><span class="p">(</span>
        <span class="o">&amp;</span><span class="k">mut</span> <span class="k">self</span><span class="p">,</span>
        <span class="k">mut</span> <span class="n">make_value</span><span class="p">:</span> <span class="k">impl</span> <span class="nf">FnMut</span><span class="p">()</span> <span class="k">-&gt;</span> <span class="nb">i64</span><span class="p">,</span>
        <span class="n">has_mutable_global</span><span class="p">:</span> <span class="nb">bool</span><span class="p">,</span>
        <span class="k">mut</span> <span class="n">inst</span><span class="p">:</span> <span class="n">Inst</span><span class="p">,</span>
    <span class="p">)</span> <span class="k">-&gt;</span> <span class="nb">Option</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span> <span class="p">{</span>
        <span class="k">match</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">inst</span> <span class="p">{</span>
            <span class="nn">Inst</span><span class="p">::</span><span class="nf">LocalGet</span><span class="p">(</span><span class="n">l</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="o">*</span><span class="n">l</span> <span class="o">%=</span> <span class="k">self</span><span class="py">.param_types</span><span class="nf">.len</span><span class="p">()</span> <span class="k">as</span> <span class="nb">u32</span><span class="p">,</span>

            <span class="c1">// ...</span>

            <span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
            <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
            <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F32Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
            <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F64Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
            <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">V128Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
                <span class="k">if</span> <span class="k">self</span><span class="py">.num_memories</span> <span class="o">==</span> <span class="mi">0</span> <span class="p">{</span>
                    <span class="k">return</span> <span class="nb">None</span><span class="p">;</span>
                <span class="p">}</span>
                <span class="o">*</span><span class="n">m</span> <span class="o">%=</span> <span class="k">self</span><span class="py">.num_memories</span><span class="p">;</span>
            <span class="p">}</span>

            <span class="c1">// ...</span>

            <span class="n">_</span> <span class="k">=&gt;</span> <span class="p">{}</span>
        <span class="p">}</span>

        <span class="nf">Some</span><span class="p">(</span><span class="n">inst</span><span class="p">)</span>
    <span class="p">}</span>
<span class="p">}</span>
</code></pre></div></div>

<p>After calling <code class="language-plaintext highlighter-rouge">fixup</code>, the <code class="language-plaintext highlighter-rouge">arb</code> generator invokes <code class="language-plaintext highlighter-rouge">Module::to_wasm_binary</code> to
get the encoded Wasm program.</p>

<h4><code class="language-plaintext highlighter-rouge">bottom_up</code></h4>

<p>The <code class="language-plaintext highlighter-rouge">bottom_up</code> generator also uses abstract interpretation to track the types
of values on the stack. It generates instructions in forwards order, from
operands to operators. It begins with an empty stack, filters candidate
instructions down to just those that would be valid given the types currently on
the stack, randomly chooses one, updates the stack types accordingly, and
repeats the process. This is the same approach that <a href="https://docs.rs/wasm-smith"><code class="language-plaintext highlighter-rouge">wasm-smith</code></a> uses. After
generating instructions this way, it then makes sure that the final types on the
stack match the function signature’s results, similar to the end of <code class="language-plaintext highlighter-rouge">fixup</code>.</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">impl</span> <span class="n">Module</span> <span class="p">{</span>
    <span class="k">pub</span> <span class="k">fn</span> <span class="nf">bottom_up</span><span class="p">(</span><span class="n">u</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">Unstructured</span><span class="o">&lt;</span><span class="nv">'_</span><span class="o">&gt;</span><span class="p">)</span> <span class="k">-&gt;</span> <span class="nb">Result</span><span class="o">&lt;</span><span class="k">Self</span><span class="o">&gt;</span> <span class="p">{</span>
        <span class="c1">// ...</span>

        <span class="k">let</span> <span class="n">max_insts</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.int_in_range</span><span class="p">(</span><span class="mi">1</span><span class="o">..=</span><span class="n">MAX_INSTS</span><span class="p">)</span><span class="o">?</span><span class="p">;</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">instructions</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">stack</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>

        <span class="k">for</span> <span class="n">_</span> <span class="k">in</span> <span class="mi">0</span><span class="o">..</span><span class="n">max_insts</span> <span class="p">{</span>
            <span class="k">if</span> <span class="n">stack</span> <span class="o">==</span> <span class="n">result_types</span> <span class="o">&amp;&amp;</span> <span class="n">u</span><span class="nf">.ratio</span><span class="p">(</span><span class="mi">3</span><span class="p">,</span> <span class="mi">4</span><span class="p">)</span><span class="o">?</span> <span class="p">{</span>
                <span class="k">break</span><span class="p">;</span>
            <span class="p">}</span>

            <span class="c1">// Choose a random instruction whose operand</span>
            <span class="c1">// types match those currently on the stack.</span>
            <span class="k">let</span> <span class="n">inst</span> <span class="o">=</span> <span class="nf">choose_inst_bottom_up</span><span class="p">(</span>
                <span class="n">u</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">stack</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">param_types</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">globals</span><span class="p">,</span>
                <span class="n">num_memories</span><span class="p">,</span>
            <span class="p">)</span><span class="o">?</span><span class="p">;</span>

            <span class="c1">// Apply this instruction's effects to the</span>
            <span class="c1">// stack.</span>
            <span class="nf">apply_inst</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="n">inst</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="k">mut</span> <span class="n">stack</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">param_types</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">globals</span><span class="p">,</span>
            <span class="p">);</span>
            <span class="n">instructions</span><span class="nf">.push</span><span class="p">(</span><span class="n">inst</span><span class="p">);</span>
        <span class="p">}</span>

        <span class="c1">// ...</span>

        <span class="nf">Ok</span><span class="p">(</span><span class="n">Module</span> <span class="p">{</span>
            <span class="n">param_types</span><span class="p">,</span>
            <span class="n">result_types</span><span class="p">,</span>
            <span class="n">globals</span><span class="p">,</span>
            <span class="n">num_memories</span><span class="p">,</span>
            <span class="n">instructions</span><span class="p">,</span>
        <span class="p">})</span>
    <span class="p">}</span>
<span class="p">}</span>

<span class="k">fn</span> <span class="nf">choose_inst_bottom_up</span><span class="p">(</span>
    <span class="n">u</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">Unstructured</span><span class="o">&lt;</span><span class="nv">'_</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">stack</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="n">ValType</span><span class="p">],</span>
    <span class="n">param_types</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="n">ValType</span><span class="p">],</span>
    <span class="n">globals</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="n">Global</span><span class="p">],</span>
    <span class="n">num_memories</span><span class="p">:</span> <span class="nb">u32</span><span class="p">,</span>
<span class="p">)</span> <span class="k">-&gt;</span> <span class="nb">Result</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span> <span class="p">{</span>
    <span class="c1">// Build up all the valid candidate instructions.</span>
    <span class="k">let</span> <span class="k">mut</span> <span class="n">candidates</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>

    <span class="c1">// Producers are always okay: [] -&gt; [t]</span>
    <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Const</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
    <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Const</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
    <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">F32Const</span><span class="p">(</span><span class="mf">0.0</span><span class="p">));</span>
    <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">F64Const</span><span class="p">(</span><span class="mf">0.0</span><span class="p">));</span>
    <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">V128Const</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
    <span class="k">if</span> <span class="o">!</span><span class="n">param_types</span><span class="nf">.is_empty</span><span class="p">()</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">LocalGet</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
    <span class="p">}</span>

    <span class="c1">// ...</span>

    <span class="k">let</span> <span class="n">top</span> <span class="o">=</span> <span class="n">stack</span><span class="nf">.last</span><span class="p">()</span><span class="nf">.copied</span><span class="p">();</span>
    <span class="k">let</span> <span class="n">second</span> <span class="o">=</span> <span class="n">stack</span><span class="nf">.get</span><span class="p">(</span><span class="n">stack</span><span class="nf">.len</span><span class="p">()</span> <span class="o">-</span> <span class="mi">2</span><span class="p">)</span><span class="nf">.copied</span><span class="p">();</span>

    <span class="c1">// Drop needs 1 operand of any type: [t] -&gt; []</span>
    <span class="k">if</span> <span class="n">top</span><span class="nf">.is_some</span><span class="p">()</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nb">Drop</span><span class="p">);</span>
    <span class="p">}</span>

    <span class="c1">// i32 unary: [i32] -&gt; [...]</span>
    <span class="k">if</span> <span class="n">top</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I32</span><span class="p">)</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Clz</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Ctz</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Popcnt</span><span class="p">);</span>
        <span class="c1">// ...</span>
    <span class="p">}</span>

    <span class="c1">// i64 unary: [i64] -&gt; [...]</span>
    <span class="k">if</span> <span class="n">top</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I64</span><span class="p">)</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Clz</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Ctz</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Popcnt</span><span class="p">);</span>
        <span class="c1">// ...</span>
    <span class="p">}</span>

    <span class="c1">// ...</span>

    <span class="c1">// i32 binary: [i32 i32] -&gt; [...]</span>
    <span class="k">if</span> <span class="n">top</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I32</span><span class="p">)</span> <span class="o">&amp;&amp;</span> <span class="n">second</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I32</span><span class="p">)</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Add</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Sub</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Mul</span><span class="p">);</span>
        <span class="c1">// ...</span>
    <span class="p">}</span>

    <span class="c1">// i64 binary: [i64 i64] -&gt; [...]</span>
    <span class="k">if</span> <span class="n">top</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I64</span><span class="p">)</span> <span class="o">&amp;&amp;</span> <span class="n">second</span> <span class="o">==</span> <span class="nf">Some</span><span class="p">(</span><span class="n">I64</span><span class="p">)</span> <span class="p">{</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Add</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Sub</span><span class="p">);</span>
        <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Mul</span><span class="p">);</span>
        <span class="c1">// ...</span>
    <span class="p">}</span>

    <span class="c1">// ...</span>

    <span class="c1">// Choose a random instruction from the</span>
    <span class="c1">// candidates.</span>
    <span class="k">let</span> <span class="k">mut</span> <span class="n">inst</span> <span class="o">=</span> <span class="o">*</span><span class="n">u</span><span class="nf">.choose</span><span class="p">(</span><span class="o">&amp;</span><span class="n">candidates</span><span class="p">)</span><span class="o">?</span><span class="p">;</span>

    <span class="c1">// If the instruction has immediates, generate</span>
    <span class="c1">// them here, as they were hard-coded during</span>
    <span class="c1">// candidate selection.</span>
    <span class="k">match</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">inst</span> <span class="p">{</span>
        <span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Const</span><span class="p">(</span><span class="n">v</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="o">*</span><span class="n">v</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.arbitrary</span><span class="p">()</span><span class="o">?</span><span class="p">,</span>
        <span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Const</span><span class="p">(</span><span class="n">v</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="o">*</span><span class="n">v</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.arbitrary</span><span class="p">()</span><span class="o">?</span><span class="p">,</span>
        <span class="c1">// ...</span>
        <span class="nn">Inst</span><span class="p">::</span><span class="nf">GlobalGet</span><span class="p">(</span><span class="n">g</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="o">*</span><span class="n">g</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.int_in_range</span><span class="p">(</span><span class="mi">0</span><span class="o">..=</span><span class="p">(</span><span class="n">globals</span><span class="nf">.len</span><span class="p">()</span> <span class="k">as</span> <span class="nb">u32</span> <span class="o">-</span> <span class="mi">1</span><span class="p">))</span><span class="o">?</span><span class="p">;</span>
        <span class="p">}</span>
        <span class="c1">// ...</span>
        <span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F32Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F64Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">V128Load</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Store</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Store</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F32Store</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">F64Store</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">V128Store</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">MemorySize</span><span class="p">(</span><span class="n">m</span><span class="p">)</span>
        <span class="p">|</span> <span class="nn">Inst</span><span class="p">::</span><span class="nf">MemoryGrow</span><span class="p">(</span><span class="n">m</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="o">*</span><span class="n">m</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.int_in_range</span><span class="p">(</span><span class="mi">0</span><span class="o">..=</span><span class="p">(</span><span class="n">num_memories</span> <span class="o">-</span> <span class="mi">1</span><span class="p">))</span><span class="o">?</span><span class="p">;</span>
        <span class="p">}</span>
        <span class="n">_</span> <span class="k">=&gt;</span> <span class="p">{}</span>
    <span class="p">}</span>

    <span class="nf">Ok</span><span class="p">(</span><span class="n">inst</span><span class="p">)</span>
<span class="p">}</span>
</code></pre></div></div>

<p>After constructing a <code class="language-plaintext highlighter-rouge">Module</code> via <code class="language-plaintext highlighter-rouge">bottom_up</code>, we don’t need to call <code class="language-plaintext highlighter-rouge">fixup</code>
because the module is already valid by construction, so all that’s left is
invoking <code class="language-plaintext highlighter-rouge">Module::to_wasm_binary</code> to get the encoded Wasm program.</p>

<h4><code class="language-plaintext highlighter-rouge">top_down</code></h4>

<p>The <code class="language-plaintext highlighter-rouge">top_down</code> generator is very similar to <code class="language-plaintext highlighter-rouge">bottom_up</code>, but instead of
generating instructions forwards, from operands to operators, it generates them
backwards, from operators to operands. Instead of maintaining a stack of the
types of values generated thus far by the instruction sequence prefix, it
maintains a stack of the types of values expected by the instruction sequence
suffix. This is the approach that <a href="https://insuyun.github.io/pubs/2025/park:rgfuzz.pdf"><code class="language-plaintext highlighter-rouge">rgfuzz</code></a> by Park, Kim, and Yun
takes.<sup><a class="footnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fn:rule-guided" rel="footnote">2</a></sup></p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">impl</span> <span class="n">Module</span> <span class="p">{</span>
    <span class="k">pub</span> <span class="k">fn</span> <span class="nf">top_down</span><span class="p">(</span>
        <span class="n">u</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">Unstructured</span><span class="o">&lt;</span><span class="nv">'_</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="p">)</span> <span class="k">-&gt;</span> <span class="nb">Result</span><span class="o">&lt;</span><span class="k">Self</span><span class="o">&gt;</span> <span class="p">{</span>
        <span class="c1">// ...</span>

        <span class="k">let</span> <span class="n">max_insts</span> <span class="o">=</span> <span class="n">u</span><span class="nf">.int_in_range</span><span class="p">(</span><span class="mi">1</span><span class="o">..=</span><span class="n">MAX_INSTS</span><span class="p">)</span><span class="o">?</span><span class="p">;</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">instructions</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>
        <span class="k">let</span> <span class="k">mut</span> <span class="n">needed</span> <span class="o">=</span> <span class="n">result_types</span><span class="nf">.clone</span><span class="p">();</span>
        <span class="k">for</span> <span class="n">_</span> <span class="k">in</span> <span class="mi">0</span><span class="o">..</span><span class="n">max_insts</span> <span class="p">{</span>
            <span class="k">if</span> <span class="n">needed</span><span class="nf">.is_empty</span><span class="p">()</span> <span class="o">&amp;&amp;</span> <span class="n">u</span><span class="nf">.ratio</span><span class="p">(</span><span class="mi">3</span><span class="p">,</span> <span class="mi">4</span><span class="p">)</span><span class="o">?</span> <span class="p">{</span>
                <span class="k">break</span><span class="p">;</span>
            <span class="p">}</span>

            <span class="c1">// Choose a random instruction in a</span>
            <span class="c1">// top-down manner.</span>
            <span class="k">let</span> <span class="n">inst</span> <span class="o">=</span> <span class="nf">choose_inst_top_down</span><span class="p">(</span>
                <span class="n">u</span><span class="p">,</span>
                <span class="n">needed</span><span class="nf">.last</span><span class="p">()</span><span class="nf">.copied</span><span class="p">(),</span>
                <span class="o">&amp;</span><span class="n">param_types</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">globals</span><span class="p">,</span>
                <span class="n">num_memories</span><span class="p">,</span>
            <span class="p">)</span><span class="o">?</span><span class="p">;</span>

            <span class="c1">// Pop the result type from `needed`, if</span>
            <span class="c1">// any, as it's been satisfied.</span>
            <span class="k">let</span> <span class="n">ty</span> <span class="o">=</span> <span class="n">inst</span><span class="nf">.result_type</span><span class="p">(</span>
                <span class="o">&amp;</span><span class="n">param_types</span><span class="p">,</span>
                <span class="o">&amp;</span><span class="n">globals</span><span class="p">,</span>
            <span class="p">);</span>
            <span class="k">if</span> <span class="n">ty</span> <span class="o">==</span> <span class="n">needed</span><span class="nf">.last</span><span class="p">()</span><span class="nf">.copied</span><span class="p">()</span> <span class="p">{</span>
                <span class="n">needed</span><span class="nf">.pop</span><span class="p">();</span>
            <span class="p">}</span>

            <span class="c1">// Add operand type demands.</span>
            <span class="k">match</span> <span class="o">&amp;</span><span class="n">inst</span> <span class="p">{</span>
                <span class="nn">Inst</span><span class="p">::</span><span class="nb">Drop</span> <span class="k">=&gt;</span> <span class="p">{</span>
                    <span class="c1">// `drop` is polymorphic; choose</span>
                    <span class="c1">// a random type.</span>
                    <span class="n">needed</span><span class="nf">.push</span><span class="p">(</span><span class="n">u</span><span class="nf">.arbitrary</span><span class="p">()</span><span class="o">?</span><span class="p">);</span>
                <span class="p">}</span>
                <span class="nn">Inst</span><span class="p">::</span><span class="nf">GlobalSet</span><span class="p">(</span><span class="n">g</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
                    <span class="n">needed</span><span class="nf">.push</span><span class="p">(</span><span class="n">globals</span><span class="p">[</span><span class="o">*</span><span class="n">g</span> <span class="k">as</span> <span class="nb">usize</span><span class="p">]</span><span class="py">.ty</span><span class="p">);</span>
                <span class="p">}</span>
                <span class="n">_</span> <span class="k">=&gt;</span> <span class="p">{</span>
                    <span class="n">needed</span><span class="nf">.extend_from_slice</span><span class="p">(</span>
                        <span class="n">inst</span><span class="nf">.operand_types</span><span class="p">(</span><span class="o">&amp;</span><span class="n">globals</span><span class="p">),</span>
                    <span class="p">);</span>
                <span class="p">}</span>
            <span class="p">}</span>

            <span class="n">instructions</span><span class="nf">.push</span><span class="p">(</span><span class="n">inst</span><span class="p">);</span>
        <span class="p">}</span>

        <span class="c1">// Fill remaining needed types with</span>
        <span class="c1">// constants.</span>
        <span class="k">for</span> <span class="n">ty</span> <span class="k">in</span> <span class="n">needed</span><span class="nf">.iter</span><span class="p">()</span><span class="nf">.rev</span><span class="p">()</span> <span class="p">{</span>
            <span class="n">instructions</span><span class="nf">.push</span><span class="p">(</span>
                <span class="n">ty</span><span class="nf">.make_const</span><span class="p">(</span><span class="n">u</span><span class="nf">.arbitrary</span><span class="p">()</span><span class="o">?</span><span class="p">),</span>
            <span class="p">);</span>
        <span class="p">}</span>

        <span class="c1">// Instructions were generated backwards, so</span>
        <span class="c1">// reverse.</span>
        <span class="n">instructions</span><span class="nf">.reverse</span><span class="p">();</span>

        <span class="nf">Ok</span><span class="p">(</span><span class="n">Module</span> <span class="p">{</span>
            <span class="n">param_types</span><span class="p">,</span>
            <span class="n">result_types</span><span class="p">,</span>
            <span class="n">globals</span><span class="p">,</span>
            <span class="n">num_memories</span><span class="p">,</span>
            <span class="n">instructions</span><span class="p">:</span> <span class="n">prefix</span><span class="p">,</span>
        <span class="p">})</span>
    <span class="p">}</span>
<span class="p">}</span>

<span class="k">fn</span> <span class="nf">choose_inst_top_down</span><span class="p">(</span>
    <span class="n">u</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">Unstructured</span><span class="o">&lt;</span><span class="nv">'_</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">target_ty</span><span class="p">:</span> <span class="nb">Option</span><span class="o">&lt;</span><span class="n">ValType</span><span class="o">&gt;</span><span class="p">,</span>
    <span class="n">param_types</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="n">ValType</span><span class="p">],</span>
    <span class="n">globals</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="n">Global</span><span class="p">],</span>
    <span class="n">num_memories</span><span class="p">:</span> <span class="nb">u32</span><span class="p">,</span>
<span class="p">)</span> <span class="k">-&gt;</span> <span class="nb">Result</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span> <span class="p">{</span>
    <span class="k">let</span> <span class="k">mut</span> <span class="n">candidates</span><span class="p">:</span> <span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Inst</span><span class="o">&gt;</span> <span class="o">=</span> <span class="nn">Vec</span><span class="p">::</span><span class="nf">new</span><span class="p">();</span>
    <span class="k">match</span> <span class="n">target_ty</span> <span class="p">{</span>
        <span class="nf">Some</span><span class="p">(</span><span class="n">I32</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Const</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Add</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Sub</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I32Mul</span><span class="p">);</span>
            <span class="c1">// ...</span>
        <span class="p">}</span>
        <span class="nf">Some</span><span class="p">(</span><span class="n">I64</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">I64Const</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Add</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Sub</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">I64Mul</span><span class="p">);</span>
            <span class="c1">// ...</span>
        <span class="p">}</span>
        <span class="nf">Some</span><span class="p">(</span><span class="n">F32</span><span class="p">)</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">F32Const</span><span class="p">(</span><span class="mf">0.0</span><span class="p">));</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">F32Add</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">F32Sub</span><span class="p">);</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="n">F32Mul</span><span class="p">);</span>
            <span class="c1">// ...</span>
        <span class="p">}</span>
        <span class="c1">// ...</span>
        <span class="nb">None</span> <span class="k">=&gt;</span> <span class="p">{</span>
            <span class="c1">// Nothing needed. `drop`, `global.set`, and</span>
            <span class="c1">// stores add demand.</span>
            <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nb">Drop</span><span class="p">);</span>
            <span class="k">if</span> <span class="n">globals</span><span class="nf">.iter</span><span class="p">()</span><span class="nf">.any</span><span class="p">(|</span><span class="n">g</span><span class="p">|</span> <span class="n">g</span><span class="py">.mutable</span><span class="p">)</span> <span class="p">{</span>
                <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">GlobalSet</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
            <span class="p">}</span>
            <span class="k">if</span> <span class="n">num_memories</span> <span class="o">&gt;</span> <span class="mi">0</span> <span class="p">{</span>
                <span class="n">candidates</span><span class="nf">.push</span><span class="p">(</span><span class="nn">Inst</span><span class="p">::</span><span class="nf">I32Store</span><span class="p">(</span><span class="mi">0</span><span class="p">));</span>
                <span class="c1">// ...</span>
            <span class="p">}</span>
        <span class="p">}</span>
    <span class="p">}</span>

    <span class="k">let</span> <span class="k">mut</span> <span class="n">inst</span> <span class="o">=</span> <span class="o">*</span><span class="n">u</span><span class="nf">.choose</span><span class="p">(</span><span class="o">&amp;</span><span class="n">candidates</span><span class="p">)</span><span class="o">?</span><span class="p">;</span>

    <span class="c1">// If the instruction has immediates, generate</span>
    <span class="c1">// them here, as they were hard-coded during</span>
    <span class="c1">// candidate selection. Same as `bottom_up`.</span>
    <span class="k">match</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="n">inst</span> <span class="p">{</span>
        <span class="c1">// ...</span>
    <span class="p">}</span>

    <span class="nf">Ok</span><span class="p">(</span><span class="n">inst</span><span class="p">)</span>
<span class="p">}</span>
</code></pre></div></div>

<p>Similar to <code class="language-plaintext highlighter-rouge">bottom_up</code>, after we’ve constructed a <code class="language-plaintext highlighter-rouge">Module</code> via <code class="language-plaintext highlighter-rouge">top_down</code>, we
don’t need to call <code class="language-plaintext highlighter-rouge">fixup</code> because the module is already valid by construction.
All that’s left is invoking <code class="language-plaintext highlighter-rouge">Module::to_wasm_binary</code> to get the encoded Wasm
program.</p>

<h4><code class="language-plaintext highlighter-rouge">mutate</code></h4>

<p><code class="language-plaintext highlighter-rouge">mutate</code> is, as the name implies, a mutator rather than a generator. It is the
direct equivalent of the <code class="language-plaintext highlighter-rouge">arb</code> generator, but for mutation: it uses
<code class="language-plaintext highlighter-rouge">derive(mutatis::Mutate)</code> on <code class="language-plaintext highlighter-rouge">Module</code> and <code class="language-plaintext highlighter-rouge">Inst</code> to automatically generate
custom mutators for these types, rather than authoring them by hand. After
producing a new <code class="language-plaintext highlighter-rouge">Module</code> by mutating an old <code class="language-plaintext highlighter-rouge">Module</code>, that new <code class="language-plaintext highlighter-rouge">Module</code> probably
represents an invalid Wasm program, in the same way that
<code class="language-plaintext highlighter-rouge">derive(arbitrary::Arbitrary)</code> produces <code class="language-plaintext highlighter-rouge">Module</code>s that are probably invalid. And
<code class="language-plaintext highlighter-rouge">mutate</code> also uses the same approach that <code class="language-plaintext highlighter-rouge">arb</code> does to resolve this problem:
the <code class="language-plaintext highlighter-rouge">fixup</code> method.</p>

<p>But first, a mutator-specific wrinkle is that <code class="language-plaintext highlighter-rouge">fuzz_mutator!</code> gives us a mutable
byte slice to mutate, not a <code class="language-plaintext highlighter-rouge">Module</code>. We address this gap by deriving the
<a href="https://serde.rs/"><code class="language-plaintext highlighter-rouge">serde</code></a> crate’s <code class="language-plaintext highlighter-rouge">Serialize</code> and <code class="language-plaintext highlighter-rouge">Deserialize</code> traits on <code class="language-plaintext highlighter-rouge">Module</code> and <code class="language-plaintext highlighter-rouge">Inst</code>,
deserializing a <code class="language-plaintext highlighter-rouge">Module</code> from the mutable byte slice, mutating that deserialized
<code class="language-plaintext highlighter-rouge">Module</code> with <code class="language-plaintext highlighter-rouge">mutatis</code>, and then reserializing it back into the mutable byte
slice. We use the <a href="https://docs.rs/postcard"><code class="language-plaintext highlighter-rouge">postcard</code></a> crate here, but could just as easily use
<a href="https://docs.rs/bincode"><code class="language-plaintext highlighter-rouge">bincode</code></a>, JSON, or protobuf.</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="k">use</span> <span class="nn">libfuzzer_sys</span><span class="p">::{</span><span class="n">fuzz_mutator</span><span class="p">,</span> <span class="n">fuzz_target</span><span class="p">,</span> <span class="n">fuzzer_mutate</span><span class="p">};</span>

<span class="nd">fuzz_mutator!</span><span class="p">(|</span>
    <span class="n">data</span><span class="p">:</span> <span class="o">&amp;</span><span class="k">mut</span> <span class="p">[</span><span class="nb">u8</span><span class="p">],</span>
    <span class="n">size</span><span class="p">:</span> <span class="nb">usize</span><span class="p">,</span>
    <span class="n">max_size</span><span class="p">:</span> <span class="nb">usize</span><span class="p">,</span>
    <span class="n">seed</span><span class="p">:</span> <span class="nb">u32</span><span class="p">,</span>
<span class="p">|</span> <span class="p">{</span>
    <span class="c1">// With probability of about 1/8, use default</span>
    <span class="c1">// mutator.</span>
    <span class="k">if</span> <span class="n">seed</span><span class="nf">.count_ones</span><span class="p">()</span> <span class="o">%</span> <span class="mi">8</span> <span class="o">==</span> <span class="mi">0</span> <span class="p">{</span>
        <span class="k">return</span> <span class="nf">fuzzer_mutate</span><span class="p">(</span><span class="n">data</span><span class="p">,</span> <span class="n">size</span><span class="p">,</span> <span class="n">max_size</span><span class="p">);</span>
    <span class="p">}</span>

    <span class="c1">// Try to decode using postcard; fallback to</span>
    <span class="c1">// default input on failure.</span>
    <span class="k">let</span> <span class="k">mut</span> <span class="n">module</span><span class="p">:</span> <span class="n">Module</span> <span class="o">=</span>
        <span class="nn">postcard</span><span class="p">::</span><span class="nf">from_bytes</span><span class="p">(</span><span class="o">&amp;</span><span class="n">data</span><span class="p">[</span><span class="o">..</span><span class="n">size</span><span class="p">])</span>
            <span class="nf">.ok</span><span class="p">()</span>
            <span class="nf">.unwrap_or_default</span><span class="p">();</span>

    <span class="c1">// Mutate with `mutatis`.</span>
    <span class="k">let</span> <span class="k">mut</span> <span class="n">session</span> <span class="o">=</span> <span class="nn">mutatis</span><span class="p">::</span><span class="nn">Session</span><span class="p">::</span><span class="nf">new</span><span class="p">()</span>
        <span class="nf">.seed</span><span class="p">(</span><span class="n">seed</span><span class="nf">.into</span><span class="p">())</span>
        <span class="nf">.shrink</span><span class="p">(</span><span class="n">max_size</span> <span class="o">&lt;</span> <span class="n">size</span><span class="p">);</span>
    <span class="k">if</span> <span class="n">session</span><span class="nf">.mutate</span><span class="p">(</span><span class="o">&amp;</span><span class="k">mut</span> <span class="n">module</span><span class="p">)</span><span class="nf">.is_ok</span><span class="p">()</span> <span class="p">{</span>
        <span class="k">if</span> <span class="k">let</span> <span class="nf">Ok</span><span class="p">(</span><span class="n">encoded</span><span class="p">)</span> <span class="o">=</span> <span class="nn">postcard</span><span class="p">::</span><span class="nf">to_slice</span><span class="p">(</span>
            <span class="o">&amp;</span><span class="n">module</span><span class="p">,</span>
            <span class="n">data</span><span class="p">,</span>
        <span class="p">)</span> <span class="p">{</span>
            <span class="k">return</span> <span class="n">encoded</span><span class="nf">.len</span><span class="p">();</span>
        <span class="p">}</span>
    <span class="p">}</span>

    <span class="c1">// Fallback to the default libfuzzer mutator if</span>
    <span class="c1">// serialization or mutation fails because, for</span>
    <span class="c1">// example, `data` doesn't have enough capacity.</span>
    <span class="nf">fuzzer_mutate</span><span class="p">(</span><span class="n">data</span><span class="p">,</span> <span class="n">size</span><span class="p">,</span> <span class="n">max_size</span><span class="p">)</span>
<span class="p">});</span>
</code></pre></div></div>

<p>Finally, the fuzz target itself deserializes the <code class="language-plaintext highlighter-rouge">Module</code> from the raw bytes,
calls <code class="language-plaintext highlighter-rouge">fixup</code>, encodes it to a Wasm binary via <code class="language-plaintext highlighter-rouge">Module::to_wasm_binary</code>, and
then passes that into Wasmtime.</p>

<div class="language-rust highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nd">fuzz_target!</span><span class="p">(|</span><span class="n">data</span><span class="p">:</span> <span class="o">&amp;</span><span class="p">[</span><span class="nb">u8</span><span class="p">]|</span> <span class="p">{</span>
    <span class="k">let</span> <span class="nf">Ok</span><span class="p">(</span><span class="k">mut</span> <span class="n">module</span><span class="p">)</span> <span class="o">=</span> <span class="nn">postcard</span><span class="p">::</span><span class="nn">from_bytes</span><span class="p">::</span><span class="o">&lt;</span><span class="n">Module</span><span class="o">&gt;</span><span class="p">(</span><span class="n">data</span><span class="p">)</span> <span class="k">else</span> <span class="p">{</span>
        <span class="k">return</span><span class="p">;</span>
    <span class="p">};</span>
    <span class="n">module</span><span class="nf">.fixup</span><span class="p">(||</span> <span class="mi">0</span><span class="p">);</span>
    <span class="k">let</span> <span class="n">wasm</span> <span class="o">=</span> <span class="n">module</span><span class="nf">.to_wasm_binary</span><span class="p">();</span>

    <span class="c1">// ...</span>
<span class="p">});</span>
</code></pre></div></div>

<h3>Benchmarking</h3>

<h4>Methodology</h4>

<p>We pair each of our generators and mutator with <a href="https://github.com/rust-fuzz/libfuzzer"><code class="language-plaintext highlighter-rouge">libfuzzer-sys</code></a> and feed the
resulting test cases into <a href="https://wasmtime.dev/">Wasmtime</a>. All fuzzers start with an empty corpus.</p>

<p>The most important metric for a fuzzer is its bug-finding ability, but that can
be difficult to measure directly. For example, Wasmtime is actively fuzzed 24/7
with more-complete fuzzers than those implemented here, so, as expected, I have
not found any bugs via these benchmarks. Therefore, instead of reporting a
found-bugs count, the benchmark harness reports two alternative metrics:</p>

<ol>
  <li>
    <p><strong><em>Coverage over time:</em></strong> Coverage is the cumulative code paths exercised by
the fuzzer. A fuzzer cannot find bugs in code paths it does not cover. <em>This
is the most important metric reported.</em></p>
  </li>
  <li>
    <p><strong><em>Executions over time:</em></strong> An execution is one iteration of the fuzzing
loop. This is basically measuring how fast the fuzzer can produce test
cases. All else being equal, more executions is better, but all else is
rarely equal. It is easy to generate poor test cases very quickly: just
return an empty sequence of Wasm instructions every time. Unfortunately, that
exclusively leads to useless executions. Therefore, this metric is really
only useful when comparing two implementations of the same algorithm, and
I’ve omitted its results in the next section.</p>
  </li>
</ol>

<p>Additionally, I report results for both 24 hours of fuzzing and 5 minutes of
fuzzing. The expected behavior of long-term fuzzing, e.g. 24/7 fuzzing in
<a href="https://github.com/google/oss-fuzz">OSS-Fuzz</a>, can be extrapolated from the 24-hour results. The 5-minute results
show the expected behavior of short-term fuzzing, e.g. when using
<a href="https://docs.rs/mutatis/latest/mutatis/check/index.html"><code class="language-plaintext highlighter-rouge">mutatis::check</code></a> or <a href="https://docs.rs/arbtest/latest/arbtest/"><code class="language-plaintext highlighter-rouge">arbtest</code></a>.</p>

<p>Discussion of short-term fuzzing is somewhat rare, so I feel its motivation
deserves explanation. I find short-term fuzzing useful in the following
scenarios, for example:</p>

<ul>
  <li>Running a quick fuzzing session locally, to catch bugs that avoid detection in
the traditional unit- and integration-test suites, before opening a pull
request.</li>
  <li>Running some quick fuzzing in CI before allowing a pull request to merge, for
similar reasons.</li>
</ul>

<p>That is, short-term fuzzing is useful for the same reasons and in the same
scenarios as property-based testing.<sup><a class="footnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fn:pbt" rel="footnote">3</a></sup></p>

<p>As recommended in <a href="https://arxiv.org/abs/1808.09700"><em>Evaluating Fuzz Testing</em></a> by Klees, Ruef, Cooper,
Wei, and Hicks and adopted in <a href="https://storage.googleapis.com/gweb-research2023-media/pubtools/6318.pdf"><em>Fuzz Bench: An Open Fuzzer Benchmarking Platform
and Service</em></a> by Metzman, Szekeres, Simon, Sprabery, and Arya, the
benchmark harness tests the statistical significance of its results with a
<a href="https://en.wikipedia.org/wiki/Mann%E2%80%93Whitney_U_test">Mann-Whitney U-test</a>. The harness performs 20 trials per fuzzer, the same
number of trials as <em>Fuzz Bench</em>.</p>

<h4>Results</h4>

<h5>24 Hours of Fuzzing</h5>

<ul>
  <li>
    <p><code class="language-plaintext highlighter-rouge">arb</code> has 1.00 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">bottom_up</code> (p = 0.01)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.01 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">arb</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">top_down</code> has 1.00 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">arb</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.02 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">bottom_up</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">top_down</code> has 1.01 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">bottom_up</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.01 ± 0.00 times more coverage than <code class="language-plaintext highlighter-rouge">top_down</code> (p = 0.00)</p>
  </li>
</ul>

<p><a href="https://raw.githubusercontent.com/fitzgen/fuzz-experiment/9c059bbe2835b2123ed379994eec76fe9278e962/results-24h/coverage-over-time.svg">
  <img src="https://raw.githubusercontent.com/fitzgen/fuzz-experiment/9c059bbe2835b2123ed379994eec76fe9278e962/results-24h/coverage-over-time.svg">
</a></p>

<h5>5 Minutes of Fuzzing</h5>

<ul>
  <li>
    <p><code class="language-plaintext highlighter-rouge">bottom_up</code> has 1.01 ± 0.01 times more coverage than <code class="language-plaintext highlighter-rouge">arb</code> (p = 0.04)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.47 ± 0.02 times more coverage than <code class="language-plaintext highlighter-rouge">arb</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">top_down</code> has 1.06 ± 0.02 times more coverage than <code class="language-plaintext highlighter-rouge">arb</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.45 ± 0.01 times more coverage than <code class="language-plaintext highlighter-rouge">bottom_up</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">top_down</code> has 1.05 ± 0.02 times more coverage than <code class="language-plaintext highlighter-rouge">bottom_up</code> (p = 0.00)</p>
  </li>
  <li>
    <p><code class="language-plaintext highlighter-rouge">mutate</code> has 1.38 ± 0.02 times more coverage than <code class="language-plaintext highlighter-rouge">top_down</code> (p = 0.00)</p>
  </li>
</ul>

<p><a href="https://raw.githubusercontent.com/fitzgen/fuzz-experiment/9c059bbe2835b2123ed379994eec76fe9278e962/results-5m/coverage-over-time.svg">
  <img src="https://raw.githubusercontent.com/fitzgen/fuzz-experiment/9c059bbe2835b2123ed379994eec76fe9278e962/results-5m/coverage-over-time.svg">
</a></p>

<h3>Conclusion</h3>

<p><strong>The <code class="language-plaintext highlighter-rouge">mutate</code> fuzzer performs best.</strong> It vastly outperforms all the others at 5
minutes of fuzzing (36-49% more coverage), and while the rest narrow that gap
after 24 hours of fuzzing, <code class="language-plaintext highlighter-rouge">mutate</code> maintains its lead (1-2% more coverage).</p>

<p>The comparison between <code class="language-plaintext highlighter-rouge">arb</code> and <code class="language-plaintext highlighter-rouge">mutate</code> is as apples-to-apples of a comparison
as it gets between idiomatic test-case generation and mutation in Rust:
<code class="language-plaintext highlighter-rouge">derive(Arbitrary)</code> and <code class="language-plaintext highlighter-rouge">derive(Mutate)</code>. They use the same <code class="language-plaintext highlighter-rouge">fixup</code> method to
ensure that the resulting Wasm instructions are valid. The fuzzer built with
<code class="language-plaintext highlighter-rouge">mutatis</code> and test-case mutation provides better coverage over time than the
fuzzer built with <code class="language-plaintext highlighter-rouge">arbitrary</code> and test-case generation. When writing
structure-aware fuzzers, I used to reach for <a href="https://github.com/rust-fuzz/arbitrary"><code class="language-plaintext highlighter-rouge">arbitrary</code></a>; in the future, I
will reach for <a href="https://docs.rs/mutatis"><code class="language-plaintext highlighter-rouge">mutatis</code></a> instead.</p>

<p>The <code class="language-plaintext highlighter-rouge">top_down</code> fuzzer performs second-best, and is best of the generation-based
fuzzers. This aligns with results from the <a href="https://insuyun.github.io/pubs/2025/park:rgfuzz.pdf"><code class="language-plaintext highlighter-rouge">rgfuzz</code></a> paper, which found that
top-down Wasm instruction generation resulted in better instruction diversity
than bottom-up generation. This result is intuitive, they point out, because
Wasm instructions tend to have more operands than results, which means that more
candidates are filtered out from consideration when generating instructions in
forward order from operands to results (bottom-up) than when generating them in
backward order from results to operands (top-down).</p>

<p>Subjectively, none of the approaches feel significantly more-complicated nor
easier to implement than the others. All approaches require a stack of types,
representing the generated Wasm’s operand stack, at some point in their
implementation. Some require it during instruction generation (<code class="language-plaintext highlighter-rouge">top_down</code> and
<code class="language-plaintext highlighter-rouge">bottom_up</code>) while others require it during <code class="language-plaintext highlighter-rouge">fixup</code> (<code class="language-plaintext highlighter-rouge">mutate</code> and <code class="language-plaintext highlighter-rouge">arb</code>). Adding
support for new Wasm instructions is roughly the same in all of them: add a new
variant to <code class="language-plaintext highlighter-rouge">enum Inst</code> and define its operand and result types. <code class="language-plaintext highlighter-rouge">top_down</code> and
<code class="language-plaintext highlighter-rouge">bottom_up</code> additionally require adding a line for the new instruction in their
<code class="language-plaintext highlighter-rouge">choose_inst_{top_down,bottom_up}</code> functions, but this could be avoided with
some targeted <code class="language-plaintext highlighter-rouge">macro_rules!</code> sugar.</p>

<p>The <code class="language-plaintext highlighter-rouge">fixup</code> method fixes instructions in a forwards order; as future work, it
would be interesting to implement a <code class="language-plaintext highlighter-rouge">backwards_fixup</code> method that fixes
instructions in a backwards order and see if <code class="language-plaintext highlighter-rouge">mutate</code> and <code class="language-plaintext highlighter-rouge">backwards_fixup</code>
outperforms the current <code class="language-plaintext highlighter-rouge">mutate</code> and forwards <code class="language-plaintext highlighter-rouge">fixup</code> the same way that
backwards generation (<code class="language-plaintext highlighter-rouge">top_down</code>) outperforms forwards generation
(<code class="language-plaintext highlighter-rouge">bottom_up</code>).</p>

<p><code class="language-plaintext highlighter-rouge">fixup</code> makes an attempt to reuse stack operands when it can, rather than
synthesize dummy constants or <code class="language-plaintext highlighter-rouge">drop</code> already-computed values, but the attempt is
somewhat half-hearted. Dropping operands introduces dead code, which is not very
interesting for exercising deep into the compiler pipeline. Dummy constants are
not that interesting either. Therefore, another potential line of follow-up work
would be to investigate ways to maximize operand reuse and minimize <code class="language-plaintext highlighter-rouge">drop</code>s and
dummy constants inserted while ensuring validity. That could include storing
values to memory or globals instead of <code class="language-plaintext highlighter-rouge">drop</code>ing them when possible. It could
even include liberating ourselves from the stack-focused paradigm we’ve had thus
far.</p>

<p>WebAssembly is a stack-based language and so it is natural that our approaches
have focused on producing stack-y code. But, in practice, optimizing WebAssembly
compilers like Wasmtime’s use a <a href="https://en.wikipedia.org/wiki/Static_single-assignment_form">static single-assignment</a> intermediate
representation, and erase the operand stack early in their compilation
pipelines. Therefore, from these compilers’ point of view, the following two
WebAssembly snippets are identical:</p>

<div class="language-nasm highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c1">;; `x = a + (b * c)` in a "stack-y" encoding and</span>
<span class="c1">;; without temporary locals.</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">a</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">b</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">c</span>
<span class="nf">i32.mul</span>
<span class="nf">i32.add</span>
<span class="nf">local.set</span> <span class="kc">$</span><span class="nv">x</span>

<span class="c1">;; `x = a + (b * c)` in a "non-stack-y" encoding</span>
<span class="c1">;; that uses temporary locals for every operation.</span>
<span class="c1">;;</span>
<span class="c1">;; Equivalent of</span>
<span class="c1">;;</span>
<span class="c1">;;     temp0 = b * c</span>
<span class="c1">;;     temp1 = a + temp0</span>
<span class="c1">;;     x = temp1</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">b</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">c</span>
<span class="nf">i32.mul</span>
<span class="nf">local.set</span> <span class="kc">$</span><span class="nv">temp0</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">a</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">temp0</span>
<span class="nf">i32.add</span>
<span class="nf">local.set</span> <span class="kc">$</span><span class="nv">temp1</span>
<span class="nf">local.get</span> <span class="kc">$</span><span class="nv">temp1</span>
<span class="nf">local.set</span> <span class="kc">$</span><span class="nv">x</span>
</code></pre></div></div>

<p>Producing code that uses many temporaries in this manner might be easier than
code that doesn’t, but, more importantly, it may enable better reuse of
already-computed subexpressions, emit less dead code, and ultimately produce
more interesting data-flow graphs that better exercise the deep innards of the
compiler.</p>

<p>A final vein of interesting follow-up work to mine would be comparing
<code class="language-plaintext highlighter-rouge">arbitrary</code>-based generators and <code class="language-plaintext highlighter-rouge">mutatis</code>-based mutators for structured inputs
that are not programming languages and when the SUT we are fuzzing is not a
compiler. Do we see these same results when, for example, producing PNG images
to fuzz an image-transformation library?</p>

<p><a href="https://github.com/fitzgen/fuzz-experiment">Here is the source code for this experiment, including the three generators,
one mutator, raw benchmark data, and benchmarking harness.</a> The <code class="language-plaintext highlighter-rouge">README</code>
includes instructions on running the benchmarks yourself.</p>

<hr>

<div class="footnotes">
  <ol>
    <li>
      <p>WebAssembly’s stack-based instructions encode an expression tree
— <code class="language-plaintext highlighter-rouge">local.get $a; local.get $b; local.get $c; i32.add; i32.mul</code> is
isomorphic to <code class="language-plaintext highlighter-rouge">a * (b + c)</code> — so the experiment should be relevant and
applicable to any other generator or mutator for a programming language with
expressions, even if it might not appear so at first glance. <a class="reversefootnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fnref:applicable">↩</a></p>
    </li>
    <li>
      <p>Ignoring its rule-guided bit, which is orthogonal and could be
applied to <code class="language-plaintext highlighter-rouge">bottom_up</code> as well. <a class="reversefootnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fnref:rule-guided">↩</a></p>
    </li>
    <li>
      <p>Structure-aware fuzzing and property-based testing are <a href="https://docs.rs/mutatis/latest/mutatis/_guide/comparisons/index.html#comparison-to-property-based-testing">basically the
same</a>:
convergent evolution from different communities. <a class="reversefootnote" href="https://fitzgeraldnick.com/weblog/feeds/latest-atom/#fnref:pbt">↩</a></p>
    </li>
  </ol>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rust 1.96.0]]></title>
<description><![CDATA[Language

Allow passing expr metavariable to cfg
Always coerce never types in tuple expressions
Avoid incorrect inference guidance of function arguments in rare cases
Support s390x vector registers in inline assembly
Allow using constants of type ManuallyDrop as patterns (fixing a regression intr...]]></description>
<link>https://tsecurity.de/de/3555163/downloads/rust-1960/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3555163/downloads/rust-1960/</guid>
<pubDate>Thu, 28 May 2026 20:01:30 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a></a></p>
<h2>Language</h2>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/146961" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/146961/hovercard">Allow passing <code>expr</code> metavariable to <code>cfg</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/147834" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/147834/hovercard">Always coerce never types in tuple expressions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/150316" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/150316/hovercard">Avoid incorrect inference guidance of function arguments in rare cases</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/154184" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/154184/hovercard">Support s390x vector registers in inline assembly</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/154891" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/154891/hovercard">Allow using constants of type <code>ManuallyDrop</code> as patterns (fixing a regression introduced in 1.94.0)</a></li>
</ul>
<p><a></a></p>
<h2>Compiler</h2>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/153427" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/153427/hovercard">Enable link relaxation feature for LoongArch Linux targets</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155072" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/155072/hovercard">Update <code>riscv64gc-unknown-fuchsia</code> baseline to RVA22 + vector</a></li>
</ul>
<p><a></a></p>
<h2>Libraries</h2>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/127534" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/127534/hovercard">Support iterating over ranges of <code>NonZero</code> integers</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152615" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/152615/hovercard">refactor 'valid for read/write' definition: exclude null; add that as an exception on individual methods instead</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152851" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/152851/hovercard">Fix SGX delayed host lookup via ToSocketAddr</a></li>
</ul>
<p><a></a></p>
<h2>Stabilized APIs</h2>
<ul>
<li><a href="https://doc.rust-lang.org/stable/std/macro.assert_matches.html" rel="nofollow"><code>assert_matches!</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/macro.debug_assert_matches.html" rel="nofollow"><code>debug_assert_matches!</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/panic/struct.AssertUnwindSafe.html#impl-From%3CT%3E-for-AssertUnwindSafe%3CT%3E" rel="nofollow"><code>From&lt;T&gt; for AssertUnwindSafe&lt;T&gt;</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/cell/struct.LazyCell.html#impl-From%3CT%3E-for-LazyCell%3CT,+F%3E" rel="nofollow"><code>From&lt;T&gt; for LazyCell&lt;T, F&gt;</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/sync/struct.LazyLock.html#impl-From%3CT%3E-for-LazyLock%3CT,+F%3E" rel="nofollow"><code>From&lt;T&gt; for LazyLock&lt;T, F&gt;</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/range/struct.RangeToInclusive.html" rel="nofollow"><code>core::range::RangeToInclusive</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/range/struct.RangeToInclusiveIter.html" rel="nofollow"><code>core::range::RangeToInclusiveIter</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/ops/struct.RangeFrom.html" rel="nofollow"><code>core::range::RangeFrom</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/ops/struct.RangeFromIter.html" rel="nofollow"><code>core::range::RangeFromIter</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/range/struct.Range.html" rel="nofollow"><code>core::range::Range</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/range/struct.RangeIter.html" rel="nofollow"><code>core::range::RangeIter</code></a></li>
</ul>
<p><a></a></p>
<h2>Cargo</h2>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/16810/" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/cargo/pull/16810/hovercard">Allow a dependency to specify both a git repository and an alternate registry.</a> Just like with crates.io, the git repository will be used locally, but the registry version will be used when published.</li>
<li><a href="https://github.com/rust-lang/cargo/pull/16846" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/cargo/pull/16846/hovercard">Added <code>target.'cfg(..)'.rustdocflags</code> support in configuration.</a></li>
<li>Fixed <a href="https://blog.rust-lang.org/2026/05/25/cve-2026-5222/" rel="nofollow">CVE-2026-5222</a> and <a href="https://blog.rust-lang.org/2026/05/25/cve-2026-5223/" rel="nofollow">CVE-2026-5223</a>.</li>
</ul>
<p><a></a></p>
<h2>Rustdoc</h2>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/149931" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/149931/hovercard">Deprecation notes are now rendered like any other documentation</a>. Previously they used the css <code>white-space: pre-wrap;</code> property and stripped any <code>&lt;p&gt;</code> elements from the rendered html, however this caused issues and unintuitive behavior. The new behavior should be more predictable, however some multi-line deprecation notes will now be rendered as as single lines. If this is undesirable, you can use the standard markdown method of forcing a linebreak, which is two spaces followed by a newline (<code>"\n"</code>).</li>
<li><a href="https://github.com/rust-lang/rust/pull/154048" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/154048/hovercard">Don't emit rustdoc <code>missing_doc_code_examples</code> lint on impl items</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/154644" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/154644/hovercard">Seperate methods and associated functions in sidebar</a></li>
</ul>
<p><a></a></p>
<h2>Compatibility Notes</h2>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/146989" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/146989/hovercard">Fix layout of <code>#[repr(Int)]</code> enums in some edge cases involving fields of uninhabited zero-sized types</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/149218" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/149218/hovercard">Prevent unsize-coercing into <code>Pin&lt;Foo&gt;</code> where <code>Foo</code> doesn't implement <code>Deref</code>. Some such coercions were previously allowed, but produce a type with no useful public API.</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/149868" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/149868/hovercard">rustc: Stop passing <code>--allow-undefined</code> on wasm targets</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152210" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/152210/hovercard">Gate the accidentally stabilized <code>#![reexport_test_harness_main]</code> attribute</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152543" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/152543/hovercard">Error on return-position-impl-trait-in-traits whose types are too private</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152853" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/152853/hovercard">Report the <code>uninhabited_static</code> lint in dependencies and make it deny-by-default</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152870" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/152870/hovercard">Distributed builds now contain non-split debuginfo for windows-gnu</a> This appears to improve the quality of backtraces. This change has no effect on the defaults for the output of rustc/cargo on these targets.</li>
<li><a href="https://github.com/rust-lang/rust/pull/152931" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/152931/hovercard">Check const generic arguments are correctly typed in more positions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152973" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/152973/hovercard">Remove <code>-Csoft-float</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152996" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/152996/hovercard">Importing structs with <code>::{self [as name]}</code>, e.g., <code>struct S {}; use S::{self as Other};</code>, is now no longer permitted because <code>{self}</code> imports require a module parent.</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/153041" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/153041/hovercard">For <code>export_name</code>, <code>link_name</code>, and <code>link_section</code> attributes, if multiple of the same attribute is present, the first one now takes precedence.</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/153684" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/153684/hovercard">Update the minimum external LLVM to 21</a></li>
<li>On <code>avr</code> targets, C's <code>double</code> type is 32-bit by default, so <a href="https://github.com/rust-lang/rust/pull/154647" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/154647/hovercard">change <code>c_double</code> to <code>f32</code> on <code>avr</code> targets to match</a>. This is a breaking change, but necessary to make <code>c_double</code> match C's double.</li>
</ul>
<p><a></a></p>
<h2>Internal Changes</h2>
<p>These changes do not affect any public interfaces of Rust, but they represent significant improvements to the performance or internals of rustc and related tools.</p>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/152941" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/152941/hovercard">JSON targets: <code>aarch64</code> softfloat targets now have to have <code>rustc_abi</code> set to <code>"softfloat"</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/153769" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/153769/hovercard">target specs: stricter checks for LLVM ABI values, and correlate that with <code>cfg(target_abi)</code></a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 653]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3553405/tools/this-week-in-rust-this-week-in-rust-653/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3553405/tools/this-week-in-rust-this-week-in-rust-653/</guid>
<pubDate>Thu, 28 May 2026 10:25:02 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://scientificcomputing.rs/monthly/2026-05">Scientific Computing in Rust #18 (May 2026)</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://github.com/GitoxideLabs/gitoxide/discussions/2621">gitoxide - May 26</a></li>
<li><a href="https://seanmonstar.com/blog/hyper-user-survey-2025-results/">hyper User Survey 2025 Results</a></li>
<li><a href="https://grpc.io/blog/grpc-welcomes-tonic/">Rust Update: gRPC Welcomes Tonic!</a></li>
<li><a href="https://github.com/ifsheldon/serde-const-default/releases/tag/v0.1">serde-const-default v0.1: Removes boilerplate when using const values as field defaults</a></li>
<li><a href="https://github.com/boquila/boquilahub/releases/tag/v0.5">BoquilaHUB 0.5: AIs for Nature. Now it includes SOTA AI bioacoustics models and embeddings models</a></li>
<li><a href="https://www.sextianbytes.fr/blog/imperfect-by-design/">splog: a log viewer TUI with automatic tag categorization</a></li>
<li><a href="https://dev.to/brevity1swos/building-a-regex-debugger-for-the-terminal-in-rust-977">rgx v0.12.3 — Building a regex debugger for the terminal in Rust</a></li>
<li><a href="https://davefx.com/en/2026/05/clipboardwire-construction-story/">UI tests are the guardrails an AI needs: the story of clipboardwire</a></li>
<li><a href="https://github.com/stevekwon211/slintcn/blob/main/docs/INTRODUCING_SLINTCN.md">slintcn 0.22: shadcn/ui-style copy-paste components for Slint native apps</a></li>
<li><a href="https://users.rust-lang.org/t/releasing-dtact-v0-2-2-and-rssn-advanced-v0-1-0/140278">Releasing dtact v0.2.2 and rssn-advanced v0.1.0: the next generation async concurrent engine and scientific computing engine</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://tritium.legal/blog/noroboto">Noroboto: Lying Fonts and Mitigation in Rust</a></li>
<li><a href="https://wolfgirl.dev/blog/2026-05-20-erasing-existentials/">Erasing Existentials</a></li>
<li><a href="https://yogthos.net/posts/2026-05-24-libwce.html">libwce: the entropy layer of a wavelet codec, on its own</a></li>
<li><a href="https://neugierig.org/software/blog/2026/05/theseus-wasm.html">Tech Notes: Theseus: translating win32 to wasm</a></li>
<li><a href="https://aibodh.com/posts/bevy-game-engine/">Bevy Game Engine Explained Visually</a></li>
<li><a href="https://verrchu.github.io/blog/3-the-reflex-of-deriving-serde-traits/">The reflex of deriving <code>serde</code> traits</a></li>
<li><a href="https://aimdb.dev/blog/typed-world-model">Physical AI Needs a Typed World Model, Not a Vector DB</a></li>
<li><a href="https://kerkour.com/rust-monorepos">Keep calm and use (Rust) monorepos</a></li>
<li>[audio] <a href="https://corrode.dev/podcast/s06e04-rust4linux/">Rust for Linux Live with Alice Ryhl and Greg Kroah-Hartman</a></li>
<li>[audio] <a href="https://netstack.fm/#episode-38">Netstack.FM episode 38 — Building and testing network stacks with Rama</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=RbmkNSqMvZY">Can a QR code be made of stars?</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://microsoft.github.io/RustTraining/rust-patterns-book/">Rust Patterns &amp; Engineering How-Tos</a></li>
<li><a href="https://hemomorphic.alexblood.net/posts/laissez-faire-errors/">Laissez-Faire Errors</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-hashmap-iterators-by-building-a-git-object-store-reader/">Learn Rust HashMap and Iterators by Building a Git Object Store Reader</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-the-basics-of-bevy-by-building-and-deploying-pong-to-itch-io/">Learn the Basics of Bevy by Building and Deploying Pong to Itch.io</a></li>
<li><a href="https://cong-or.xyz/false-sharing-cache-lines.html">The Slowdown That Doesn't Show Up in Profiles</a></li>
<li><a href="https://blog.cat-girl.gay/3ds-async-part-one/">Building an AsyncIO executor for the 3DS</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=3IyKC5EtNkM">Nine Ways to do Inheritance in Rust, a Language without Inheritance</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#miscellaneous">Miscellaneous</a></h5>
<ul>
<li><a href="https://kunobi.ninja/blog/what-kache-actually-caches">Content-addressed Rust builds (or, what kache actually caches)</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://docs.rs/inline_tweak">inline_tweak</a>, a crate to embed tweakable constants inside your Rust application without full recompilation.</p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1607">Kill The Mule</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>
<ul>
<li><a href="https://github.com/rust-lang-nursery/rust-cookbook/issues/760">rust cookbook - Expand Command Line section with clap derive, subcommands, and env vars</a></li>
</ul>




<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>


<ul>
<li><em>No Calls for papers or presentations were submitted this week.</em></li>
</ul>
<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>352 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-05-19..2026-05-26">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156161"><code>rustc_on_unimplemented</code>: introduce format specifiers</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156763">account for proc macro spans in <code>do_not_recommend</code> diagnostics</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155598">implement fast path for <code>derive(PartialOrd)</code> when deriving <code>Ord</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/153640">make bitset <code>would_modify_words</code> more vectorzer-friendly</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156824">parse <code>mut</code> restrictions</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156116">stop needing materialized places for most intrinsics</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156828">add unstable Share trait</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156594">stabilize <code>bool_to_result</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152112">use strongly typed wrapped indices in <code>VecDeque</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/17006">compiler: forward verbose flag to rustc for local crates</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17027">don't use the network for a publish dry-run test</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17011">break out <code>RegistryConfig</code> and <code>crate_url</code> for interpreting <code>RegistryConfig::dl</code></a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17031">fix CVE-2026-5222 and CVE-2026-5223</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17016">artifact: remove compat mode from artifacts</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/155307">stabilize <code>--remap-path-prefix</code> in rustdoc</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17060"><code>useless_format</code>: fire on wrapped in a block-producing macro</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16959"><code>return</code> can be removed from the last stmt of a block if it has an expr</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17025">add check for midpoint using multiplication by <code>0.5</code> and <code>&gt;&gt; 1</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17057">avoid unnecessary <code>String</code> allocations in <code>MinifyingSugg</code> arithmetic ops</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16767">extend <code>clippy::missing_safety_doc</code> to unsafe fields</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17065">fix <code>manual_range_contains</code> NAN handling</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17036">fix error message for <code>useless_borrows_in_formatting</code> for mutable borrows</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16998">move <code>unnecessary_get_then_check</code> to <code>complexity</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17055">simplify <code>is_some() &amp;&amp; …unwrap()</code> to <code>is_some_and</code> in <code>unit_arg</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22406"><code>diagnostics: mut_ref</code> binding feature diagnostic</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22342"><code>assists/add_reference_here: _modify_</code> the reference type when dealing with <code>&amp;T-&gt;&amp;mut T</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22426"><code>cfg</code>: correct separator index in CfgDiff disable loop</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22430"><code>hir-ty</code>: saturate float-to-uint cast in const eval</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22427"><code>test-utils</code>: drain <code>inactive_regions</code> by <code>inactive_line_region</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22411">add diagnostic for E0033</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22404">add diagnostic for E0608</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22416">completions imports exclude supports sub items</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22432">filter package-scoped features</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22437"><code>extract_module</code> missing import for macro calls</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22452">add <code>type_match</code> score for <code>struct_pat</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22415">allow wildcard params in foreign fn declarations</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22449">analysis expected ty in <code>enum</code> variant</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22385">autoimport <code>enum</code> variants</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22392">do not autoref in method probe in path mode</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22408">do not complete semicolon in match-expr place</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22397">do not consider the path of the macro in a macro call to be inside a macro call</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22424">emit diagnostic for rest array patterns without fixed-length arrays</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/21566">fix <code>SyntaxContext::root</code>s technically overlapping valid interneds</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22451">flip <code>coerce_never type_mismatch</code> tys</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22383">have a specific error for unimplemented builtin macros</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22409">no suggest ref match when expected generic ref</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22369">no use sad pattern on happy arm with guard</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22425">normalize expected tuple <code>struct</code> pat field</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22252">refactor handling of generic params in <code>hir::Type</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22396">support named consts in range pattern types</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22419">use grouped annotation for <code>add_label_to_loop</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22322">provide better incrementality for modules</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week was largely positive, with most of the improvements coming from algorithm change in visibility checking: <a href="https://github.com/rust-lang/rust/pull/156228">#156228</a>.</p>
<p>Triage done by <strong>@panstromek</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=281c97c3240a9abd984ca0c6a2cd7389115e80d5&amp;end=783eb8c8682ddde0807c60ed8293670ef523794f&amp;absolute=false&amp;stat=instructions%3Au">281c97c3..783eb8c8</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.4%</td>
<td>[0.1%, 0.7%]</td>
<td>5</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>0.5%</td>
<td>[0.1%, 1.1%]</td>
<td>16</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-0.9%</td>
<td>[-6.6%, -0.1%]</td>
<td>164</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-0.4%</td>
<td>[-1.3%, -0.1%]</td>
<td>51</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-0.9%</td>
<td>[-6.6%, 0.7%]</td>
<td>169</td>
</tr>
</tbody>
</table>
<p>2 Regressions, 2 Improvements, 5 Mixed; 2 of them in rollups
34 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/4e9e90ee6ec008cadd1f351541185eff56319998/triage/2026/2026-05-25.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3946">Propose the concept of a crates.io username for identity</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/985">Promotes 5 Thumb-mode bare-metal Arm targets to Tier 2</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/976">Add -Z dead-fn-elimination to skip codegen of BFS-unreachable functions</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/155989">Update <code>transmute_copy</code> to ub_checks and <code>?Sized</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/117224">Tracking Issue for NEON dot product intrinsics</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/152761">Never break between empty parens</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-rfcs"></a><a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3928">Avoid linting <code>unreachable_code</code> on <code>todo!()</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#unsafe-code-guidelines"></a><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>
<ul>
<li><a href="https://github.com/rust-lang/unsafe-code-guidelines/issues/438">What are the values of a union type? (in particular, what is the validity invariant of a union)</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a> or
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>.</em>
Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><em>No New or Updated RFCs were created this week.</em></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-05-27 - 2026-06-24 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-05-27 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/9v7hv2g1"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-02 | Virtual | <a href="https://luma.com/libp2p">libp2p Events</a><ul>
<li><a href="https://luma.com/ukfh0mcf"><strong>rust-libp2p Open Maintainers Call</strong></a></li>
</ul>
</li>
<li>2026-06-02 | Virtual (Tel Aviv-yafo, IL) | <a href="https://www.meetup.com/rust-tlv">Rust 🦀 TLV</a><ul>
<li><a href="https://www.meetup.com/rust-tlv/events/314871990/"><strong>‎שיחה חופשית ווירטואלית על ראסט</strong></a></li>
</ul>
</li>
<li>2026-06-03 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/314691782/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455930/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345241/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Virtual (Tel Aviv-yafo, IL) | <a href="https://www.meetup.com/code-mavens/">Code Mavens 🦀 - 🐍 - 🐪</a><ul>
<li><a href="https://www.meetup.com/code-mavens/events/314979560/"><strong>Exploring FalkorDB - Learning to use a Graph Database in Rust</strong></a> </li>
</ul>
</li>
<li>2026-06-06 | Virtual (Kampala, UG) | <a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587">Rust Circle Meetup</a><ul>
<li><a href="https://www.eventbrite.com/e/rust-circle-meetup-tickets-628763176587"><strong>Rust Circle Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-07 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095285/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-06-09 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254780/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-06-10 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/3bcnx1jb"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/rdhhptyjcjbvb/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314000478/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ekws5nr4"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314236370/"><strong>June, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455931/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-06-21 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329044/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254779/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-06-23 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/313767883/"><strong>Lunch &amp; Learn: What the heck are monads - and how do we fake them in Rust</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-06-02 | Beijing, CN | <a href="https://www.meetup.com/wasm-rust-meetup/events/">Voice AI and Rust Meetup (Rust for AI, lowcoderust.com)</a><ul>
<li><a href="https://www.meetup.com/wasm-rust-meetup/events/314750465/"><strong>AI Agents and Open Source LLM (Call for Speakers)</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-05-28 | Copenhagen, DK | <a href="https://www.meetup.com/copenhagen-rust-community">Copenhagen Rust Community</a><ul>
<li><a href="https://www.meetup.com/copenhagen-rust-community/events/314868448/"><strong>Rust meetup #68</strong></a></li>
</ul>
</li>
<li>2026-05-28 | London, UK | <a href="https://www.meetup.com/rust-london-user-group">Rust London User Group</a><ul>
<li><a href="https://www.meetup.com/rust-london-user-group/events/314846861/"><strong>LDN Talks May Community Showcase</strong></a></li>
</ul>
</li>
<li>2026-05-29 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/314396588/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-05-30 | Stockholm, SE | <a href="https://www.meetup.com/stockholm-rust">Stockholm Rust</a><ul>
<li><a href="https://www.meetup.com/stockholm-rust/events/314926826/"><strong>Ferris' Fika Forum #26</strong></a></li>
</ul>
</li>
<li>2026-06-02 | Frankfurt, DE | <a href="https://www.meetup.com/rust-rhein-main">Rust Rhein-Main</a><ul>
<li><a href="https://www.meetup.com/rust-rhein-main/events/314051727/"><strong>gRPC with Rust and Tonic</strong></a></li>
</ul>
</li>
<li>2026-06-03 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin">Rust Dublin</a><ul>
<li><a href="https://www.meetup.com/rust-dublin/events/314689875/"><strong>Join us live and INPERSON for Rust 261</strong></a></li>
</ul>
</li>
<li>2026-06-03 | Girona, ES | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/4bmlc7qd"><strong>Rust Girona Hack &amp; Learn 06 2026</strong></a></li>
</ul>
</li>
<li>2026-06-10 | München, DE | <a href="https://www.meetup.com/rust-munich">Rust Munich</a><ul>
<li><a href="https://www.meetup.com/rust-munich/events/313791798/"><strong>Rust Munich 2026 / 2 - Hacking Evening</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
<li>2026-06-12 - 2026-06-14 | Kraków, PL | <a href="https://rustmeet.eu/">Rustmeet</a><ul>
<li><a href="https://rustmeet.eu/"><strong>Rustmeet</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313813937/"><strong>Interactive: Everything is Open Source</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Milano, IT | <a href="https://www.meetup.com/rust-language-milano">Rust Language Milan</a><ul>
<li><a href="https://www.meetup.com/rust-language-milan/events/314766950/"><strong>Real-time planning in Rust: SolverForge &amp; SERIO</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Aarhus, DK | <a href="https://www.meetup.com/rust-aarhus">Rust Aarhus</a><ul>
<li><a href="https://www.meetup.com/rust-aarhus/events/314965238/"><strong>Talk Night at Danske Commodities</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-05-27 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/314209662/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-05-28 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539319/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-05-28 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/314218564/"><strong>Rust LA: Rust in Embedded &amp; Autonomous Systems at Parallel Systems in DTLA</strong></a></li>
</ul>
</li>
<li>2026-05-28 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/314716463/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-05-30 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480537/"><strong>Central Cambridge Rust Lunch, May 30</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/314106244/"><strong>Testing, Coverage, Tracey &amp; Mutations</strong></a></li>
</ul>
</li>
<li>2026-06-06 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480539/"><strong>Boston Common Rust Lunch, June 6</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696643/"><strong>Utah Rust June Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/314825006/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-06-11 | San Diego, CA, US | <a href="https://www.meetup.com/san-diego-rust">San Diego Rust</a><ul>
<li><a href="https://www.meetup.com/san-diego-rust/events/313721899/"><strong>San Diego Rust June Meetup - Back in person!</strong></a></li>
</ul>
</li>
<li>2026-06-16 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/ghhwqtyjcjbvb/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314000478/"><strong>Jiff</strong></a></li>
</ul>
</li>
<li>2026-06-18 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/314236370/"><strong>June, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/xvkdgtyjcjbgc/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-06-24 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/314386080/"><strong>Rust LA: Rust-Based Constraint Solvers in 2D Sketching with Zoo Technologies</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-06-18 | Florianópolis, BR | <a href="https://luma.com/rust-sc">Rust SC</a><ul>
<li><a href="https://luma.com/acinctdf"><strong>Rust Floripa</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1sobu1s/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>This overflows the trait solver today as well as my brain</p>
</blockquote>
<p>– <a href="https://nadrieril.github.io/blog/2026/05/14/when-can-traits-depend-on-themselves.html">Nadrieril on their blog</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1774">Theemathas</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1tptzbz/this_week_in_rust_653/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox Tooling Announcements: Firefox Profiler Deployment (May 26, 2026)]]></title>
<description><![CDATA[The latest version of the Firefox Profiler is now live! Check out the full changelog below to see what’s changed:
Highlights:

[Markus Stange] Use @streamparser/json if the input is too large to fit in a V8 string (#6016)
[Nazım Can Altınova] Include --search option in pq filter push (#6026)
[fat...]]></description>
<link>https://tsecurity.de/de/3548813/tools/firefox-tooling-announcements-firefox-profiler-deployment-may-26-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548813/tools/firefox-tooling-announcements-firefox-profiler-deployment-may-26-2026/</guid>
<pubDate>Tue, 26 May 2026 19:09:00 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The latest version of the <a href="https://profiler.firefox.com/" rel="noopener nofollow ugc">Firefox Profiler</a> is now live! Check out the full changelog below to see what’s changed:</p>
<p><strong>Highlights:</strong></p>
<ul>
<li>[Markus Stange] Use <code>@streamparser/json</code> if the input is too large to fit in a V8 string (<a href="https://github.com/firefox-devtools/profiler/pull/6016" rel="noopener nofollow ugc">#6016</a>)</li>
<li>[Nazım Can Altınova] Include <code>--search</code> option in <code>pq filter push</code> (<a href="https://github.com/firefox-devtools/profiler/pull/6026" rel="noopener nofollow ugc">#6026</a>)</li>
<li>[fatadel] Translate URL track-index state through profile sanitization (<a href="https://github.com/firefox-devtools/profiler/pull/6000" rel="noopener nofollow ugc">#6000</a>)</li>
<li>[Nazım Can Altınova] Print also the status output right after cli <code>load</code> command (<a href="https://github.com/firefox-devtools/profiler/pull/6019" rel="noopener nofollow ugc">#6019</a>)</li>
</ul>
<p><strong>Other Changes:</strong></p>
<ul>
<li>[fatadel] Remove unused dependencies from package.json (<a href="https://github.com/firefox-devtools/profiler/pull/6010" rel="noopener nofollow ugc">#6010</a>)</li>
<li>[Nazım Can Altınova] Make profiler-cli work in sandboxed environments (<a href="https://github.com/firefox-devtools/profiler/pull/6003" rel="noopener nofollow ugc">#6003</a>)</li>
<li>[Markus Stange] Make profiler-edit run profile compacting before writing out the file (<a href="https://github.com/firefox-devtools/profiler/pull/6015" rel="noopener nofollow ugc">#6015</a>)</li>
<li>[Markus Stange] Migrate from prettier to oxfmt (<a href="https://github.com/firefox-devtools/profiler/pull/5986" rel="noopener nofollow ugc">#5986</a>)</li>
<li>[Markus Stange] Add a --symbolicate-wasm arg to profiler-edit. (<a href="https://github.com/firefox-devtools/profiler/pull/6008" rel="noopener nofollow ugc">#6008</a>)</li>
<li>[Markus Stange] Build and upload the cli artifact in PRs (<a href="https://github.com/firefox-devtools/profiler/pull/6020" rel="noopener nofollow ugc">#6020</a>)</li>
<li>[Nicolas Chevobbe] Update devtools-reps to 0.27.7 (<a href="https://github.com/firefox-devtools/profiler/pull/6030" rel="noopener nofollow ugc">#6030</a>)</li>
<li>[Markus Stange/fatadel] Make withSize use a wrapper element so that it can stop calling findDOMNode (<a href="https://github.com/firefox-devtools/profiler/pull/5988" rel="noopener nofollow ugc">#5988</a>)</li>
<li>[Markus Stange] Fix dhat importer (<a href="https://github.com/firefox-devtools/profiler/pull/6036" rel="noopener nofollow ugc">#6036</a>)</li>
<li>[Nazım Can Altınova] Annotate inlined frames in CLI call trees and stacks (<a href="https://github.com/firefox-devtools/profiler/pull/6041" rel="noopener nofollow ugc">#6041</a>)</li>
<li>[Nazım Can Altınova] Use proper types in cli tests instead of custom inline types (<a href="https://github.com/firefox-devtools/profiler/pull/6038" rel="noopener nofollow ugc">#6038</a>)</li>
<li>[Nazım Can Altınova] Fix text truncation for frames named after Object.prototype methods (<a href="https://github.com/firefox-devtools/profiler/pull/6044" rel="noopener nofollow ugc">#6044</a>)</li>
<li>[Nazım Can Altınova] Add missing key props to CodeErrorOverlay error list items (<a href="https://github.com/firefox-devtools/profiler/pull/6047" rel="noopener nofollow ugc">#6047</a>)</li>
<li>[depfu[bot]] <img alt=":up_arrow:" class="emoji" height="20" src="https://emoji.discourse-cdn.com/twitter/up_arrow.png?v=15" title=":up_arrow:" width="20"> Update oxfmt to version 0.51.0 (<a href="https://github.com/firefox-devtools/profiler/pull/6054" rel="noopener nofollow ugc">#6054</a>)</li>
<li>[Nazım Can Altınova] <img alt=":clockwise_vertical_arrows:" class="emoji" height="20" src="https://emoji.discourse-cdn.com/twitter/clockwise_vertical_arrows.png?v=15" title=":clockwise_vertical_arrows:" width="20"> Sync: l10n → main (May 26, 2026) (<a href="https://github.com/firefox-devtools/profiler/pull/6058" rel="noopener nofollow ugc">#6058</a>)</li>
<li>[Nazım Can Altınova] Use URL-state symbol server for <code>profiler-cli function annotate</code> (<a href="https://github.com/firefox-devtools/profiler/pull/6051" rel="noopener nofollow ugc">#6051</a>)</li>
<li>[Nazım Can Altınova] Bump profiler-cli version to 0.2.0 (<a href="https://github.com/firefox-devtools/profiler/pull/6059" rel="noopener nofollow ugc">#6059</a>)</li>
</ul>
<p>Big thanks to our amazing localizers for making this release possible:</p>
<ul>
<li>fr: YD</li>
<li>sr: Марко Костић (Marko Kostić)</li>
<li>tr: Ali Demirtaş</li>
<li>zh-CN: Olvcpr423</li>
<li>zh-CN: wxie</li>
</ul>
<p>Find out more about the Firefox Profiler on <a href="https://profiler.firefox.com/" rel="noopener nofollow ugc">profiler.firefox.com</a>! If you have any questions, join the discussion on our <a href="https://chat.mozilla.org/#/room/%23profiler:mozilla.org" rel="noopener nofollow ugc">Matrix channel</a>!</p>
            <p><small>1 post - 1 participant</small></p>
            <p><a href="https://discourse.mozilla.org/t/firefox-profiler-deployment-may-26-2026/148468">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Project Onyx] Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing]]></title>
<description><![CDATA[submitted by    /u/Admin-ABC-XYZ   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3546447/reverse-engineering/project-onyx-advanced-edr-evasion-via-ai-telemetry-spoofing-wasm-sandboxing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546447/reverse-engineering/project-onyx-advanced-edr-evasion-via-ai-telemetry-spoofing-wasm-sandboxing/</guid>
<pubDate>Tue, 26 May 2026 00:20:18 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/Admin-ABC-XYZ"> /u/Admin-ABC-XYZ </a> <br> <span><a href="https://github.com/X-3306/Project-Onyx">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1tnfq3i/project_onyx_advanced_edr_evasion_via_ai/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 652]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3535118/tools/this-week-in-rust-this-week-in-rust-652/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3535118/tools/this-week-in-rust-this-week-in-rust-652/</guid>
<pubDate>Thu, 21 May 2026 07:08:37 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#official">Official</a></h5>
<ul>
<li><a href="https://blog.rust-lang.org/2026/05/18/project-goals-2026-04/">Project goals update — April 2026 (end of 2025H2)</a></li>
<li><a href="https://blog.rust-lang.org/inside-rust/2026/05/13/program-management-update--april-2026/">Program management update — April 2026</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://rust-osdev.com/this-month/2026-04/">This Month in Rust OSDev: April 2026</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://luciofranco.com/blog/tonic-joins-grpc/">Tonic is joining the gRPC project</a></li>
<li><a href="https://tokio.rs/blog/2026-05-15-announcing-toasty-0-6-0">Toasty 0.6.0 - What is new?</a></li>
<li><a href="https://hexdocs.pm/ex_ratatui">ex_ratatui: Elixir bindings for ratatui via Rustler NIFs</a></li>
<li><a href="https://medium.com/@jinhopers/in-depth-llvm-ir-how-omniscope-tracks-ownership-across-languages-2919e418ca61">OmniScope: A Cross-Language LLVM IR Static Analyzer Targeting Unsafe/FFI Boundaries</a>: </li>
<li><a href="https://citum.org/">citum: a new Rust citation processor and associated tools.</a></li>
<li><a href="https://minikin.me/blog/cargo-crap">cargo-crap: Finding Untested Complexity in AI-Generated Rust Code</a></li>
<li><a href="https://aimdb.dev/blog/graph-owes">What the Graph Owes: Connectors That Drive Outputs</a></li>
<li><a href="https://beeb.li/blog/introducing-swpui">swpui: a TUI for case-aware search and replace</a></li>
<li><a href="https://kunobi.ninja/blog/kache-update">kache 0.3.0: zero-copy efficient worktree compilation</a></li>
<li><a href="https://catcoding.me/ghr/">ghr: a Rust TUI for managing GitHub pull requests, issues, notifications, and reviews</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://kerkour.com/rust-organize-large-projects-code-error-handling">Scaling Rust codebases: Lessons learned organizing large projects and managing errors</a></li>
<li><a href="https://corrode.dev/learn/migration-guides/go-to-rust/">Migrating from Go to Rust</a></li>
<li><a href="https://blog.gokuls.in/posts/why-i-built-wrkflw.html">Why I built wrkflw</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=VIsKIzFz_zA">Rust's God Mode</a></li>
<li>[video] <a href="https://www.youtube.com/watch?v=FUg1y-yv6cs">How Rust engineered the perfect async runtime</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://apas.tel/blog/optimizing-image-rs-blur">5× faster fast_blur in image-rs</a></li>
<li><a href="https://thejpster.org.uk/blog/blog-2026-05-17/">Finding the Time Part 2 - Rust Async and the Arm Generic Timer</a></li>
<li><a href="https://assethoard.com/blog/parsing-godot-tres-files">Parsing Godot .tres files and walking the resource graph</a></li>
<li><a href="https://jonahnestrick.com/blog/rust-gba-tutorial-1/">Rust x GBA: Setup and Pixels</a></li>
<li><a href="https://blog.sheerluck.dev/posts/learn-rust-lifetimes-by-building-a-lru-cache/">Learn Rust Lifetimes by Building a Generic LRU Cache</a></li>
<li><a href="https://bencher.dev/learn/benchmarking/rust/gungraun/">How to benchmark Rust code with Gungraun</a></li>
<li><a href="https://root-11.github.io/intro-book/">Book: An Introduction to Programming, using ECS &amp; EBP in Rust</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/minikin/cargo-crap">cargo-crap</a>, a cargo subcommand to calculate the Change Risk Anti-Patterns metric for a crate.</p>
<p>Despite a lamentable lack of suggestions, llogiq is pleased with his choice.</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>




<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<ul>
<li><a href="https://scientificcomputing.rs/2026/submit-talk"><strong>Scientific Computing in Rust 2026</strong></a>| 2026-06-05 | Virtual | 2026-07-08 - 2026-07-10</li>
</ul>
<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>369 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-05-12..2026-05-19">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/155815">add Swift function call ABI</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156452">implement pinned drop sugar</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/155360"><code>map_try_insert</code> changes</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156444">implement <code>OsStr::split_at</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156234">implement <code>into_array</code> for <code>Vec&lt;T&gt;</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156428">move <code>std::io::Cursor</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156431">move <code>std::io::util</code> to <code>core::io</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156644">widen the result of <code>widening_mul</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/16988"><code>clean</code>: respect <code>build.target</code> config for <code>clean -p</code></a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16989"><code>diag</code>: Consolidate verify/run diagnostics passes</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16994"><code>diag</code>: Report deferred diagnostics like other diagnostics</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17008"><code>diag</code>: Pull in the parse pass</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17007"><code>lints</code>: Avoid compiling where possible</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/17002">drop <code>-Zunstable-options</code> for <code>rustdoc --emit</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rustdoc">Rustdoc</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/146220">stabilize <code>--emit</code> flag</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156587">correctly handle associated items in rustdoc macro expansion</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156413">correctness &amp; perf improvements to link-to-definition</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152449">properly support macros with multiple kinds</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16922">fix <code>duration_suboptimal_units</code> for small literals</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/17011">fix arithmetic side effects false positive</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22347">add diagnostic for E0029</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22380">add diagnostic for E0614</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22355">add diagnostic for E0638</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22378">add handler for E0040</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22329">encode the name instead of index in <code>EnumVariantId</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22354">fix assist <code>qualify_path</code> loses path segment</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22335">add param on result methods for <code>replace_method_eager_lazy</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22399">complete <code>ref_match</code> in macro</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22368">fully support pattern types</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22344">handle usages in macro for <code>extract_function</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22386">no complete module colons before exists colons</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22363">no lint unsized adt <code>self_ty</code> missing bounded assoc</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22376">not complete same name inherent deref methods</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22367">only ref match non-unknown value items</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22357">show Run lens for fn main in bench targets</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22384">handle <code>TyKind::{Pat,UnsafeBinder}</code> in <code>has_drop_glue</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22082">implement <code>pattern_type</code> macro</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22372">method-resolution: emit error for method calls with illegal Sized bound</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22352">migrate <code>inline_call</code> assist to SyntaxFactory</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22191">perf: provide access to <code>RootDatabase</code>'s <code>LineIndex</code> for the proc macro protocol</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22358">show <code>const</code> in the signature help if applicable</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22381">show <code>unsafe</code> in the signature help if applicable</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>Fewer than usual PRs merged, mostly due to a shorter week than normal and some
CI trouble. Overall a slightly positive week for performance.</p>
<p>Triage done by <strong>@simulacrum</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=29b7590130c83542a095cdf1323ed0f78eec2bb8&amp;end=281c97c3240a9abd984ca0c6a2cd7389115e80d5&amp;absolute=false&amp;stat=instructions%3Au">29b75901..281c97c3</a></p>
<p>0 Regressions, 0 Improvements, 4 Mixed; 1 of them in rollups
17 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/master/triage/2026/2026-05-17.md">Full report here</a></p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3923">Cargo RFC for min publish age</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler-team-mcps-only"></a><a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>
<ul>
<li><a href="https://github.com/rust-lang/compiler-team/issues/990">Removing the unstable ptx linker flavor</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/988">Create a new Tier 3 target: <code>powerpc64le-unknown-none</code></a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/922">Optimize <code>repr(Rust)</code> enums by omitting tags in more cases involving uninhabited variants.</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/906">Proposal for a dedicated test suite for the parallel frontend</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/864">Promote tier 3 riscv32 ESP-IDF targets to tier 2</a></li>
<li><a href="https://github.com/rust-lang/compiler-team/issues/841">Proposal for Adapt Stack Protector for Rust</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a>,
<a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>,
<a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em></p>
<p>Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3962">Documentation interpolation</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-05-20 - 2026-06-17 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-05-20 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/313572925/"><strong>Mouse Control with Rust</strong></a></li>
</ul>
</li>
<li>2026-05-20 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/548kbqhl"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/313873203/"><strong>May, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455929/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Virtual (Charlottesville, VA, US) | <a href="https://www.meetup.com/charlottesville-rust-meetup">Charlottesville Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/charlottesville-rust-meetup/events/314477948/"><strong>Tock OS Part #4 - Capsule coding in QEMU!</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Virtual (Cardiff, GB) | <a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/">Rust and C++ Cardiff</a><ul>
<li><a href="https://www.meetup.com/rust-and-c-plus-plus-in-cardiff/events/314820642/"><strong>Hybrid event with Rust Dortmund!</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254781/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/313506048/"><strong>Lunch &amp; Learn: Seeing Into Your Code - A Practical Guide to Tracing in Rust</strong></a></li>
</ul>
</li>
<li>2026-05-27 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/9v7hv2g1"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-02 | Virtual | <a href="https://luma.com/libp2p">libp2p Events</a><ul>
<li><a href="https://luma.com/ukfh0mcf"><strong>rust-libp2p Open Maintainers Call</strong></a></li>
</ul>
</li>
<li>2026-06-03 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/314691782/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455930/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris/events/">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345241/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-06-07 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095285/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-06-09 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254780/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-06-10 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/3bcnx1jb"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc/events/">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/rdhhptyjcjbvb/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-06-02 | Virtual | <a href="https://luma.com/libp2p">libp2p Events</a><ul>
<li><a href="https://luma.com/pegz5x4h"><strong>rust-libp2p Open Maintainers Call</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ekws5nr4"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-17 | Virtual (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust/events/">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/314000478/"><strong>Rust Study/Hack/Hang-out</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-06-02 | Beijing, CN | <a href="https://www.meetup.com/wasm-rust-meetup/events/">Voice AI and Rust Meetup (Rust for AI, lowcoderust.com)</a><ul>
<li><a href="https://www.meetup.com/wasm-rust-meetup/events/314750465/"><strong>AI Agents and Open Source LLM (Call for Speakers)</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-05-18 - 2026-05-23 | Utrecht, NL | <a href="https://2026.rustweek.org/">RustWeek 2026</a><ul>
<li><a href="https://2026.rustweek.org/"><strong>RustWeek 2026</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Amsterdam, NL | <a href="https://www.meetup.com/rust-amsterdam">RustNL</a><ul>
<li><a href="https://www.meetup.com/rust-nederland/events/314301699/"><strong>RustWeek Hackathon</strong></a></li>
</ul>
</li>
<li>2026-05-22 | Amsterdam, NL | <a href="https://www.meetup.com/rust-amsterdam/events/">RustNL</a><ul>
<li><a href="https://www.meetup.com/rust-nederland/events/314770275/"><strong>Walking Tour around Utrecht</strong></a></li>
</ul>
</li>
<li>2026-05-22 | Amsterdam, NL | <a href="https://www.meetup.com/rust-amsterdam">RustNL</a><ul>
<li><a href="https://www.meetup.com/rust-nederland/events/314523659/"><strong>Bike tour around Utrecht</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Dortmund, DE | <a href="https://www.meetup.com/rust-dortmund">Rust Dortmund</a><ul>
<li><a href="https://www.meetup.com/rust-dortmund/events/314522781/"><strong>Rust Dortmund Meetup - Agentic Programming - May</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Manchester, UK | <a href="https://www.meetup.com/rust-manchester">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/314452972/"><strong>Rust Manchester May Code Night</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Trondheim, NO | <a href="https://www.meetup.com/rust-trondheim/events/">Rust Trondheim</a><ul>
<li><a href="https://www.meetup.com/rust-trondheim/events/314711434/"><strong>Motorized blinds, and replacing Docker, in Rust!</strong></a></li>
</ul>
</li>
<li>2026-05-28 | London, UK | <a href="https://www.meetup.com/rust-london-user-group/events/">Rust London User Group</a><ul>
<li><a href="https://www.meetup.com/rust-london-user-group/events/314846861/"><strong>LDN Talks May Community Showcase</strong></a></li>
</ul>
</li>
<li>2026-05-29 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/314396588/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-06-03 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin/events/">Rust Dublin</a><ul>
<li><a href="https://www.meetup.com/rust-dublin/events/314689875/"><strong>Join us live and INPERSON for Rust 261</strong></a></li>
</ul>
</li>
<li>2026-06-03 | Girona, ES | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/4bmlc7qd"><strong>Rust Girona Hack &amp; Learn 06 2026</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
<li>2026-06-16 | Leipzig, SN, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313813937/"><strong>Interactive: Everything is Open Source</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-05-20 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/313572925/"><strong>Mouse Control with Rust</strong></a></li>
</ul>
</li>
<li>2026-05-20 | San Francisco, CA, US | <a href="https://luma.com/bayarearust">Bay Area Rust Meetup</a><ul>
<li><a href="https://luma.com/9j3q5ejl"><strong>Bay Area Rust Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/313873203/"><strong>May, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-21 | New York, NY, US | <a href="https://www.meetup.com/rust-nyc/events/">Rust NYC</a><ul>
<li><a href="https://www.meetup.com/rust-nyc/events/314783868/"><strong>Rust NYC: "Boring File Storage" &amp; "Indie News Feed Optimization"</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Nashville, TN, US | <a href="https://www.meetup.com/music-city-rust-developers">Music City Rust Developers</a><ul>
<li><a href="https://www.meetup.com/music-city-rust-developers/events/314359076/"><strong>Community Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-23 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480534/"><strong>Allston Rust Lunch, May 23</strong></a></li>
</ul>
</li>
<li>2026-05-27 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/314209662/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-05-28 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539319/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-05-28 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/314218564/"><strong>Rust LA: Rust in Embedded &amp; Autonomous Systems at Parallel Systems in DTLA</strong></a></li>
</ul>
</li>
<li>2026-05-28 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/314716463/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-05-30 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480537/"><strong>Central Cambridge Rust Lunch, May 30</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust/events/">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/314106244/"><strong>Testing, Coverage, Tracey &amp; Mutations</strong></a></li>
</ul>
</li>
<li>2026-06-06 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480539/"><strong>Boston Common Rust Lunch, June 6</strong></a></li>
</ul>
</li>
<li>2026-06-11 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust/events/">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696643/"><strong>Utah Rust June Meetup</strong></a></li>
</ul>
</li>
<li>2026-06-11 | San Diego, CA, US | <a href="https://www.meetup.com/san-diego-rust/events/">San Diego Rust</a><ul>
<li><a href="https://www.meetup.com/san-diego-rust/events/313721899/"><strong>San Diego Rust June Meetup - Back in person!</strong></a></li>
</ul>
</li>
<li>2026-06-16 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group/events/">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/ghhwqtyjcjbvb/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-05-26 | Barton, ACT, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a><ul>
<li><a href="https://www.meetup.com/rust-canberra/events/314050576/"><strong>May Meetup</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1sobu1s/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>Posts like this are useful for those of us who like to help, and who work on rustc to make it more helpful, by letting us learn about what kinds of mistakes people make.</p>
</blockquote>
<p>– <a href="https://users.rust-lang.org/t/slightly-surprising-behavior-of-a-while-loop/140117/5">Kevin Reid on rust-users</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/crate-of-the-week/2704/1605">firebits.io</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1tj8ja6/this_week_in_rust_652/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hands-on with React, Supabase, and PowerSync]]></title>
<description><![CDATA[It’s not every day that a radically new architecture comes along, but here we are: in-browser SQLite, combined with reactive SQL and auto-syncing. The promise is instant interactivity on the front end, while maintaining data symmetry with the back end. As a direct challenger to the RESTful group-...]]></description>
<link>https://tsecurity.de/de/3517485/ai-nachrichten/hands-on-with-react-supabase-and-powersync/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517485/ai-nachrichten/hands-on-with-react-supabase-and-powersync/</guid>
<pubDate>Thu, 14 May 2026 19:18:34 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>It’s not every day that a radically new architecture comes along, but here we are: <a href="https://sqlite.org/wasm/doc/trunk/index.md" data-type="link" data-id="https://sqlite.org/wasm/doc/trunk/index.md">in-browser SQLite</a>, combined with <a href="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html" data-type="link" data-id="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html">reactive SQL</a> and auto-syncing. The promise is instant interactivity on the front end, while maintaining data symmetry with the back end. As a direct challenger to the <a href="https://www.infoworld.com/article/2334742/what-is-rest-the-de-facto-web-architecture-standard.html" data-type="link" data-id="https://www.infoworld.com/article/2334742/what-is-rest-the-de-facto-web-architecture-standard.html">RESTful group-think</a> that has dominated web development for a decade, it is well worth a look. </p>



<h2 class="wp-block-heading">Not really new, but improved</h2>



<p>This idea isn’t brand new. Developers have been doing this kind of thing in one fashion or another for years (think of how some apps work offline). But this new-generation stack feels different, and it’s starting to see broader appeal. </p>



<p>It’s called local-first data. I recently <a href="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html" data-type="link" data-id="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html">covered the idea at a high level</a>. Now it’s time for a look at the nitty gritty.</p>



<p>The concept is simple. Instead of asking a remote server for permission to change a number, your app writes state directly to a local SQLite database running in the browser (via <a href="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html">WebAssembly</a>). A sophisticated background engine then handles the hard work of syncing those changes to the cloud and other devices.</p>



<p>For React developers, the best part is that we remain in the reactive paradigm. Even though we are writing raw <a href="https://www.infoworld.com/article/2255395/what-is-sql-the-lingua-franca-of-data-analysis.html" data-type="link" data-id="https://www.infoworld.com/article/2255395/what-is-sql-the-lingua-franca-of-data-analysis.html">SQL</a> queries, the shuffling of the data is handled for us. Our UI components subscribe to the database, and when the data changes (whether locally from a user click or an inbound sync update from the cloud), the UI updates instantly.</p>



<p>When you use Spotify, you don’t download their entire multi-million song catalog. You just download your list and, even if you are offline, you listen to your music lag-free. This is the same kind of model we are building with local-first data, but with a lot of extra power. We can make changes to our local state, and those changes will be synced with the back end when a connection is available. And correspondingly, we will automatically receive important updates from the world.</p>



<h2 class="wp-block-heading">Three architectural components</h2>



<p>To pull this off we need three major architectural components:</p>



<ul class="wp-block-list">
<li>The client-side UI and database (React and SQLite Wasm )</li>



<li>A syncing engine (PowerSync)</li>



<li>A database of record (Supabase)</li>
</ul>



<p>Let’s start by setting up the cloud services we need: Supabase and PowerSync, both of which will be free-tier. For our client-side UI and database, we’ll make use of a React+SQLite demo app provided by Supabase. </p>



<h3 class="wp-block-heading">Supabase – the database of record</h3>



<p>Supabase is a managed Postgres service with a lot of niceties. Our example is going to be very simple, with only one row required. Go to <a href="http://supabase.com/">Supabase.com</a>, create a free account, and start a new project. Clicking on the project will bring you to its details:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/React-Supabase-PowerSync-01.png?w=1024" alt="React-Supabase-PowerSync 01" class="wp-image-4168592" width="1024" height="406" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Foundry</p></div>



<p>Next we create a database schema to hold our data, which will be a simple one. On the left side menu, open the SQL Editor and run the following code.</p>



<pre class="wp-block-code"><code>-- 1. Create the table to store our counters
CREATE TABLE counters (
  id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
  created_at TIMESTAMPTZ DEFAULT NOW(),
  count INTEGER DEFAULT 0,
  owner_id UUID DEFAULT auth.uid()
);

-- 2. Turn on Row Level Security (RLS) 
ALTER TABLE counters ENABLE ROW LEVEL SECURITY;

-- 3. Access Policies 
CREATE POLICY "Users can all on own counters" 
ON counters FOR ALL 
USING (auth.uid() = owner_id);

-- 4. Publish the table
DROP PUBLICATION IF EXISTS powersync;
CREATE PUBLICATION powersync FOR TABLE counters;
</code></pre>



<p>Each step is annotated within the code above. The first step is standard SQL, creating a table with a few columns including a random UUID primary key. The second step turns on <a href="https://supabase.com/docs/guides/database/postgres/row-level-security">row level security</a>. The third step creates an access policy allowing users access to their own counter row (as determined by their logged in id: <code>auth.uid() = owner_id</code>). The fourth step creates a link between the Supabase instance and PowerSync.</p>



<p>Before we leave Supabase, click the “+ Connect” button at the top and grab the connection string, which looks something like this:</p>



<pre class="wp-block-code"><code>postgresql://postgres:[YOUR-PASSWORD]@db.fooizpddffaabqcydusj.supabase.co:5432/postgres</code></pre>



<h3 class="wp-block-heading">PowerSync – the syncing engine</h3>



<p>Now let’s jump into PowerSync. Go to <a href="https://powersync.com/" data-type="link" data-id="https://powersync.com/">PowerSync.com</a>, create a free account, and start a new project. Open the project details:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/React-Supabase-PowerSync-02.png?w=1024" alt="React-Supabase-PowerSync 02" class="wp-image-4168596" width="1024" height="454" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Foundry</p></div>



<p>In the PowerSync dashboard, we need to create a bridge to Supabase. Follow these steps: </p>



<ol class="wp-block-list">
<li>Click “Create New Instance”.</li>



<li>Click the “Database Connections” item on the left, then click the + button.</li>



<li>Paste the connection string you copied from Supabase. Note: If your string has a <code>[YOUR-PASSWORD]</code> placeholder, replace it with the actual password you created for the instance.</li>



<li>Click “Test Connection”.</li>
</ol>



<p>PowerSync will now reach out to the Postgres instance we created before. If you ran the <code>CREATE PUBLICATION SQL</code> command correctly in the Supabase setup, this will succeed, and you’ll see a green “Connection Successful!” status message.</p>



<h4 class="wp-block-heading">Configure authentication</h4>



<p>We told PowerSync how to <em>read</em> our Supabase data (Postgres). Now we need tell it how to <em>trust</em> our users. Here are the steps: </p>



<ol class="wp-block-list">
<li>In the PowerSync dashboard, click the “Client Auth” tab</li>



<li>Look for the “JWKS URI” field.</li>



<li>Construct your JWKS URL. It is your Supabase Project URL + a specific suffix. 
<ul class="wp-block-list">
<li>Format: <code>https://[YOUR-PROJECT-ID].supabase.co/auth/v1/.well-known/jwks.json</code></li>



<li>Note: You can get your Project URL from Supabase &gt; Settings &gt; API.</li>
</ul>
</li>



<li>Paste your JWKS URL into the JWKS URI field and click “Save”.</li>



<li>Set the Audience to “authenticated”:
<ul class="wp-block-list">
<li>Click the (+) Add button under “Token Claims”.</li>



<li>Claim: Type <code>aud</code></li>



<li>Value: Type <code>authenticated</code></li>
</ul>
</li>
</ol>



<p>This configuration tells PowerSync, “Only trust tokens that are signed by Supabase AND are meant for the ‘authenticated’ user group.”</p>



<h4 class="wp-block-heading">Define the sync rules</h4>



<p>The sync rules are the essential architectural element to understand. This is where we tell Powersync what <em>part </em>of the data the user is privy to. This is sometimes called the “data shape” for the user. Each user has their own shape of the overall data, based on their unique profile.</p>



<p>We do not want to sync the <em>entire</em> database to the user’s laptop. That would be bad on many levels. Instead, we define a sync rule (or “bucket” in PowerSync), which is a filter that determines what data belongs to which user.</p>



<p>Navigate to “Sync Rules” on the left. You’ll get a YAML editor. Replace the default code with the following code.</p>



<pre class="wp-block-code"><code>YAML
config:
  edition: 2

bucket_definitions:
  user_counters:
    # 1. Identify the user from their Auth Token
    parameters: SELECT request.user_id() as user_id

    # 2. Only sync rows that belong to them
    data:
      - SELECT * FROM counters WHERE owner_id = bucket.user_id
</code></pre>



<p>This code defines the special view of the data for users:</p>



<ul class="wp-block-list">
<li><code>user_counters</code>: This is a “bucket”, a collection of data</li>



<li><code>request.user_id()</code>: PowerSync automatically extracts the user id from the Supabase auth token.</li>



<li>The data query: This SQL runs in the cloud, grabbing only the rows where the <code>owner_id</code> column matches the logged-in user and streams them down to the device.</li>
</ul>



<p>You can click “Validate” to check that this is working. Click “Deploy” to make it live.</p>



<h2 class="wp-block-heading">React and SQLite – the client-side UI and database</h2>



<p>We have done a lot of administrative work here, but it is giving us an entire reactive architecture based on SQL. Let’s push ahead with a client that can use it.</p>



<p>To get a quick look, let’s clone a demo app from Supabase. At the command line, run: </p>



<pre class="wp-block-code"><code>$ git clone https://github.com/powersync-community/vite-react-ts-powersync-supabase.git
$ cd vite-react-ts-powersync-supabase
$ npm install
</code></pre>



<p>Once the npm command finishes, we want to point the app at the infrastructure we just created. We can do that using the <code>.env.local</code> environmental variable file. Open <code>.env.local</code> and change the vars to point to your services. Here is the code:</p>



<pre class="wp-block-code"><code>VITE_SUPABASE_URL=https://fooizpddffaabqcydusj.supabase.co
VITE_SUPABASE_ANON_KEY=sb_publishable_gqUrYxDt04rg74fopz5rUg_ayDxpmgE
VITE_POWERSYNC_URL=https://foofcf18cc2560584a018a12.powersync.journeyapps.com
</code></pre>



<p>We are ready to test our React app:</p>



<pre class="wp-block-code"><code>$ npm run dev:ui
</code></pre>



<p>The demo app is a simple counter—a web page that presents an “Increment” button and shows the count. None too exciting, except for the data syncing magic behind the scenes. </p>



<p>Run the above command, and a browser window will open showing a “Create Counter” button. When you click it, the demo will give you a counter in a new window, along with a user ID and a panel that shows connection and sync status. You can create as many counters as you like, each in a separate browser window. </p>



<p>You can verify your counter is working by going to the Supabase dashboard, looking at the “Table” pane and seeing that a row has indeed been inserted for your user in the counter table. Another good check is to log in using another browser/device (or incognito tab). </p>



<p>Log in and create another counter in the second browser window, so that you have two different Supabase-synced session counters side by side: </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/React-Supabase-PowerSync-03-1.png" alt="React-Supabase-PowerSync 03" class="wp-image-4169002" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Foundry</p></div>



<p>Whenever you create a new counter, a new row will be inserted into Supabase. The screenshot below shows a Supabase table with two rows, each with its own user ID and counter value. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/React-Supabase-PowerSync-04.png" alt="React-Supabase-PowerSync 04" class="wp-image-4169007" width="1024" height="487" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Foundry</p></div>



<h3 class="wp-block-heading">The React code (App.tsx)</h3>



<p>We are moving quickly, but there are some interesting things to make note of in the src/App.tsx file. This code is the main React code for the app, and demonstrates the shift from “asking the server” to “interacting with local database state.” </p>



<p>There are two landmarks here that every React developer needs to see: the reactive read and the instant write. </p>



<h4 class="wp-block-heading">The reactive read (useQuery)</h4>



<p>In a standard React app, we would retrieve the data by using a <code>useEffect</code> to call <code>fetch('/api/counters')</code>. In our local-first React app, we use raw SQL:</p>



<pre class="wp-block-code"><code>const { data: counters, isLoading } = useQuery<counterrecord>(
  `SELECT * FROM ${COUNTER_TABLE} ORDER BY created_at ASC`,
  [],
  {
    rowComparator: {
      keyBy: (item) =&gt; item.id,
      compareBy: (item) =&gt; JSON.stringify(item)
    }
  }
);
</counterrecord></code></pre>



<p>This is the “reactive SQL” part of the architecture.</p>



<p>This <code>useQuery</code> hook subscribes to the local SQLite database. When the background worker receives an update from the cloud—or when you update a row locally—this hook fires instantly and re-renders the component. No manual state management or re-fetching logic is required, and there is no intermediate object of state. The back-end state and the front-end state are the same.</p>



<h4 class="wp-block-heading">The instant write (powerSync.execute)</h4>



<p>Notice what happens when we increment the counter. There is no <code>await api.post(...)</code> and no loading spinner state.</p>



<pre class="wp-block-code"><code>const updateCounter = async (counter: CounterRecord, newCount: number) =&gt; {
  // Writes to Local SQLite immediately
  await powerSync.execute(
    `UPDATE ${COUNTER_TABLE} SET count = ? WHERE owner_id = ?`,
    [newCount, counter.owner_id]
  );
};
</code></pre>



<p>This code is interesting on its own, because it’s like a reactive SQL statement. We write to the local file (Wasm). The write completes in milliseconds, and the UI updates immediately via the <code>useQuery</code> hook. The PowerSync syncing engine picks up the change asynchronously and pushes it to Supabase.</p>



<h2 class="wp-block-heading">The local-first vs. RESTful calculation</h2>



<p>So, is all of this configuration and newfangled code worth it?</p>



<p>If you are building a simple dashboard or a form-based application, the traditional JSON API (REST or GraphQL) approach is still king. In those models, the server is the single source of truth, and the client is just a dumb terminal. It is simple, stateless, and easy to debug. It’s also familiar.</p>



<p>But that simplicity comes with an unavoidable latency cost. Every interaction requires a round-trip ticket to the server. If the network hiccups, your app freezes. JSON APIs force you to manage loading states, error boundaries, and optimistic UI rollbacks manually.</p>



<p>Local-first flips the calculation. You pay a higher cost up front: you have to define a schema, manage a local database, and think about syncing rules. But in exchange, you get an application that feels like a native piece of software. Local-first creates data continuity, the ability to walk out of Wi-Fi range, keep working, and have your data follow you across devices when you reconnect.</p>



<p>Architecturally, we used three major components: the database, the syncing engine, and the client. This is actually similar to your conventional RESTful stack. In the local-first structure, the syncing engine takes the place of the JSON API server. In short, you have a similar amount of high-level complexity, but with different actors on the ground.</p>



<p>Local-first architecture is a fascinating development for JavaScript and the web in general. There is a huge inertial mass of JSON APIs to overcome, but here is a real countercurrent. Local-first may never rise to the level of adoption of RESTful architecture, but local-first data and reactive SQL constitute one of the most important trends to be watching closely right now.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[This Week In Rust: This Week in Rust 651]]></title>
<description><![CDATA[Hello and welcome to another issue of This Week in Rust!
Rust is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
@thisweekinrust.bsky.social on Bluesky or
@ThisWeekinRu...]]></description>
<link>https://tsecurity.de/de/3515481/tools/this-week-in-rust-this-week-in-rust-651/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515481/tools/this-week-in-rust-this-week-in-rust-651/</guid>
<pubDate>Thu, 14 May 2026 04:07:37 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello and welcome to another issue of <em>This Week in Rust</em>!
<a href="https://www.rust-lang.org/">Rust</a> is a programming language empowering everyone to build reliable and efficient software.
This is a weekly summary of its progress and community.
Want something mentioned? Tag us at
<a href="https://bsky.app/profile/thisweekinrust.bsky.social">@thisweekinrust.bsky.social</a> on Bluesky or
<a href="https://mastodon.social/@thisweekinrust">@ThisWeekinRust</a> on mastodon.social, or
<a href="https://github.com/rust-lang/this-week-in-rust">send us a pull request</a>.
Want to get involved? <a href="https://github.com/rust-lang/rust/blob/main/CONTRIBUTING.md">We love contributions</a>.</p>
<p><em>This Week in Rust</em> is openly developed <a href="https://github.com/rust-lang/this-week-in-rust">on GitHub</a> and archives can be viewed at <a href="https://this-week-in-rust.org/">this-week-in-rust.org</a>.
If you find any errors in this week's issue, <a href="https://github.com/rust-lang/this-week-in-rust/pulls">please submit a PR</a>.</p>
<p>Want TWIR in your inbox? <a href="https://this-week-in-rust.us11.list-manage.com/subscribe?u=fd84c1c757e02889a9b08d289&amp;id=0ed8b72485">Subscribe here</a>.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-rust-community">Updates from Rust Community</a></h4>


<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#foundation">Foundation</a></h5>
<ul>
<li><a href="https://rustfoundation.org/media/rust-foundation-and-package-registry-leaders-unite-to-address-open-source-sustainability-crisis/">Rust Foundation and Package Registry Leaders Unite to Address Open Source Sustainability Crisis</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#newsletters">Newsletters</a></h5>
<ul>
<li><a href="https://www.theembeddedrustacean.com/p/the-embedded-rustacean-issue-71">The Embedded Rustacean Issue #71</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#projecttooling-updates">Project/Tooling Updates</a></h5>
<ul>
<li><a href="https://github.com/GianIac/numax/releases/tag/v0.1.0-alpha.1">Numax - A portable Rust runtime for distributed apps</a></li>
<li><a href="https://github.com/juyterman1000/entroly/discussions/43">Entroly 0.18.0: Rust-powered AI context engine with PRISM reinforcement learning, SimHash dedup, and EGSC caching</a></li>
<li><a href="https://www.theembeddedrustacean.com/uferris">uFerris: A Versatile Learning Board for Rust Embedded</a></li>
<li><a href="https://aimdb.dev/blog/record-ownership">Record Ownership: Which Side Is Right?</a></li>
<li><a href="https://www.iroh.computer/blog/iroh-1-0-0-rc-0">iroh 1.0.0-rc.0 - The first release candidate</a></li>
<li><a href="https://burn.dev/blog/release-0.21.0/">Burn 0.21.0 Release: Up to 8× Lower Framework Overhead, Differentiable Collectives and Improved Kernels</a></li>
<li><a href="https://blog.orhun.dev/introducing-ratty/">Ratty: A terminal emulator with inline 3D graphics</a></li>
<li><a href="https://this-week-in-rust.org/blog/2026/05/06/this-week-in-rust-650/">Announcing the Rust runtime for Appwrite Functions</a></li>
<li><a href="https://blog.weiznich.de/blog/diesel-async-0-9/">Announcing diesel-async 0.9</a></li>
<li><a href="https://github.com/sinelaw/fresh/releases/tag/v0.3.4">Fresh 0.3.4: Ansi-native 'terminal' theme matches the system's theme; UI for Live Grep + custom grep providers; persistent 'dock' split; Verilog/VHDL support; and much more</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#observationsthoughts">Observations/Thoughts</a></h5>
<ul>
<li><a href="https://jacobasper.com/blog/killing-a-cow-made-my-json-formatter-42-percent-faster/">Killing a <code>Cow</code> made my JSON formatter 42% faster</a></li>
<li><a href="https://eors-workspace-a6ef35.gitlab.io/posts/001-introduction-geospatial-rust/">Getting Started with Geospatial Rust</a> — What satellites measure, spectral bands, indices, cloud detection.</li>
<li><a href="https://pawelurbanek.com/rust-performance-profiling">Lessons Learned Building High-Performance Rust Profiler</a></li>
<li><a href="https://kerkour.com/the-limits-of-rust">The limits of Rust, or why you should probably not follow Amazon, Cloudflare and Discord</a></li>
<li><a href="https://blog.howardjohn.info/posts/mpsc-cost/">The hidden cost of mpsc channels</a></li>
<li><a href="https://verrchu.github.io/blog/2-respectful-yaml-patching-in-rust/">"Respectful" YAML patching in Rust</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-walkthroughs">Rust Walkthroughs</a></h5>
<ul>
<li><a href="https://blog.sheerluck.dev/posts/learn-generics-traits-in-rust-by-building-blackjack-card-game-engine/">Learn Rust Generics and Traits By Building a Mini Blackjack Game</a></li>
<li><a href="https://0xkiire.com/build-text-editor-from-scratch/">Build a Full-Featured Text Editor From Scratch | 0xKiire</a></li>
<li><a href="https://bitfieldconsulting.com/posts/sun-keeps-shinin">Where the sun keeps shinin': the provider pattern</a></li>
<li><a href="https://eors-workspace-a6ef35.gitlab.io/posts/002-end-to-end-workflow/">End-to-End Geospatial Processing with EORST</a> — Build a satellite pipeline in Rust: STAC query to GeoTIFF.</li>
<li><a href="https://blog.appliedcomputing.io/p/all-the-ways-to-mock-your-rust-code">All the ways to mock your Rust code</a></li>
<li><a href="https://chayanmistry.medium.com/rust-in-android-development-complete-guide-5f3313f40e50">Rust in Android Development: Complete Guide</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#miscellaneous">Miscellaneous</a></h5>
<ul>
<li><a href="https://rust-edu.org/news/call-for-participation/">Announcing the 2026 Rust-Edu Refresh and CFP</a></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#crate-of-the-week">Crate of the Week</a></h4>
<p>This week's crate is <a href="https://github.com/kadir/cloakrs">cloakrs</a>, a library and CLI tool for detecting and masking personally identifiable information.</p>
<p>Despite having no suggestion to work with, llogiq is content with his choice.</p>
<p><a href="https://users.rust-lang.org/t/crate-of-the-week/2704">Please submit your suggestions and votes for next week</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#calls-for-testing">Calls for Testing</a></h4>
<p>An important step for RFC implementation is for people to experiment with the
implementation and give feedback, especially before stabilization.</p>
<p>If you are a feature implementer and would like your RFC to appear in this list, add a
<code>call-for-testing</code> label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.</p>
<p><em>No calls for testing were issued this week by
<a href="https://github.com/rust-lang/rust/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rust</a>,
<a href="https://github.com/rust-lang/cargo/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/rustup/issues?q=state%3Aopen%20label%3Acall-for-testing%20state%3Aopen">Rustup</a> or
<a href="https://github.com/rust-lang/rfcs/issues?q=label%3Acall-for-testing%20state%3Aopen">Rust language RFCs</a>.</em></p>
<p><a href="https://github.com/rust-lang/this-week-in-rust/issues">Let us know</a> if you would like your feature to be tracked as a part of this list.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#call-for-participation-projects-and-speakers">Call for Participation; projects and speakers</a></h4>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-projects">CFP - Projects</a></h5>
<p>Always wanted to contribute to open-source projects but did not know where to start?
Every week we highlight some tasks from the Rust community for you to pick and get started!</p>
<p>Some of these tasks may also have mentors available, visit the task page for more information.</p>


<p><em>No Calls for participation were submitted this week.</em></p>
<p>If you are a Rust project owner and are looking for contributors, please submit tasks <a href="https://github.com/rust-lang/this-week-in-rust?tab=readme-ov-file#call-for-participation-guidelines">here</a> or through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cfp-events">CFP - Events</a></h5>
<p>Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.</p>



<ul>
<li><a href="https://scientificcomputing.rs/2026/submit-talk"><strong>Scientific Computing in Rust 2026</strong></a>| 2026-06-05 | Virtual | 2026-07-08 - 2026-07-10</li>
</ul>
<p>If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a <a href="https://github.com/rust-lang/this-week-in-rust">PR to TWiR</a> or by reaching out on <a href="https://bsky.app/profile/thisweekinrust.bsky.social">Bluesky</a> or <a href="https://mastodon.social/@thisweekinrust">Mastodon</a>!</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#updates-from-the-rust-project">Updates from the Rust Project</a></h4>
<p>502 pull requests were <a href="https://github.com/search?q=is%3Apr+org%3Arust-lang+is%3Amerged+merged%3A2026-05-05..2026-05-12">merged in the last week</a></p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#compiler">Compiler</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/148214">consider <code>Result&lt;T, Uninhabited&gt;</code> and <code>ControlFlow&lt;Uninhabited, T&gt;</code> to be equivalent to <code>T</code> for must use lint</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156173">fewer global <code>node_id_to_def_id</code> lookups</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155023">introduce move expressions (<code>move($expr)</code>)</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156185">resolve: evaluate private visibilities eagerly in eff vis computation</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#library">Library</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/149362">add <code>Command::get_resolved_envs</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/144537">add <code>Drop::pin_drop</code> for pinned drops</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/154025">add <code>keepalive</code>, <code>set_keepalive</code> to <code>TcpStream</code> implementations</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/152487">drop unmapped ZSTs in array <code>map</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155184">have arrays' <code>drop_glue</code> just unsize and call the slice version</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/156204">implemented <code>PathBuf::into_string</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#cargo">Cargo</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/16981"><code>diag</code>: Track Cargo diagnostic warning/error count like is done for rustc</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16985">suggest 'fmt' when user types 'cargo rustfmt'</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16965">rebuild when -Zpublic-dependency changes</a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#clippy">Clippy</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16486">add new lint <code>inline_trait_bounds</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16617">new lint: <code>manual_clear</code></a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16970">fix <code>manual_option_zip</code> false positive when the outer param is used in closure</a></li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16949">incompatibility of <code>non_canonical_clone_impl</code> and <code>implicit_return</code></a></li>
</ul>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-analyzer">Rust-Analyzer</a></h6>
<ul>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22256">add wrap in tree list with editor</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22309">add diagnostic for E0436</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22334">add diagnostic for E0529</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22259">complete <code>:</code>: on module def</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22292">support deref patterns</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22315">add whitespaces on postfix completion in macro</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22198">do not infer signatures, instead infer anon consts in them</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22319">do not replace closure capture place types with errors if they fail to normalize</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22266">fix handling of <code>self</code> in <code>lower_coroutine_body_with_moved_arguments()</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22304">fix offer on unrelated for <code>toggle_macro_delimiter</code></a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22299">generally fix derive helper resolution in semantics</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22291">in "Implement missing members", do not add assoc types with defaults</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22302">no add spaces on <code>..=</code> on macro inside macro</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22237">provide an InferCtxt to TyLoweringContext</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22318">provide source map for the lowered <code>let self = self</code> binding in async fns</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22285">ref match uses unified type</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22303">renaming mut vars removed <code>mut</code> in patterns generated by macro</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22290">respect lint attributes for diagnostics that don't set their main node</a></li>
<li><a href="https://github.com/rust-lang/rust-analyzer/pull/22310">remove make mut</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-compiler-performance-triage">Rust Compiler Performance Triage</a></h5>
<p>This week saw a couple of PRs affecting the new trait solver, which is steadily moving forward,
in particular <a href="https://github.com/rust-lang/rust/pull/156139">#156139</a> was a massive perf. win.
<a href="https://github.com/rust-lang/rust/pull/156185">#156185</a> optimized visibility computation, resulting
in up to a 8% win on the <code>typenum</code> crate.</p>
<p>Triage done by <strong>@Kobzol</strong>.
Revision range: <a href="https://perf.rust-lang.org/?start=1d72d7e8136faaebad3a85eeed432e6ea1b2ffab&amp;end=aa31d6d8020dcb7c6e6635648d1ca2bc18caf059&amp;absolute=false&amp;stat=instructions%3Au">1d72d7e8..aa31d6d8</a></p>
<p><strong>Summary</strong>:</p>
<table>
<thead>
<tr>
<th>(instructions:u)</th>
<th>mean</th>
<th>range</th>
<th>count</th>
</tr>
</thead>
<tbody>
<tr>
<td>Regressions ❌ <br> (primary)</td>
<td>0.3%</td>
<td>[0.1%, 0.4%]</td>
<td>62</td>
</tr>
<tr>
<td>Regressions ❌ <br> (secondary)</td>
<td>0.5%</td>
<td>[0.1%, 1.5%]</td>
<td>77</td>
</tr>
<tr>
<td>Improvements ✅ <br> (primary)</td>
<td>-1.7%</td>
<td>[-8.8%, -0.2%]</td>
<td>18</td>
</tr>
<tr>
<td>Improvements ✅ <br> (secondary)</td>
<td>-13.6%</td>
<td>[-85.6%, -0.0%]</td>
<td>34</td>
</tr>
<tr>
<td>All ❌✅ (primary)</td>
<td>-0.2%</td>
<td>[-8.8%, 0.4%]</td>
<td>80</td>
</tr>
</tbody>
</table>
<p>2 Regressions, 2 Improvements, 5 Mixed; 4 of them in rollups
31 artifact comparisons made in total</p>
<p><a href="https://github.com/rust-lang/rustc-perf/blob/d4003fd3999eabaef2bca2c218d10f7547425a96/triage/2026/2026-05-12.md">Full report here</a>.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#approved-rfcs"></a><a href="https://github.com/rust-lang/rfcs/commits/master">Approved RFCs</a></h5>
<p>Changes to Rust follow the Rust <a href="https://github.com/rust-lang/rfcs#rust-rfcs">RFC (request for comments) process</a>. These
are the RFCs that were approved for implementation this week:</p>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3931">Rust Foundation Maintainer Fund</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3945">RFC: Inheriting of default-features in Cargo</a></li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#final-comment-period">Final Comment Period</a></h5>
<p>Every week, <a href="https://www.rust-lang.org/team.html">the team</a> announces the 'final comment period' for RFCs and key PRs
which are reaching a decision. Express your opinions now.</p>
<h6><a class="toclink" href="https://this-week-in-rust.org/atom.xml#tracking-issues-prs">Tracking Issues &amp; PRs</a></h6>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust"></a><a href="https://github.com/rust-lang/rust/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Rust</a>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/156379">lint on <code>core::ffi::c_void</code> as a return type</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/156477">Tracking issue for release notes of #154647: change <code>c_double</code> to <code>f32</code> on <code>avr</code> targets</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155307">Stabilize <code>--remap-path-prefix</code> in rustdoc</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/155527">Replace printables table with <code>unicode_data.rs</code> tables</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/44930">Tracking issue for RFC 2137: Support defining C-compatible variadic functions in Rust (c_variadic</a></li>
<li><a href="https://github.com/rust-lang/rust/issues/148494">Tracking Issue for <code>Path::is_empty</code></a></li>
<li><a href="https://github.com/rust-lang/rust/issues/138215">Tracking Issue for integer formatting into a fixed-size buffer</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/149195">resolve: Partially convert <code>ambiguous_glob_imports</code> lint into a hard error</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#rust-rfcs"></a><a href="https://github.com/rust-lang/rfcs/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Rust RFCs</a>
<ul>
<li><a href="https://github.com/rust-lang/rfcs/pull/3946">Propose the concept of a crates.io username for identity</a></li>
<li><a href="https://github.com/rust-lang/rfcs/pull/3923">Cargo RFC for min publish age</a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#language-reference"></a><a href="https://github.com/rust-lang/reference/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Reference</a>
<ul>
<li><a href="https://github.com/rust-lang/reference/pull/2264">New rule <code>layout.repr.c.struct.align-empty</code></a></li>
</ul>
<a class="toclink" href="https://this-week-in-rust.org/atom.xml#leadership-council"></a><a href="https://github.com/rust-lang/leadership-council/issues?q=state%3Aopen%20label%3Afinal-comment-period%20state%3Aopen">Leadership Council</a>
<ul>
<li><a href="https://github.com/rust-lang/leadership-council/issues/294">Establish the funding team</a></li>
</ul>
<p><em>No Items entered Final Comment Period this week for
<a href="https://github.com/rust-lang/cargo/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Cargo</a>,
<a href="https://github.com/rust-lang/compiler-team/issues?q=label%3Amajor-change%20label%3Afinal-comment-period%20state%3Aopen">Compiler Team</a> <a href="https://forge.rust-lang.org/compiler/mcp.html">(MCPs only)</a>,
<a href="https://github.com/rust-lang/lang-team/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Language Team</a> or
<a href="https://github.com/rust-lang/unsafe-code-guidelines/issues?q=is%3Aopen%20label%3Afinal-comment-period%20sort%3Aupdated-desc%20state%3Aopen">Unsafe Code Guidelines</a>.</em>
Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#new-and-updated-rfcs"></a><a href="https://github.com/rust-lang/rfcs/pulls">New and Updated RFCs</a></h5>
<ul>
<li><em>No New or Updated RFCs were created this week.</em></li>
</ul>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#upcoming-events">Upcoming Events</a></h4>
<p>Rusty Events between 2026-05-13 - 2026-06-10 🦀</p>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#virtual">Virtual</a></h5>
<ul>
<li>2026-05-17 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314329043/"><strong>Rust Deep Learning: Third Sunday</strong></a></li>
</ul>
</li>
<li>2026-05-19 | Virtual (Washington, DC, US) | <a href="https://www.meetup.com/rustdc">Rust DC</a><ul>
<li><a href="https://www.meetup.com/rustdc/events/rdhhptyjchbzb/"><strong>Mid-month Rustful</strong></a></li>
</ul>
</li>
<li>2026-05-20 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/313572925/"><strong>Mouse Control with Rust</strong></a></li>
</ul>
</li>
<li>2026-05-20 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/548kbqhl"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/313873203/"><strong>May, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455929/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Virtual (Charlottesville, VA, US) | <a href="https://www.meetup.com/charlottesville-rust-meetup">Charlottesville Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/charlottesville-rust-meetup/events/314477948/"><strong>Tock OS Part #4 - Capsule coding in QEMU!</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254781/"><strong>Fourth Tuesday</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Virtual (London, UK) | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/313506048/"><strong>Lunch &amp; Learn: Seeing Into Your Code - A Practical Guide to Tracing in Rust</strong></a></li>
</ul>
</li>
<li>2026-05-27 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/9v7hv2g1"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
<li>2026-06-03 | Virtual (Indianapolis, IN, US) | <a href="https://www.meetup.com/indyrs">Indy Rust</a><ul>
<li><a href="https://www.meetup.com/indyrs/events/wqzhftyjcjbfb/"><strong>Indy.rs - with Social Distancing</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Virtual (Berlin, DE) | <a href="https://www.meetup.com/rust-berlin/events/">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/308455930/"><strong>Rust Hack and Learn</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Virtual (Nürnberg, DE) | <a href="https://www.meetup.com/rust-noris/events/">Rust Nuremberg</a><ul>
<li><a href="https://www.meetup.com/rust-noris/events/313345241/"><strong>Rust Nürnberg online</strong></a></li>
</ul>
</li>
<li>2026-06-07 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/314095285/"><strong>Rust Deep Learning: First Sunday</strong></a></li>
</ul>
</li>
<li>2026-06-09 | Virtual (Dallas, TX, US) | <a href="https://www.meetup.com/dallasrust/events/">Dallas Rust User Meetup</a><ul>
<li><a href="https://www.meetup.com/dallasrust/events/310254780/"><strong>Second Tuesday</strong></a></li>
</ul>
</li>
<li>2026-06-10 | Virtual (Girona, ES) | <a href="https://lu.ma/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/3bcnx1jb"><strong>Weekly coding session</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#asia">Asia</a></h5>
<ul>
<li>2026-05-13 | Malaysia, MY | <a href="https://docs.google.com/forms/d/e/1FAIpQLSfMh6PA05ujl3lS59tJU3DcLHGVZ1zjzJhl49hXEHU7e6vsQA/viewform">Rust Meetup Malaysia</a><ul>
<li><a href="https://docs.google.com/forms/d/e/1FAIpQLSfMh6PA05ujl3lS59tJU3DcLHGVZ1zjzJhl49hXEHU7e6vsQA/viewform"><strong>Rust Meetup May 2026</strong></a></li>
</ul>
</li>
<li>2026-05-14 | Seoul, KR | <a href="https://www.meetup.com/rust-seoul-meetup">Seoul Rust (Programming Language) Meetup</a><ul>
<li><a href="https://www.meetup.com/rust-seoul-meetup/events/314649688/"><strong>Seoul Rust Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-16 | Bangalore, IN | <a href="https://hasgeek.com/rustbangalore">Rust Bangalore</a><ul>
<li><a href="https://hasgeek.com/rustbangalore/may-2026-rustacean-meetup/"><strong>May 2026 Rustacean meetup</strong></a></li>
</ul>
</li>
<li>2026-06-02 | Beijing, CN | <a href="https://www.meetup.com/wasm-rust-meetup/events/">Voice AI and Rust Meetup (Rust for AI, lowcoderust.com)</a><ul>
<li><a href="https://www.meetup.com/wasm-rust-meetup/events/314750465/"><strong>AI Agents and Open Source LLM (Call for Speakers)</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#europe">Europe</a></h5>
<ul>
<li>2026-05-13 | Girona, ES | <a href="https://luma.com/rust-girona">Rust Girona</a><ul>
<li><a href="https://luma.com/ooub1kt0"><strong>Rust Girona Hack &amp; Learn 05 2026</strong></a></li>
</ul>
</li>
<li>2026-05-14 | Switzerland, CH | <a href="https://www.posttenebraslab.ch/wiki/events/start">PostTenebrasLab</a><ul>
<li><a href="https://www.posttenebraslab.ch/wiki/events/monthly_meeting/rust_meetup"><strong>Rust Meetup Geneva</strong></a></li>
</ul>
</li>
<li>2026-05-18 - 2026-05-23 | Utrecht, NL | <a href="https://2026.rustweek.org/">RustWeek 2026</a><ul>
<li><a href="https://2026.rustweek.org/"><strong>RustWeek 2026</strong></a></li>
</ul>
</li>
<li>2026-05-18 | Milano, MI, IT | <a href="https://www.meetup.com/rust-language-milano">Rust Language Milan</a><ul>
<li><a href="https://www.meetup.com/rust-language-milan/events/314329200/"><strong>RustWeek 2026</strong></a></li>
</ul>
</li>
<li>2026-05-19 | Aarhus, DK | <a href="https://www.meetup.com/rust-aarhus">Rust Aarhus</a><ul>
<li><a href="https://www.meetup.com/rust-aarhus/events/314129975/"><strong>Hack Night</strong></a></li>
</ul>
</li>
<li>2026-05-19 | Amsterdam, NL | <a href="https://www.meetup.com/rust-amsterdam">RustNL</a><ul>
<li><a href="https://www.meetup.com/rust-nederland/events/312861992/"><strong>RustWeek 2026 announcement</strong></a></li>
</ul>
</li>
<li>2026-05-19 | Leipzig, DE | <a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig">Rust - Modern Systems Programming in Leipzig</a><ul>
<li><a href="https://www.meetup.com/rust-modern-systems-programming-in-leipzig/events/313813902/"><strong>Cross-Building &amp; Cross-Testing</strong></a></li>
</ul>
</li>
<li>2026-05-19 | London, UK | <a href="https://www.meetup.com/women-in-rust">Women in Rust</a><ul>
<li><a href="https://www.meetup.com/women-in-rust/events/314313054/"><strong>RustWeek lunch meetup</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Amsterdam, NL | <a href="https://www.meetup.com/rust-amsterdam">RustNL</a><ul>
<li><a href="https://www.meetup.com/rust-nederland/events/314301699/"><strong>RustWeek Hackathon</strong></a></li>
</ul>
</li>
<li>2026-05-22 | Amsterdam, NL | <a href="https://www.meetup.com/rust-amsterdam">RustNL</a><ul>
<li><a href="https://www.meetup.com/rust-nederland/events/314523659/"><strong>Bike tour around Utrecht</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Dortmund, DE | <a href="https://www.meetup.com/rust-dortmund">Rust Dortmund</a><ul>
<li><a href="https://www.meetup.com/rust-dortmund/events/314522781/"><strong>Rust Dortmund Meetup - Agentic Programming - May</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Manchester, UK | <a href="https://www.meetup.com/rust-manchester">Rust Manchester</a><ul>
<li><a href="https://www.meetup.com/rust-manchester/events/314452972/"><strong>Rust Manchester May Code Night</strong></a></li>
</ul>
</li>
<li>2026-05-29 | Berlin, DE | <a href="https://www.meetup.com/rust-berlin">Rust Berlin</a><ul>
<li><a href="https://www.meetup.com/rust-berlin/events/314396588/"><strong>Rust Berlin Talks: The next generation</strong></a></li>
</ul>
</li>
<li>2026-06-03 | Dublin, IE | <a href="https://www.meetup.com/rust-dublin/events/">Rust Dublin</a><ul>
<li><a href="https://www.meetup.com/rust-dublin/events/314689875/"><strong>Join us live and INPERSON for Rust 261</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#north-america">North America</a></h5>
<ul>
<li>2026-05-14 | Lehi, UT, US | <a href="https://www.meetup.com/utah-rust/events/">Utah Rust</a><ul>
<li><a href="https://www.meetup.com/utah-rust/events/314696639/"><strong>Utah Rust May Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-14 | Mountain View, CA, US | <a href="https://www.meetup.com/hackerdojo/events/">Hacker Dojo</a><ul>
<li><a href="https://www.meetup.com/hackerdojo/events/314469265/"><strong>RUST MEETUP at HACKER DOJO</strong></a></li>
</ul>
</li>
<li>2026-05-14 | Portland, OR, US | <a href="https://www.meetup.com/pdxrust">PDXRust</a><ul>
<li><a href="https://www.meetup.com/pdxrust/events/314256732/"><strong>From Radio Waves to Pixels - Real-Time Visualizations with Rust and WebAssembly</strong></a></li>
</ul>
</li>
<li>2026-05-14 | San Diego, CA, US | <a href="https://www.meetup.com/san-diego-rust">San Diego Rust</a><ul>
<li><a href="https://www.meetup.com/san-diego-rust/events/313721886/"><strong>San Diego Rust May Meetup - Back in person!</strong></a></li>
</ul>
</li>
<li>2026-05-16 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480531/"><strong>Lechmere Rust Lunch, May 16</strong></a></li>
</ul>
</li>
<li>2026-05-19 | San Francisco, CA, US | <a href="https://www.meetup.com/san-francisco-rust-study-group">San Francisco Rust Study Group</a><ul>
<li><a href="https://www.meetup.com/san-francisco-rust-study-group/events/314154841/"><strong>Rust Hacking in Person</strong></a></li>
</ul>
</li>
<li>2026-05-20 | Hybrid (Vancouver, BC, CA) | <a href="https://www.meetup.com/vancouver-rust">Vancouver Rust</a><ul>
<li><a href="https://www.meetup.com/vancouver-rust/events/313572925/"><strong>Mouse Control with Rust</strong></a></li>
</ul>
</li>
<li>2026-05-20 | San Francisco, CA, US | <a href="https://luma.com/bayarearust">Bay Area Rust Meetup</a><ul>
<li><a href="https://luma.com/9j3q5ejl"><strong>Bay Area Rust Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Hybrid (Seattle, WA, US) | <a href="https://www.meetup.com/join-srug">Seattle Rust User Group</a><ul>
<li><a href="https://www.meetup.com/seattle-rust-user-group/events/313873203/"><strong>May, 2026 SRUG (Seattle Rust User Group) Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-21 | Nashville, TN, US | <a href="https://www.meetup.com/music-city-rust-developers">Music City Rust Developers</a><ul>
<li><a href="https://www.meetup.com/music-city-rust-developers/events/314359076/"><strong>Community Meetup</strong></a></li>
</ul>
</li>
<li>2026-05-23 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480534/"><strong>Allston Rust Lunch, May 23</strong></a></li>
</ul>
</li>
<li>2026-05-27 | Austin, TX, US | <a href="https://www.meetup.com/rust-atx">Rust ATX</a><ul>
<li><a href="https://www.meetup.com/rust-atx/events/314209662/"><strong>Rust Lunch - Fareground</strong></a></li>
</ul>
</li>
<li>2026-05-28 | Atlanta, GA, US | <a href="https://www.meetup.com/rust-atl">Rust Atlanta</a><ul>
<li><a href="https://www.meetup.com/rust-atl/events/313539319/"><strong>Rust-Atl</strong></a></li>
</ul>
</li>
<li>2026-05-28 | Los Angeles, CA, US | <a href="https://www.meetup.com/rust-los-angeles">Rust Los Angeles</a><ul>
<li><a href="https://www.meetup.com/rust-los-angeles/events/314218564/"><strong>Rust LA: Rust in Embedded &amp; Autonomous Systems at Parallel Systems in DTLA</strong></a></li>
</ul>
</li>
<li>2026-05-30 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480537/"><strong>Central Cambridge Rust Lunch, May 30</strong></a></li>
</ul>
</li>
<li>2026-06-04 | Saint Louis, MO, US | <a href="https://www.meetup.com/stl-rust/events/">STL Rust</a><ul>
<li><a href="https://www.meetup.com/stl-rust/events/314106244/"><strong>Testing, Coverage, Tracey &amp; Mutations</strong></a></li>
</ul>
</li>
<li>2026-06-06 | Boston, MA, US | <a href="https://www.meetup.com/bostonrust/events/">Boston Rust Meetup</a><ul>
<li><a href="https://www.meetup.com/bostonrust/events/314480539/"><strong>Boston Common Rust Lunch, June 6</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#oceania">Oceania</a></h5>
<ul>
<li>2026-05-14 | Melbourne, AU | <a href="https://www.meetup.com/rust-melbourne">Rust Melbourne</a><ul>
<li><a href="https://www.meetup.com/rust-melbourne/events/314260890/"><strong>Rust Melbourne - May 2026</strong></a></li>
</ul>
</li>
<li>2026-05-26 | Barton, ACT, AU | <a href="https://www.meetup.com/rust-canberra">Canberra Rust User Group</a><ul>
<li><a href="https://www.meetup.com/rust-canberra/events/314050576/"><strong>May Meetup</strong></a></li>
</ul>
</li>
</ul>
<h5><a class="toclink" href="https://this-week-in-rust.org/atom.xml#south-america">South America</a></h5>
<ul>
<li>2026-05-13 | Montevideo, UY | <a href="https://www.meetup.com/rust-uruguay">Rust Meetup Uruguay</a><ul>
<li><a href="https://www.meetup.com/rust-uruguay/events/314532884/"><strong>Rust Uruguay meetup de Mayo</strong></a></li>
</ul>
</li>
</ul>
<p>If you are running a Rust event please add it to the <a href="https://www.google.com/calendar/embed?src=apd9vmbc22egenmtu5l6c5jbfc%40group.calendar.google.com">calendar</a> to get
it mentioned here. Please remember to add a link to the event too.
Email the <a href="mailto:community-team@rust-lang.org">Rust Community Team</a> for access.</p>
<h4><a class="toclink" href="https://this-week-in-rust.org/atom.xml#jobs">Jobs</a></h4>
<p>Please see the latest <a href="https://www.reddit.com/r/rust/comments/1sobu1s/official_rrust_whos_hiring_thread_for_jobseekers/">Who's Hiring thread on r/rust</a></p>
<h3><a class="toclink" href="https://this-week-in-rust.org/atom.xml#quote-of-the-week">Quote of the Week</a></h3>
<blockquote>
<p>Of the last 150 merged PRs to Bun, <strong>108 are memory-safety-adjacent</strong> — missed cleanup on an error path, use-after-free, uninitialized reads, out-of-bounds access, reentrancy. <strong>75 of those would not compile</strong> in a language with destructors, move semantics, and a borrow checker. One in three PRs we ship is "forgot to free something on an error path."</p>
<p>Of the 108, ~88 are in Zig. The ~14 in C++ are mostly ref-cycles and GC-concurrency races — the residual class that survives any language. So the Zig→Rust delta is real: the Zig bugs are exactly the destructor/ownership-fixable kind, and the C++ side is already near the floor.</p>
<p>Without stronger compile-time guarantees, this stays a cat-and-mouse game. The proposal is to remove the largest bug class structurally rather than fix instances of it indefinitely.</p>
</blockquote>
<p>– <a href="https://github.com/oven-sh/bun/blob/claude/phase-a-port/docs/rust-rewrite-plan.md#why">Jarred Sumner on the bun github</a></p>
<p>Thanks to <a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328/1765">Brian Kung</a> for the suggestion!</p>
<p><a href="https://users.rust-lang.org/t/twir-quote-of-the-week/328">Please submit quotes and vote for next week!</a></p>
<p>This Week in Rust is edited by:</p>
<ul>
<li><a href="https://github.com/nellshamrell">nellshamrell</a></li>
<li><a href="https://github.com/llogiq">llogiq</a></li>
<li><a href="https://github.com/ericseppanen">ericseppanen</a></li>
<li><a href="https://github.com/extrawurst">extrawurst</a></li>
<li><a href="https://github.com/U007D">U007D</a></li>
<li><a href="https://github.com/mariannegoldin">mariannegoldin</a></li>
<li><a href="https://github.com/bdillo">bdillo</a></li>
<li><a href="https://github.com/opeolluwa">opeolluwa</a></li>
<li><a href="https://github.com/bnchi">bnchi</a></li>
<li><a href="https://github.com/KannanPalani57">KannanPalani57</a></li>
<li><a href="https://github.com/tzilist">tzilist</a></li>
</ul>
<p><em>Email list hosting is sponsored by <a href="https://foundation.rust-lang.org/">The Rust Foundation</a></em></p>
<p><small><a href="https://www.reddit.com/r/rust/comments/1tcjse1/this_week_in_rust_651/">Discuss on r/rust</a></small></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-8257 | WebAssembly Binaryen up to 117 BrOn Parser wasm-ir-builder.cpp IRBuilder::makeBrOn assertion (Issue 8633 / CNNVD-202605-2396)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable assertion.

This vulnerability w...]]></description>
<link>https://tsecurity.de/de/3512622/sicherheitsluecken/cve-2026-8257-webassembly-binaryen-up-to-117-bron-parser-wasm-ir-buildercpp-irbuildermakebron-assertion-issue-8633-cnnvd-202605-2396/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3512622/sicherheitsluecken/cve-2026-8257-webassembly-binaryen-up-to-117-bron-parser-wasm-ir-buildercpp-irbuildermakebron-assertion-issue-8633-cnnvd-202605-2396/</guid>
<pubDate>Wed, 13 May 2026 08:22:44 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/webassembly:binaryen">WebAssembly Binaryen up to 117</a>. This issue affects the function <code>IRBuilder::makeBrOn</code> of the file <em>src/wasm/wasm-ir-builder.cpp</em> of the component <em>BrOn Parser</em>. Performing a manipulation results in reachable assertion.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-8257">CVE-2026-8257</a>. The attack needs to be approached locally. In addition, an exploit is available.

It is suggested to install a patch to address this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kill the loading spinner with local-first data and reactive SQL]]></title>
<description><![CDATA[It’s not every day that a radically new architecture comes along, but here we are: in-browser SQLite, combined with reactive SQL and auto-syncing. The promise is instant interactivity on the front end, while maintaining data symmetry with the back end. As a direct challenger to the RESTful group-...]]></description>
<link>https://tsecurity.de/de/3509683/ai-nachrichten/kill-the-loading-spinner-with-local-first-data-and-reactive-sql/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3509683/ai-nachrichten/kill-the-loading-spinner-with-local-first-data-and-reactive-sql/</guid>
<pubDate>Tue, 12 May 2026 11:33:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>It’s not every day that a radically new architecture comes along, but here we are: <a href="https://sqlite.org/wasm/doc/trunk/index.md" data-type="link" data-id="https://sqlite.org/wasm/doc/trunk/index.md">in-browser SQLite</a>, combined with <a href="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html" data-type="link" data-id="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html">reactive SQL</a> and auto-syncing. The promise is instant interactivity on the front end, while maintaining data symmetry with the back end. As a direct challenger to the <a href="https://www.infoworld.com/article/2334742/what-is-rest-the-de-facto-web-architecture-standard.html" data-type="link" data-id="https://www.infoworld.com/article/2334742/what-is-rest-the-de-facto-web-architecture-standard.html">RESTful group-think</a> that has dominated web development for a decade, it is well worth a look. </p>



<h2 class="wp-block-heading">Not really new, but improved</h2>



<p>This idea isn’t brand new. Developers have been doing this kind of thing in one fashion or another for years (think of how some apps work offline). But this new-generation stack feels different, and it’s starting to see broader appeal. </p>



<p>It’s called local-first data. I recently <a href="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html" data-type="link" data-id="https://www.infoworld.com/article/4133648/the-browser-is-your-database-local-first-comes-of-age.html">covered the idea at a high level</a>. Now it’s time for a look at the nitty gritty.</p>



<p>The concept is simple. Instead of asking a remote server for permission to change a number, your app writes state directly to a local SQLite database running in the browser (via <a href="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html">WebAssembly</a>). A sophisticated background engine then handles the hard work of syncing those changes to the cloud and other devices.</p>



<p>For React developers, the best part is that we remain in the reactive paradigm. Even though we are writing raw <a href="https://www.infoworld.com/article/2255395/what-is-sql-the-lingua-franca-of-data-analysis.html" data-type="link" data-id="https://www.infoworld.com/article/2255395/what-is-sql-the-lingua-franca-of-data-analysis.html">SQL</a> queries, the shuffling of the data is handled for us. Our UI components subscribe to the database, and when the data changes (whether locally from a user click or an inbound sync update from the cloud), the UI updates instantly.</p>



<p>When you use Spotify, you don’t download their entire multi-million song catalog. You just download your list and, even if you are offline, you listen to your music lag-free. This is the same kind of model we are building with local-first data, but with a lot of extra power. We can make changes to our local state, and those changes will be synced with the back end when a connection is available. And correspondingly, we will automatically receive important updates from the world.</p>



<h2 class="wp-block-heading">Three architectural components</h2>



<p>To pull this off we need three major architectural components:</p>



<ul class="wp-block-list">
<li>The client-side UI and database (React and SQLite Wasm )</li>



<li>A syncing engine (PowerSync)</li>



<li>A database of record (Supabase)</li>
</ul>



<p>Let’s start by setting up the cloud services we need: Supabase and PowerSync, both of which will be free-tier. For our client-side UI and database, we’ll make use of a React+SQLite demo app provided by Supabase. </p>



<h3 class="wp-block-heading">Supabase – the database of record</h3>



<p>Supabase is a managed Postgres service with a lot of niceties. Our example is going to be very simple, with only one row required. Go to <a href="http://supabase.com/">Supabase.com</a>, create a free account, and start a new project. Clicking on the project will bring you to its details:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/React-Supabase-PowerSync-01.png?w=1024" alt="React-Supabase-PowerSync 01" class="wp-image-4168592" width="1024" height="406" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Foundry</p></div>



<p>Next we create a database schema to hold our data, which will be a simple one. On the left side menu, open the SQL Editor and run the following code.</p>



<pre class="wp-block-code"><code>-- 1. Create the table to store our counters
CREATE TABLE counters (
  id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
  created_at TIMESTAMPTZ DEFAULT NOW(),
  count INTEGER DEFAULT 0,
  owner_id UUID DEFAULT auth.uid()
);

-- 2. Turn on Row Level Security (RLS) 
ALTER TABLE counters ENABLE ROW LEVEL SECURITY;

-- 3. Access Policies 
CREATE POLICY "Users can all on own counters" 
ON counters FOR ALL 
USING (auth.uid() = owner_id);

-- 4. Publish the table
DROP PUBLICATION IF EXISTS powersync;
CREATE PUBLICATION powersync FOR TABLE counters;
</code></pre>



<p>Each step is annotated within the code above. The first step is standard SQL, creating a table with a few columns including a random UUID primary key. The second step turns on <a href="https://supabase.com/docs/guides/database/postgres/row-level-security">row level security</a>. The third step creates an access policy allowing users access to their own counter row (as determined by their logged in id: <code>auth.uid() = owner_id</code>). The fourth step creates a link between the Supabase instance and PowerSync.</p>



<p>Before we leave Supabase, click the “+ Connect” button at the top and grab the connection string, which looks something like this:</p>



<pre class="wp-block-code"><code>postgresql://postgres:[YOUR-PASSWORD]@db.fooizpddffaabqcydusj.supabase.co:5432/postgres</code></pre>



<h3 class="wp-block-heading">PowerSync – the syncing engine</h3>



<p>Now let’s jump into PowerSync. Go to <a href="https://powersync.com/" data-type="link" data-id="https://powersync.com/">PowerSync.com</a>, create a free account, and start a new project. Open the project details:</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/React-Supabase-PowerSync-02.png?w=1024" alt="React-Supabase-PowerSync 02" class="wp-image-4168596" width="1024" height="454" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Foundry</p></div>



<p>In the PowerSync dashboard, we need to create a bridge to Supabase. Follow these steps: </p>



<ol class="wp-block-list">
<li>Click “Create New Instance”.</li>



<li>Click the “Database Connections” item on the left, then click the + button.</li>



<li>Paste the connection string you copied from Supabase. Note: If your string has a <code>[YOUR-PASSWORD]</code> placeholder, replace it with the actual password you created for the instance.</li>



<li>Click “Test Connection”.</li>
</ol>



<p>PowerSync will now reach out to the Postgres instance we created before. If you ran the <code>CREATE PUBLICATION SQL</code> command correctly in the Supabase setup, this will succeed, and you’ll see a green “Connection Successful!” status message.</p>



<h4 class="wp-block-heading">Configure authentication</h4>



<p>We told PowerSync how to <em>read</em> our Supabase data (Postgres). Now we need tell it how to <em>trust</em> our users. Here are the steps: </p>



<ol class="wp-block-list">
<li>In the PowerSync dashboard, click the “Client Auth” tab</li>



<li>Look for the “JWKS URI” field.</li>



<li>Construct your JWKS URL. It is your Supabase Project URL + a specific suffix. 
<ul class="wp-block-list">
<li>Format: <code>https://[YOUR-PROJECT-ID].supabase.co/auth/v1/.well-known/jwks.json</code></li>



<li>Note: You can get your Project URL from Supabase &gt; Settings &gt; API.</li>
</ul>
</li>



<li>Paste your JWKS URL into the JWKS URI field and click “Save”.</li>



<li>Set the Audience to “authenticated”:
<ul class="wp-block-list">
<li>Click the (+) Add button under “Token Claims”.</li>



<li>Claim: Type <code>aud</code></li>



<li>Value: Type <code>authenticated</code></li>
</ul>
</li>
</ol>



<p>This configuration tells PowerSync, “Only trust tokens that are signed by Supabase AND are meant for the ‘authenticated’ user group.”</p>



<h4 class="wp-block-heading">Define the sync rules</h4>



<p>The sync rules are the essential architectural element to understand. This is where we tell Powersync what <em>part </em>of the data the user is privy to. This is sometimes called the “data shape” for the user. Each user has their own shape of the overall data, based on their unique profile.</p>



<p>We do not want to sync the <em>entire</em> database to the user’s laptop. That would be bad on many levels. Instead, we define a sync rule (or “bucket” in PowerSync), which is a filter that determines what data belongs to which user.</p>



<p>Navigate to “Sync Rules” on the left. You’ll get a YAML editor. Replace the default code with the following code.</p>



<pre class="wp-block-code"><code>YAML
config:
  edition: 2

bucket_definitions:
  user_counters:
    # 1. Identify the user from their Auth Token
    parameters: SELECT request.user_id() as user_id

    # 2. Only sync rows that belong to them
    data:
      - SELECT * FROM counters WHERE owner_id = bucket.user_id
</code></pre>



<p>This code defines the special view of the data for users:</p>



<ul class="wp-block-list">
<li><code>user_counters</code>: This is a “bucket”, a collection of data</li>



<li><code>request.user_id()</code>: PowerSync automatically extracts the user id from the Supabase auth token.</li>



<li>The data query: This SQL runs in the cloud, grabbing only the rows where the <code>owner_id</code> column matches the logged-in user and streams them down to the device.</li>
</ul>



<p>You can click “Validate” to check that this is working. Click “Deploy” to make it live.</p>



<h2 class="wp-block-heading">React and SQLite – the client-side UI and database</h2>



<p>We have done a lot of administrative work here, but it is giving us an entire reactive architecture based on SQL. Let’s push ahead with a client that can use it.</p>



<p>To get a quick look, let’s clone a demo app from Supabase. At the command line, run: </p>



<pre class="wp-block-code"><code>$ git clone https://github.com/powersync-community/vite-react-ts-powersync-supabase.git
$ cd vite-react-ts-powersync-supabase
$ npm install
</code></pre>



<p>Once the npm command finishes, we want to point the app at the infrastructure we just created. We can do that using the <code>.env.local</code> environmental variable file. Open <code>.env.local</code> and change the vars to point to your services. Here is the code:</p>



<pre class="wp-block-code"><code>VITE_SUPABASE_URL=https://fooizpddffaabqcydusj.supabase.co
VITE_SUPABASE_ANON_KEY=sb_publishable_gqUrYxDt04rg74fopz5rUg_ayDxpmgE
VITE_POWERSYNC_URL=https://foofcf18cc2560584a018a12.powersync.journeyapps.com
</code></pre>



<p>We are ready to test our React app:</p>



<pre class="wp-block-code"><code>$ npm run dev:ui
</code></pre>



<p>The demo app is a simple counter—a web page that presents an “Increment” button and shows the count. None too exciting, except for the data syncing magic behind the scenes. </p>



<p>Run the above command, and a browser window will open showing a “Create Counter” button. When you click it, the demo will give you a counter in a new window, along with a user ID and a panel that shows connection and sync status. You can create as many counters as you like, each in a separate browser window. </p>



<p>You can verify your counter is working by going to the Supabase dashboard, looking at the “Table” pane and seeing that a row has indeed been inserted for your user in the counter table. Another good check is to log in using another browser/device (or incognito tab). </p>



<p>Log in and create another counter in the second browser window, so that you have two different Supabase-synced session counters side by side: </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/React-Supabase-PowerSync-03-1.png" alt="React-Supabase-PowerSync 03" class="wp-image-4169002" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Foundry</p></div>



<p>Whenever you create a new counter, a new row will be inserted into Supabase. The screenshot below shows a Supabase table with two rows, each with its own user ID and counter value. </p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-full"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2026/05/React-Supabase-PowerSync-04.png" alt="React-Supabase-PowerSync 04" class="wp-image-4169007" width="1024" height="487" sizes="auto, (max-width: 1024px) 100vw, 1024px"></figure><p class="imageCredit">Foundry</p></div>



<h3 class="wp-block-heading">The React code (App.tsx)</h3>



<p>We are moving quickly, but there are some interesting things to make note of in the src/App.tsx file. This code is the main React code for the app, and demonstrates the shift from “asking the server” to “interacting with local database state.” </p>



<p>There are two landmarks here that every React developer needs to see: the reactive read and the instant write. </p>



<h4 class="wp-block-heading">The reactive read (useQuery)</h4>



<p>In a standard React app, we would retrieve the data by using a <code>useEffect</code> to call <code>fetch('/api/counters')</code>. In our local-first React app, we use raw SQL:</p>



<pre class="wp-block-code"><code>const { data: counters, isLoading } = useQuery<counterrecord>(
  `SELECT * FROM ${COUNTER_TABLE} ORDER BY created_at ASC`,
  [],
  {
    rowComparator: {
      keyBy: (item) =&gt; item.id,
      compareBy: (item) =&gt; JSON.stringify(item)
    }
  }
);
</counterrecord></code></pre>



<p>This is the “reactive SQL” part of the architecture.</p>



<p>This <code>useQuery</code> hook subscribes to the local SQLite database. When the background worker receives an update from the cloud—or when you update a row locally—this hook fires instantly and re-renders the component. No manual state management or re-fetching logic is required, and there is no intermediate object of state. The back-end state and the front-end state are the same.</p>



<h4 class="wp-block-heading">The instant write (powerSync.execute)</h4>



<p>Notice what happens when we increment the counter. There is no <code>await api.post(...)</code> and no loading spinner state.</p>



<pre class="wp-block-code"><code>const updateCounter = async (counter: CounterRecord, newCount: number) =&gt; {
  // Writes to Local SQLite immediately
  await powerSync.execute(
    `UPDATE ${COUNTER_TABLE} SET count = ? WHERE owner_id = ?`,
    [newCount, counter.owner_id]
  );
};
</code></pre>



<p>This code is interesting on its own, because it’s like a reactive SQL statement. We write to the local file (Wasm). The write completes in milliseconds, and the UI updates immediately via the <code>useQuery</code> hook. The PowerSync syncing engine picks up the change asynchronously and pushes it to Supabase.</p>



<h2 class="wp-block-heading">The local-first vs. RESTful calculation</h2>



<p>So, is all of this configuration and newfangled code worth it?</p>



<p>If you are building a simple dashboard or a form-based application, the traditional JSON API (REST or GraphQL) approach is still king. In those models, the server is the single source of truth, and the client is just a dumb terminal. It is simple, stateless, and easy to debug. It’s also familiar.</p>



<p>But that simplicity comes with an unavoidable latency cost. Every interaction requires a round-trip ticket to the server. If the network hiccups, your app freezes. JSON APIs force you to manage loading states, error boundaries, and optimistic UI rollbacks manually.</p>



<p>Local-first flips the calculation. You pay a higher cost up front: you have to define a schema, manage a local database, and think about syncing rules. But in exchange, you get an application that feels like a native piece of software. Local-first creates data continuity, the ability to walk out of Wi-Fi range, keep working, and have your data follow you across devices when you reconnect.</p>



<p>Architecturally, we used three major components: the database, the syncing engine, and the client. This is actually similar to your conventional RESTful stack. In the local-first structure, the syncing engine takes the place of the JSON API server. In short, you have a similar amount of high-level complexity, but with different actors on the ground.</p>



<p>Local-first architecture is a fascinating development for JavaScript and the web in general. There is a huge inertial mass of JSON APIs to overcome, but here is a real countercurrent. Local-first may never rise to the level of adoption of RESTful architecture, but local-first data and reactive SQL constitute one of the most important trends to be watching closely right now.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Building a Wasm-in-Wasm Virtualizer (with JIT decrypted paged memory)]]></title>
<description><![CDATA[submitted by    /u/TrustSig   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3505571/reverse-engineering/building-a-wasm-in-wasm-virtualizer-with-jit-decrypted-paged-memory/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3505571/reverse-engineering/building-a-wasm-in-wasm-virtualizer-with-jit-decrypted-paged-memory/</guid>
<pubDate>Mon, 11 May 2026 03:37:54 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/TrustSig"> /u/TrustSig </a> <br> <span><a href="https://trustsig.eu/blog/wasm-vm">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1t9kx4e/building_a_wasminwasm_virtualizer_with_jit/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Rust Programming Language Blog: Changes to WebAssembly targets and handling undefined symbols]]></title>
<description><![CDATA[Rust's WebAssembly targets are soon going to experience a change which has a
risk of breaking existing projects, and this post is intended to notify users of
this upcoming change, explain what it is, and how to handle it. Specifically, all
WebAssembly targets in Rust have been linked using the --...]]></description>
<link>https://tsecurity.de/de/3501669/tools/the-rust-programming-language-blog-changes-to-webassembly-targets-and-handling-undefined-symbols/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501669/tools/the-rust-programming-language-blog-changes-to-webassembly-targets-and-handling-undefined-symbols/</guid>
<pubDate>Fri, 08 May 2026 23:25:02 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Rust's WebAssembly targets are soon going to experience a change which has a
risk of breaking existing projects, and this post is intended to notify users of
this upcoming change, explain what it is, and how to handle it. Specifically, all
WebAssembly targets in Rust have been linked using the <code>--allow-undefined</code> flag
to <code>wasm-ld</code>, and this flag is being removed.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/04/04/changes-to-webassembly-targets-and-handling-undefined-symbols/#what-is-allow-undefined"></a>
What is <code>--allow-undefined</code>?</h3>
<p>WebAssembly binaries in Rust today are all created by linking with <code>wasm-ld</code>.
This serves a similar purpose to <code>ld</code>, <code>lld</code>, and <code>mold</code>, for example; it
takes separately compiled crates/object files and creates one final binary.
Since the first introduction of WebAssembly targets in Rust, the
<code>--allow-undefined</code> flag has been passed to <code>wasm-ld</code>. This flag is documented
as:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span>  --allow-undefined       Allow undefined symbols in linked binary. This options</span></span>
<span class="giallo-l"><span>                          is equivalent to --import-undefined and</span></span>
<span class="giallo-l"><span>                          --unresolved-symbols=ignore-all</span></span></code></pre>
<p>The term "undefined" here specifically means with respect to symbol resolution in <code>wasm-ld</code> itself. Symbols used by <code>wasm-ld</code> correspond relatively closely to what native platforms use, for example all Rust functions have a symbol associated with them. Symbols can be referred to in Rust through <code>extern "C"</code> blocks, for example:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span class="z-keyword">unsafe</span><span class="z-storage z-type"> extern</span><span class="z-punctuation z-definition z-string z-string"> "</span><span class="z-string z-quoted z-string">C</span><span class="z-punctuation z-definition z-string z-string">"</span><span> {</span></span>
<span class="giallo-l"><span class="z-keyword">    fn</span><span class="z-entity z-name z-function"> mylibrary_init</span><span>(</span><span>)</span><span>;</span></span>
<span class="giallo-l"><span>}</span></span>
<span class="giallo-l"></span>
<span class="giallo-l"><span class="z-keyword">fn</span><span class="z-entity z-name z-function"> init</span><span>(</span><span>)</span><span> {</span></span>
<span class="giallo-l"><span class="z-keyword">    unsafe</span><span> {</span></span>
<span class="giallo-l"><span class="z-entity z-name z-function">        mylibrary_init</span><span>(</span><span>)</span><span>;</span></span>
<span class="giallo-l"><span>    }</span></span>
<span class="giallo-l"><span>}</span></span></code></pre>
<p>The symbol <code>mylibrary_init</code> is an undefined symbol. This is typically defined by
a separate component of a program, such as an externally compiled C library,
which will provide a definition for this symbol. By passing <code>--allow-undefined</code>
to <code>wasm-ld</code>, however, it means that the above would generate a WebAssembly
module like so:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span>(</span><span class="z-storage z-type">module</span></span>
<span class="giallo-l"><span>    (</span><span class="z-storage z-type">import</span><span class="z-punctuation z-definition z-string z-string"> "</span><span class="z-string z-quoted z-string">env</span><span class="z-punctuation z-definition z-string z-string">"</span><span class="z-punctuation z-definition z-string z-string"> "</span><span class="z-string z-quoted z-string">mylibrary_init</span><span class="z-punctuation z-definition z-string z-string">"</span><span> (</span><span class="z-entity z-name z-type">func</span><span class="z-entity z-name z-function"> $mylibrary_init</span><span>))</span></span>
<span class="giallo-l"></span>
<span class="giallo-l"><span class="z-punctuation z-definition z-comment z-comment">    ;;</span><span class="z-comment"> ...</span></span>
<span class="giallo-l"><span>)</span></span></code></pre>
<p>This means that the undefined symbol was ignored and ended up as an imported
symbol in the final WebAssembly module that is produced.</p>
<p>The precise history here is somewhat lost to time, but the current understanding
is that <code>--allow-undefined</code> was effectively required in the very early days of
introducing <code>wasm-ld</code> to the Rust toolchain. This historical workaround stuck
around till today and hasn't changed.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/04/04/changes-to-webassembly-targets-and-handling-undefined-symbols/#what-s-wrong-with-allow-undefined"></a>
What's wrong with <code>--allow-undefined</code>?</h3>
<p>By passing <code>--allow-undefined</code> on all WebAssembly targets, rustc is introducing
diverging behavior between other platforms and WebAssembly. The main risk of
<code>--allow-undefined</code> is that misconfiguration or mistakes in building can
result in broken WebAssembly modules being produced, as opposed to compilation
errors. This means that the proverbial can is kicked down the road and lengthens
the distance from where the problem is discovered to where it was introduced.
Some example problematic situations are:</p>
<ul>
<li>
<p>If <code>mylibrary_init</code> was typo'd as <code>mylibraryinit</code> then the final binary would
import the <code>mylibraryinit</code> symbol instead of calling the linked
<code>mylibrary_init</code> C symbol.</p>
</li>
<li>
<p>If <code>mylibrary</code> was mistakenly not compiled and linked into a final
application then the <code>mylibrary_init</code> symbol would end up imported rather than
producing a linker error saying it's undefined.</p>
</li>
<li>
<p>If external tooling is used to process a WebAssembly module, such as <code>wasm-bindgen</code> or <code>wasm-tools component new</code>, these tools don't know what to do with <code>"env"</code> imports by default and they are likely to provide an error message of some form that isn't clearly connected back to the original source code and where the symbols was imported from.</p>
</li>
<li>
<p>For web users if you've ever seen an error along the lines of <code>Uncaught TypeError: Failed to resolve module specifier "env". Relative references must start with either "/", "./", or "../".</code> this can mean that <code>"env"</code> leaked into the final module unexpectedly and the true error is the undefined symbol error, not the lack of <code>"env"</code> items provided.</p>
</li>
</ul>
<p>All native platforms consider undefined symbols to be an error by default, and
thus by passing <code>--allow-undefined</code> rustc is introducing surprising behavior on
WebAssembly targets. The goal of the change is to remove this surprise and
behave more like native platforms.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/04/04/changes-to-webassembly-targets-and-handling-undefined-symbols/#what-is-going-to-break-and-how-to-fix"></a>
What is going to break, and how to fix?</h3>
<p>In theory, not a whole lot is expected to break from this change. If the final
WebAssembly binary imports unexpected symbols, then it's likely that the binary
won't be runnable in the desired embedding, as the desired embedding probably
doesn't provide the symbol as a definition. For example, if you compile an
application for <code>wasm32-wasip1</code> if the final binary imports <code>mylibrary_init</code>
then it'll fail to run in most runtimes because it's considered an unresolved
import. This means that most of the time this change won't break users, but
it'll instead provide better diagnostics.</p>
<p>The reason for this post, however, is that it's possible users could be
intentionally relying on this behavior. For example your application might have:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span class="z-keyword">unsafe</span><span class="z-storage z-type"> extern</span><span class="z-punctuation z-definition z-string z-string"> "</span><span class="z-string z-quoted z-string">C</span><span class="z-punctuation z-definition z-string z-string">"</span><span> {</span></span>
<span class="giallo-l"><span class="z-keyword">    fn</span><span class="z-entity z-name z-function"> js_log</span><span>(</span><span class="z-variable">n</span><span class="z-keyword z-operator">:</span><span class="z-entity z-name z-type"> u32</span><span>)</span><span>;</span></span>
<span class="giallo-l"><span>}</span></span>
<span class="giallo-l"></span>
<span class="giallo-l"><span class="z-punctuation z-definition z-comment z-comment">//</span><span class="z-comment z-line z-double-slash z-comment"> ...</span></span></code></pre>
<p>And then perhaps some JS code that looks like:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span class="z-storage z-type">let</span><span class="z-variable z-other z-readwrite z-js z-variable"> instance</span><span class="z-keyword z-operator z-assignment z-keyword z-operator"> =</span><span class="z-keyword z-control z-flow z-js z-keyword z-control"> await</span><span class="z-variable z-other z-object z-js z-variable"> WebAssembly</span><span class="z-punctuation z-accessor">.</span><span class="z-entity z-name z-function">instantiate</span><span class="z-meta z-brace">(</span><span class="z-support z-type">module</span><span class="z-meta z-var z-expr">,</span><span class="z-meta z-var z-expr"> {</span></span>
<span class="giallo-l"><span class="z-meta z-var z-expr z-meta z-object-literal z-key">    env</span><span class="z-meta z-var z-expr z-meta z-object-literal z-key">:</span><span class="z-meta z-var z-expr"> {</span></span>
<span class="giallo-l"><span class="z-entity z-name z-function">        js_log</span><span class="z-meta z-var z-expr z-meta z-object-literal z-key">:</span><span class="z-variable z-parameter z-variable"> n</span><span class="z-storage z-type"> =&gt;</span><span class="z-variable z-other z-object z-js z-variable"> console</span><span class="z-punctuation z-accessor">.</span><span class="z-entity z-name z-function">log</span><span class="z-meta z-brace">(</span><span class="z-variable z-other z-readwrite z-js z-variable">n</span><span class="z-meta z-brace">)</span><span class="z-meta z-var z-expr">,</span></span>
<span class="giallo-l"><span class="z-meta z-var z-expr">    }</span></span>
<span class="giallo-l"><span class="z-meta z-var z-expr">}</span><span class="z-meta z-brace">)</span><span>;</span></span></code></pre>
<p>Effectively it's possible for users to explicitly rely on the behavior of
<code>--allow-undefined</code> generating an import in the final WebAssembly binary.</p>
<p>If users encounter this then the code can be fixed through a <code>#[link]</code> attribute
which explicitly specifies the <code>wasm_import_module</code> name:</p>
<pre class="giallo z-code"><code><span class="giallo-l"><span>#</span><span>[</span><span>link</span><span>(</span><span>wasm_import_module </span><span class="z-keyword z-operator z-assignment z-keyword z-operator">=</span><span class="z-punctuation z-definition z-string z-string"> "</span><span class="z-string z-quoted z-string">env</span><span class="z-punctuation z-definition z-string z-string">"</span><span>)</span><span>]</span></span>
<span class="giallo-l"><span class="z-keyword">unsafe</span><span class="z-storage z-type"> extern</span><span class="z-punctuation z-definition z-string z-string"> "</span><span class="z-string z-quoted z-string">C</span><span class="z-punctuation z-definition z-string z-string">"</span><span> {</span></span>
<span class="giallo-l"><span class="z-keyword">    fn</span><span class="z-entity z-name z-function"> js_log</span><span>(</span><span class="z-variable">n</span><span class="z-keyword z-operator">:</span><span class="z-entity z-name z-type"> u32</span><span>)</span><span>;</span></span>
<span class="giallo-l"><span>}</span></span>
<span class="giallo-l"></span>
<span class="giallo-l"><span class="z-punctuation z-definition z-comment z-comment">//</span><span class="z-comment z-line z-double-slash z-comment"> ...</span></span></code></pre>
<p>This will have the same behavior as before and will no longer be considered an
undefined symbol to <code>wasm-ld</code>, and it'll work both before and after this change.</p>
<p>Affected users can also compile with <code>-Clink-arg=--allow-undefined</code> as well to
quickly restore the old behavior.</p>
<h3><a class="anchor" href="https://blog.rust-lang.org/2026/04/04/changes-to-webassembly-targets-and-handling-undefined-symbols/#when-is-this-change-being-made"></a>
When is this change being made?</h3>
<p>Removing <code>--allow-undefined</code> on wasm targets is being done in
<a href="https://github.com/rust-lang/rust/pull/149868" rel="external">rust-lang/rust#149868</a>. That change is slated to land in nightly soon, and will then get released with Rust 1.96 on 2026-05-28. If you see any issues as a
result of this fallout please don't hesitate to file an issue on
<a href="https://github.com/rust-lang/rust" rel="external">rust-lang/rust</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox Tooling Announcements: Engineering Effectiveness Newsletter (Q1 2026 Edition)]]></title>
<description><![CDATA[Welcome to the Q1 edition of the Engineering Effectiveness Newsletter! The Engineering Effectiveness org makes it easy to develop, test and release Mozilla software at scale. See below for some highlights, then read on for more detailed info!
Highlights

Suhaib Integrated Review Helper with Phabr...]]></description>
<link>https://tsecurity.de/de/3501667/tools/firefox-tooling-announcements-engineering-effectiveness-newsletter-q1-2026-edition/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501667/tools/firefox-tooling-announcements-engineering-effectiveness-newsletter-q1-2026-edition/</guid>
<pubDate>Fri, 08 May 2026 23:25:00 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Welcome to the Q1 edition of the Engineering Effectiveness Newsletter! The Engineering Effectiveness org makes it easy to develop, test and release Mozilla software at scale. See below for some highlights, then read on for more detailed info!</p>
<h3><a class="anchor" href="https://discourse.mozilla.org/#p-293819-highlights-1" name="p-293819-highlights-1"></a>Highlights</h3>
<ul>
<li>Suhaib Integrated Review Helper with Phabricator and moz-phab making AI-powered code review quick and simple.</li>
<li>Connor Sheehan implemented ETL from Lando to STMO, which allows us to get better visibility into lando’s performance and usage.</li>
<li>Firefox 150 will ship with new PDF editing features completed by Calixte, letting users delete, copy, move, and export pages to a new PDF.</li>
</ul>
<h3><a class="anchor" href="https://discourse.mozilla.org/#p-293819-detailed-project-updates-2" name="p-293819-detailed-project-updates-2"></a>Detailed Project Updates</h3>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-ai-for-development-3" name="p-293819-ai-for-development-3"></a>AI for Development</h4>
<ul>
<li>Suhaib Mujahid integrated Review Helper with Phabricator, enabling AI-powered code review directly from patches by clicking a “Request AI Review” button, allowing it to analyze the patch and post comments with any findings.</li>
<li>Suhaib Mujahid extended moz-phab to support requesting an AI review at patch submission time, enabling contributors to trigger Review Helper analysis directly from the command line via moz-phab --ai.</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-bugzilla-4" name="p-293819-bugzilla-4"></a>Bugzilla</h4>
<ul>
<li>Marco trained a new model in bugbug to detect bugs that are accessibility-related and missing the “access” keyword, to bring them to the attention of the accessibility team
<ul>
<li>First bugs found: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2026654">Bug 2026654</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2026647">Bug 2026647</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2025992">Bug 2025992</a></li>
</ul>
</li>
<li>Two fixes from dkl to improve the reliability of the background bot that syncs Phabricator revisions with Bugzilla bugs.</li>
<li>Kohei updated the markdown comment editor now intelligently handles pasting URLs. When you paste a URL while text is selected, it automatically formats it as a markdown link “<a>selected text</a>”.</li>
<li>Kohei has also done significant improvements to the Guided Bug Entry page for new Bugzilla pages that should be going live soon.</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-build-system-and-mach-environment-5" name="p-293819-build-system-and-mach-environment-5"></a>Build System and Mach Environment</h4>
<ul>
<li>Better scheduling of rust dependencies through <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2011880">Bug 2011880</a> leads to ~1m saving in build time for opt build with hot cache.</li>
<li>Warning flags can no longer be added directly to CFLAGS or CXXFLAGS in moz.build, they have to go in COMPILE_FLAGS[“WARNINGS_CXXFLAGS”] (resp. COMPILE_FLAGS[“WARNINGS_CFLAGS”]) (see <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1986258">Bug 1986258</a>)</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-firefox-ci-taskcluster-and-treeherder-6" name="p-293819-firefox-ci-taskcluster-and-treeherder-6"></a>Firefox-CI, Taskcluster and Treeherder</h4>
<ul>
<li>Matt Boris upgraded FxCI to use RabbitMQ quorum queues and upgraded pulse to the latest available version for performance, security, and reliability.</li>
<li>Abhishek Madan migrated schema validation from Voluptuous to msgspec across taskgraph, mozilla-taskgraph, and firefox, resulting in a 30% improvement to decision task times.
<ul>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1652123">Bug for conversion in Firefox</a>, <a href="https://github.com/taskcluster/taskgraph/pull/844" rel="noopener nofollow ugc">PR in Taskgraph</a>, <a href="https://github.com/mozilla-releng/mozilla-taskgraph/pull/160" rel="noopener nofollow ugc">PR in Mozilla-Taskgraph</a></li>
</ul>
</li>
<li>Abhishek Madan moved Firefox from a vendored copy of taskgraph to PyPI installs at setup time, enabling support for packages that include compiled components.
<ul>
<li><a href="https://phabricator.services.mozilla.com/D273841" rel="noopener nofollow ugc">Patch stack</a></li>
</ul>
</li>
<li>Andrew Halberstadt made lots of progress migrating CI to Github, currently being used by mozilla/enterprise-firefox:
<ul>
<li><a href="http://bugzilla.mozilla.org/show_bug.cgi?id=2009019">Support for actions</a></li>
<li>Fixed <a href="http://bugzilla.mozilla.org/show_bug.cgi?id=2013889">index</a> and <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1998731">Treeherder</a> routes</li>
<li><a href="http://bugzilla.mozilla.org/show_bug.cgi?id=2021009">Support for mach try</a></li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2027836">Added pull_request_number as a parameter</a></li>
</ul>
</li>
<li>Andrew Halberstadt <a href="https://github.com/taskcluster/taskcluster/pull/8431" rel="noopener nofollow ugc">wrote a patch</a> implementing the ability for the Taskcluster Github service to trigger hooks listed in .taskcluster.yml files. This will pave the way to share cross-project workflows and simplify in-repo configuration.</li>
<li>Cameron Dawson upgraded major frontend libraries of Treeherder</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-lint-static-analysis-and-code-coverage-7" name="p-293819-lint-static-analysis-and-code-coverage-7"></a>Lint, Static Analysis and Code Coverage</h4>
<ul>
<li>New linter for header guards, through <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2009182">bug 2009182</a>, triggered by mach lint --linter header-guards . It enforces our code style.</li>
<li>A limited subset of clang-tidy’s static analysis is now run and enforced on our whole codebase. It is also reported during review on phabricator (see <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2023518">Bug 2023518</a> and related bugs)</li>
<li>ESLint and Prettier have been<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2009689"> updated to the latest versions</a>.
<ul>
<li>This included a<a href="https://github.com/gajus/eslint-plugin-jsdoc/issues/1619" rel="noopener nofollow ugc"> fix for eslint-plugin-jsdoc check-property-names</a> rule which was raising some false-positives in firefox-main.</li>
</ul>
</li>
<li><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1967204">eslint-env comments are being removed</a> as ESLint v9 does not support them (use eslint-file-globals.config.mjs instead). ESLint v10 (currently in rc) will raise errors for them.</li>
<li>More eslint-plugin-jsdoc rules have been<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2009691"> enabled across the whole tree</a>. These are the ones relating to valid-jsdoc. A few remain, but will need work by teams to fix the failur</li>
<li>The “Black” python formatter has now been<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2006716"> replaced by “Ruff”</a>.</li>
<li>Marco greatly simplified the code coverage infrastructure, getting rid of two Heroku services, a frontend service, and a lot of code. The code coverage official UI is now Searchfox.</li>
<li>Marco added a <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2017368">new mach command</a> (“./mach coverage-report”) to generate a coverage report from a push. The command is documented on the <a href="https://firefox-source-docs.mozilla.org/tools/code-coverage/index.html#generate-report-locally">code coverage page</a> in the Firefox source docs.</li>
<li>Teklia added added support for Github pull requests to Code Review Bot (prototype)</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-pdfjs-8" name="p-293819-pdfjs-8"></a>PDF.js</h4>
<ul>
<li>Calixte finished the implementation of the new reorganize and split functionality in PDF, which will ship in Firefox 150! Users will be able to delete, copy, move pages, and to export a subset of pages to a new PDF.</li>
<li>Nicolò Ribaudo implemented the ability to open context menus on images in PDFs, allowing users to perform actions they are used to (such as downloading images). This was a <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1012805">long standing feature request</a> (11 years!).</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-firefox-translations-9" name="p-293819-firefox-translations-9"></a>Firefox Translations</h4>
<ul>
<li>Evgeny Pavlov, Jaume Zaragoza-Bernabeu, and Sergio Ortiz Rojas contributed to training both new and improved Translations models for use in Firefox.
<ul>
<li>Bosnian</li>
<li>Croatian</li>
<li>Norwegian Bokmål</li>
<li>Serbian</li>
<li>Thai</li>
<li>Traditional Chinese</li>
<li>Vietnamese</li>
</ul>
</li>
<li>Erik Nordin fixed an issue where text contained within stand-alone SVG images was not being translated (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2003545">Bug 2003545</a>).</li>
<li>Erik Nordin reworked the Translations settings to be compatible with the upcoming about:settings redesign (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2002127">Bug 2002127</a>).</li>
<li>Erik Nordin helped design a system to control the enablement of <a href="https://searchfox.org/firefox-main/source/toolkit/components/ml/AIFeature.sys.mjs" rel="noopener nofollow ugc">AI Features</a> within Firefox, and worked to make the entire Translations feature set have the capability to be turned off and back on within the same browsing session (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2010922">Bug 2010922</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2010993">Bug 2010993</a>).</li>
<li>Erik Nordin reworked the about:translations page in order to get it ready for an official release with a URL-bar QuickAction entry point. (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004463">Bug 2004463</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2016677">Bug 2016677</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2015798"> Bug 2015798</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2016658"> Bug 2016658</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2016675"> Bug 2016675</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2016690">Bug 2016690</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019753"> Bug 2019753</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2020014"> Bug 2020014</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2020062"> Bug 2020062</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2020067"> Bug2020067</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2022838"> Bug2022838</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1814168">Bug 1814168</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1814195"> Bug 1814195</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1841109"> Bug 1841109</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1869772"> Bug 1869772</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1879933"> Bug 1879933</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1970962"> Bug 1970962</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1990333"> Bug 1990333</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1991224"> Bug 1991224</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1992230"> Bug 1992230</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1992231"> Bug 1992231</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1992232"> Bug 1992232</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1992233"> Bug 1992233</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2000959"> Bug 2000959</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004471"> Bug 2004471</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004473"> Bug 2004473</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019119"> Bug 2019119</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019120"> Bug 2019120</a>, <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1970963">Bug 1970963</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004454"> Bug 2004454</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2010399"> Bug 2010399</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2023677"> Bug 2023677</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1836451"> Bug 1836451</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1999999"> Bug 1999999</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004476"> Bug 2004476</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004477"> Bug 2004477</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004479"> Bug 2004479</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2004962"> Bug 2004962</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2007007"> Bug 2007007</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2007194"> Bug 2007194</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2007551"> Bug 2007551</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2008213"> Bug 2008213</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2008257"> Bug 2008257</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2010335"> Bug 2010335</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019116"> Bug 2019116</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019117"> Bug 2019117</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019121"> Bug 2019121</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019123"> Bug 2019123</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2020697"> Bug 2020697</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2020841"> Bug 2020841</a>,<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2024467"> Bug 2024467</a>)
<ul>
<li>Thank you to Dasha Andriyenko for designing the visuals and UX of the page.</li>
<li>Thank you to Kim Bryant for managing the product and release considerations.</li>
<li>Thank you to Sam Foster and Greg Tatum who reviewed a significant portion of the code.</li>
<li>Thank you to Ciprian Georgiu and Giorgia Nichita for testing quality assurance.</li>
<li>Thank you to Anna Yeddi for reviewing engineering accessibility characteristics.</li>
<li>Thank you to Dale Harvey for designing the QuickAction system that this feature plugs into.</li>
</ul>
</li>
<li>Leonardo Paffi improved our testing capabilities by allowing us to serve inline HTML on the fly, rather than having to add an HTML file into the repository. This eases the burden of overhead to test special-case language characteristics, and ultimately helped us release Norwegian Bokmål (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1996967">Bug 1996967</a>).</li>
<li>Leonardo Paffi improved our handling of the macro language tag for Norwegian (no) to be compatible with our support for Norwegian Bokmål translations (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2019123">Bug 2019123</a>).</li>
<li>Tyler Etchart removed in-code references to quality estimation models, which are not utilized during translation inference within Firefox (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1889753">Bug 1889753</a>).</li>
<li>Tyler Etchart updated the generated Translations WASM JavaScript code to have explicit. comments expressing that the file is generated and should not be modified (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1968038">Bug 1968038</a>).</li>
<li>Tyler Etchart removed some old dead code related to prior ideas for Translations within Firefox (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1996681">Bug 1996681</a>).</li>
<li>Emilio Cobos Álvarez fixed an issue where the checkboxes within the Full-Page Translations Panel settings menu were no longer appearing (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2010234">Bug 2010234</a>).</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-phabricator-moz-phab-and-lando-10" name="p-293819-phabricator-moz-phab-and-lando-10"></a>Phabricator, moz-phab, and Lando</h4>
<ul>
<li>Connor Sheehan implemented ETL from Lando to STMO, which allows us to get better visibility into lando’s performance and usage, e.g., the new uplift feature: <a class="inline-onebox" href="https://sql.telemetry.mozilla.org/dashboard/uplift-dashboard?p_date_range=d_last_12_months">Client Challenge</a></li>
<li>Zeid continues spear-heading the GitHub PR pilot, gathering feedback and fixing usability issues as they are reported. One key focus was on supporting triggering the Code Review Bot on request, via pushes to try.</li>
<li>Olivier Mehani added backward-compatible support for try pushes in the new instance of lando. It will become the default soon, but you can try it out now by setting <code>LANDO_TRY_CONFIG=lando-prod-new</code> in your environment prior to running `mach try .</li>
<li>Olivier Mehani landed a small change to lando, to make the current Tree Status visible on main landing pages (<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2025629">Bug 2025629</a>). This, with the landing queue visible on the job details pages, should help get a better understanding of why jobs sometimes seem to take longer than expected to land.</li>
<li>moz-phab had several new releases:
<ul>
<li>Suhaib Mujahid added the --ai flag and submit.ai_review commit option to request an AI review of patches at submission time.</li>
<li>Johan Lorenzo added the --test-plan flag to enable submitting a test plan from the CLI, which is useful for working with AI agents</li>
<li>See the release notes here:
<ul>
<li><a class="inline-onebox" href="https://discourse.mozilla.org/t/mozphab-2-8-2-released/147246/1">MozPhab 2.8.2 Released</a></li>
<li><a class="inline-onebox" href="https://discourse.mozilla.org/t/mozphab-2-8-3-released/147559/1">MozPhab 2.8.3 Released</a></li>
<li><a class="inline-onebox" href="https://discourse.mozilla.org/t/mozphab-2-9-0-released/147579/1">MozPhab 2.9.0 Released</a></li>
<li><a class="inline-onebox" href="https://discourse.mozilla.org/t/mozphab-2-9-1-released/147741/1">MozPhab 2.9.1 Released</a></li>
<li><a class="inline-onebox" href="https://discourse.mozilla.org/t/mozphab-2-10-0-released/147778/1">MozPhab 2.10.0 Released</a></li>
<li><a class="inline-onebox" href="https://discourse.mozilla.org/t/mozphab-2-11-0-released/147789/1">MozPhab 2.11.0 Released</a></li>
<li><a href="https://discourse.mozilla.org/t/mozphab-2-11-1-released/147821/1">https://discourse.mozilla.org/t/mozphab-2-11-1-released/147821/1 </a></li>
</ul>
</li>
</ul>
</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-release-engineering-and-release-management-11" name="p-293819-release-engineering-and-release-management-11"></a>Release Engineering and Release Management</h4>
<ul>
<li>Ben Hearsum added <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1837440">new tests to verify update integrity on mozilla-central</a>.</li>
<li>Julien Cristau updated the docker images for many build and related tasks from Debian 12 to Debian 13</li>
<li>Relman streamlined the release process by removing the Nightly soft code freeze and adjusting the Beta schedule to reduce end-of-cycle friction, create more effective stabilization time, and simplify release candidate workflows.</li>
<li>We now ship to the Xiaomi Store.</li>
<li>Delivered mid-cycle ESR dot releases to address critical security fixes ahead of the standard cadence, improving responsiveness while coordinating across multiple ESR versions and release channels.</li>
<li>Andrew Halberstadt helped support and build out the Firefox Enterprise release pipeline.</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-release-operations-12" name="p-293819-release-operations-12"></a>Release Operations</h4>
<ul>
<li>Mark Cornmesser improved Windows hardware management, including self-configuration and self-deployment capabilities, automated BIOS management, and standardization of BIOS settings across performance testing environments to ensure consistency and reliability.</li>
</ul>
<h4><a class="anchor" href="https://discourse.mozilla.org/#p-293819-other-13" name="p-293819-other-13"></a>Other</h4>
<ul>
<li>
<p>Thanks to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2013401">Bug #2013401</a> mozilla::Maybe&lt;scalar_type&gt; generates better and denser code, which led to a reduction of 300kB for libxul.so</p>
</li>
<li>
<p>Thanks to <a href="https://github.com/llvm/llvm-project/pull/184136" rel="noopener nofollow ugc">A new clang-tidy pass</a> we’ve been able to automatically add std::move in location where it could improve performance (see <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=2012658">Bug 2012658</a>)</p>
</li>
</ul>
<p>Thanks for reading and see you next quarter!</p>
            <p><small>1 post - 1 participant</small></p>
            <p><a href="https://discourse.mozilla.org/t/engineering-effectiveness-newsletter-q1-2026-edition/147880">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[13 new critical holes in JavaScript sandbox allow execution of arbitrary code]]></title>
<description><![CDATA[Thirteen critical vulnerabilities have been found in the vm2 JavaScript sandbox package that could allow an attacker’s code to escape the container and do nasty things to IT environments. As a result, developers using this library in their applications are urged to update the software to the late...]]></description>
<link>https://tsecurity.de/de/3497651/ai-nachrichten/13-new-critical-holes-in-javascript-sandbox-allow-execution-of-arbitrary-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497651/ai-nachrichten/13-new-critical-holes-in-javascript-sandbox-allow-execution-of-arbitrary-code/</guid>
<pubDate>Fri, 08 May 2026 02:34:37 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Thirteen critical vulnerabilities have been found in the vm2 JavaScript sandbox package that could allow an attacker’s code to escape the container and do nasty things to IT environments. As a result, developers using this library in their applications are urged to update the software to the latest version, which is currently 3.11.2.</p>



<p>The warnings come in advisories from vm2 maintainer <a href="https://github.com/patriksimek" target="_blank" rel="noreferrer noopener">Patrik Simek</a>.</p>



<p>vm2 is an open source vm/sandbox that can run untrusted code with whitelisted Node.js’s built-in modules.</p>



<p>One of the more serious of the 13 vulnerabilities is <a href="https://www.cve.org/CVERecord?id=CVE-2026-26956" target="_blank" rel="noreferrer noopener">CVE-2026-26956</a>, a full sandbox escape with arbitrary code execution. Attacker code that is inside <em>VM.run()</em> can obtain host process object and runs host commands with zero co-operation from the host.</p>



<p>However, researchers at Socket told us in an email that <a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-ffh4-j6h5-pg66" target="_blank" rel="noreferrer noopener">the advisory</a> about this escape says it has been confirmed only on Node.js 25.6.1, and requires a Node.js version with WebAssembly exception handling and <em>JSTag</em> support.</p>



<p>The highest-risk scenario, they said, would be an application using vm2 version 3.10.4 on Node 25, where attacker-controlled JavaScript is passed into <em>VM.run()</em>.</p>



<p>“This is a narrow but high-impact vulnerability,” Socket research engineer <a href="https://wenxin-jiang.github.io/" target="_blank" rel="noreferrer noopener">Wenxin Jiang</a> said in an email. “It does not appear to affect every vm2 deployment, because the advisory points to a specific vulnerable version and a specific Node 25/WebAssembly combination. But when those conditions line up, the security boundary fails completely: code that was supposed to be confined to the sandbox can reach the host process and execute commands. That is why teams using vm2 for user-supplied JavaScript should patch quickly and review what the sandboxed process can access.”</p>



<p>Although it is not a vm2 maintainer, Socket said it is issuing a patch for developers who can’t immediately upgrade to the latest, fixed version.</p>



<p>Another serious hole is <a href="https://www.tenable.com/cve/CVE-2026-44007" target="_blank" rel="noreferrer noopener">CVE-2026-44007</a>, an improper access control vulnerability in the vm2 Node.js library that allows sandbox escape and execution of arbitrary operating system commands on the underlying host. <a href="https://github.com/advisories/GHSA-8hg8-63c5-gwmx" target="_blank" rel="noreferrer noopener">Its advisory says</a> that the vulnerability is in how the <em>nesting:true</em> option interacts with the legacy module resolver. This was patched in vm2 version 3.11.1.</p>



<p>“For CSOs, both [vulnerabilities] deserve urgent attention,” said Jiang, “but the second [the NodeVM nesting issue] may be the one more organizations need to audit for immediately.”</p>



<p>Both flaws, said Socket researchers, can turn sandboxed JavaScript into command execution on the host system. The difference is in how many environments are likely to be exposed. The Node 25/WebAssembly issue appears narrower because it depends on a specific vm2 version and a specific newer Node.js runtime behavior. The NodeVM nesting issue may be broader because it affects more versions and is triggered by a configuration pattern that some developers may have used intentionally.</p>



<p>Jiang added that both advisories point to a broader lesson: JavaScript sandboxes are <a href="https://www.csoonline.com/article/4123782/critical-bug-in-popular-vm2-node-js-sandboxing-library-puts-projects-at-risk.html" target="_blank">difficult to secure</a>, and small differences in runtime behavior or configuration can have major security consequences. “The first issue appears tied to a narrow Node 25/WebAssembly path,” he said. “This second issue is a configuration-driven escape involving NodeVM and <em>nesting:true</em>.</p>



<p>In both cases, the highest-risk users are organizations that run untrusted JavaScript and assume vm2 is containing it. Those [application development] teams should patch immediately and add stronger isolation around sandboxed workloads.”</p>



<h2 class="wp-block-heading">‘Fragile security model’  </h2>



<p>These sandbox escape vulnerabilities demonstrate why sandboxing untrusted code inside a trusted process is a fragile security model, <a href="https://www.linkedin.com/in/ar6s/" target="_blank" rel="noreferrer noopener">Adam Reynolds</a>, senior security researcher at Sonatype, said in an email. “Once untrusted code runs inside a process with access to credentials and secrets, the underlying filesystem, the network, or with deployment privileges, a sandbox bypass can easily lead to a full system compromise,” he said.</p>



<p>Simply having vm2 installed somewhere in the dependency tree is not enough to make some of these vulnerabilities exploitable, he added. For example, an attacker generally needs the ability to execute crafted JavaScript (and in the case of CVE-2026-26956, crafted WebAssembly) inside a vm2 sandbox controlled by the vulnerable application. If the application never instantiates vm2, only uses it for trusted internal scripts, or does not allow attacker-controlled code execution at all, then there may be no realistic exploit path despite the presence of the dependency.</p>



<p>If an organization is running any applications impacted by vm2, they should be upgraded immediately, he said. To mitigate risk until the upgrade is complete, users can avoid Node.js 25 runtimes, disable or block WebAssembly entirely inside untrusted sandboxes, and prevent user-controlled WASM compilation/execution.</p>



<p>“Since future runtime updates could lead to similar issues, vm2 should be viewed as a convenience isolation layer as opposed to a hard security boundary,” he added.</p>



<p>In addition, <a href="https://www.linkedin.com/in/rob-enderle-03729/" target="_blank" rel="noreferrer noopener">Robert Enderle</a> of the Enderle Group said that IT leaders who are serious about security should stop relying on software-level sandboxing for untrusted code. Start looking at moving those processes into hardened Docker containers or V8 Isolates, he advised.</p>



<p><em>This article originally appeared on <a href="https://www.csoonline.com/article/4168568/13-new-critical-holes-in-javascript-sandbox-allow-execution-of-arbitrary-code.html" target="_blank">CSOonline</a>.</em></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[13 new critical holes in JavaScript sandbox allow execution of arbitrary code]]></title>
<description><![CDATA[Thirteen critical vulnerabilities have been found in the vm2 JavaScript sandbox package that could allow an attacker’s code to escape the container and do nasty things to IT environments. As a result, developers using this library in their applications are urged to update the software to the late...]]></description>
<link>https://tsecurity.de/de/3497626/it-security-nachrichten/13-new-critical-holes-in-javascript-sandbox-allow-execution-of-arbitrary-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3497626/it-security-nachrichten/13-new-critical-holes-in-javascript-sandbox-allow-execution-of-arbitrary-code/</guid>
<pubDate>Fri, 08 May 2026 02:26:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Thirteen critical vulnerabilities have been found in the vm2 JavaScript sandbox package that could allow an attacker’s code to escape the container and do nasty things to IT environments. As a result, developers using this library in their applications are urged to update the software to the latest version, which is currently 3.11.2.</p>



<p>The warnings come in advisories from vm2 maintainer <a href="https://github.com/patriksimek" target="_blank" rel="noreferrer noopener">Patrik Simek</a>.</p>



<p>vm2 is an open source vm/sandbox that can run untrusted code with whitelisted Node.js’s built-in modules.</p>



<p>One of the more serious of the 13 vulnerabilities is <a href="https://www.cve.org/CVERecord?id=CVE-2026-26956" target="_blank" rel="noreferrer noopener">CVE-2026-26956</a>, a full sandbox escape with arbitrary code execution. Attacker code that is inside <em>VM.run()</em> can obtain host process object and runs host commands with zero co-operation from the host.</p>



<p>However, researchers at Socket told us in an email that <a href="https://github.com/patriksimek/vm2/security/advisories/GHSA-ffh4-j6h5-pg66" target="_blank" rel="noreferrer noopener">the advisory</a> about this escape says it has been confirmed only on Node.js 25.6.1, and requires a Node.js version with WebAssembly exception handling and <em>JSTag</em> support.</p>



<p>The highest-risk scenario, they said, would be an application using vm2 version 3.10.4 on Node 25, where attacker-controlled JavaScript is passed into <em>VM.run()</em>.</p>



<p>“This is a narrow but high-impact vulnerability,” Socket research engineer <a href="https://wenxin-jiang.github.io/" target="_blank" rel="noreferrer noopener">Wenxin Jiang</a> said in an email. “It does not appear to affect every vm2 deployment, because the advisory points to a specific vulnerable version and a specific Node 25/WebAssembly combination. But when those conditions line up, the security boundary fails completely: code that was supposed to be confined to the sandbox can reach the host process and execute commands. That is why teams using vm2 for user-supplied JavaScript should patch quickly and review what the sandboxed process can access.”</p>



<p>Although it is not a vm2 maintainer, Socket said it is issuing a patch for developers who can’t immediately upgrade to the latest, fixed version.</p>



<p>Another serious hole is <a href="https://www.tenable.com/cve/CVE-2026-44007" target="_blank" rel="noreferrer noopener">CVE-2026-44007</a>, an improper access control vulnerability in the vm2 Node.js library that allows sandbox escape and execution of arbitrary operating system commands on the underlying host. <a href="https://github.com/advisories/GHSA-8hg8-63c5-gwmx" target="_blank" rel="noreferrer noopener">Its advisory says</a> that the vulnerability is in how the <em>nesting:true</em> option interacts with the legacy module resolver. This was patched in vm2 version 3.11.1.</p>



<p>“For CSOs, both [vulnerabilities] deserve urgent attention,” said Jiang, “but the second [the NodeVM nesting issue] may be the one more organizations need to audit for immediately.”</p>



<p>Both flaws, said Socket researchers, can turn sandboxed JavaScript into command execution on the host system. The difference is in how many environments are likely to be exposed. The Node 25/WebAssembly issue appears narrower because it depends on a specific vm2 version and a specific newer Node.js runtime behavior. The NodeVM nesting issue may be broader because it affects more versions and is triggered by a configuration pattern that some developers may have used intentionally.</p>



<p>Jiang added that both advisories point to a broader lesson: JavaScript sandboxes are <a href="https://www.csoonline.com/article/4123782/critical-bug-in-popular-vm2-node-js-sandboxing-library-puts-projects-at-risk.html" target="_blank">difficult to secure</a>, and small differences in runtime behavior or configuration can have major security consequences. “The first issue appears tied to a narrow Node 25/WebAssembly path,” he said. “This second issue is a configuration-driven escape involving NodeVM and <em>nesting:true</em>.</p>



<p>In both cases, the highest-risk users are organizations that run untrusted JavaScript and assume vm2 is containing it. Those [application development] teams should patch immediately and add stronger isolation around sandboxed workloads.”</p>



<h2 class="wp-block-heading">‘Fragile security model’  </h2>



<p>These sandbox escape vulnerabilities demonstrate why sandboxing untrusted code inside a trusted process is a fragile security model, <a href="https://www.linkedin.com/in/ar6s/" target="_blank" rel="noreferrer noopener">Adam Reynolds</a>, senior security researcher at Sonatype, said in an email. “Once untrusted code runs inside a process with access to credentials and secrets, the underlying filesystem, the network, or with deployment privileges, a sandbox bypass can easily lead to a full system compromise,” he said.</p>



<p>Simply having vm2 installed somewhere in the dependency tree is not enough to make some of these vulnerabilities exploitable, he added. For example, an attacker generally needs the ability to execute crafted JavaScript (and in the case of CVE-2026-26956, crafted WebAssembly) inside a vm2 sandbox controlled by the vulnerable application. If the application never instantiates vm2, only uses it for trusted internal scripts, or does not allow attacker-controlled code execution at all, then there may be no realistic exploit path despite the presence of the dependency.</p>



<p>If an organization is running any applications impacted by vm2, they should be upgraded immediately, he said. To mitigate risk until the upgrade is complete, users can avoid Node.js 25 runtimes, disable or block WebAssembly entirely inside untrusted sandboxes, and prevent user-controlled WASM compilation/execution.</p>



<p>“Since future runtime updates could lead to similar issues, vm2 should be viewed as a convenience isolation layer as opposed to a hard security boundary,” he added.</p>



<p>In addition, <a href="https://www.linkedin.com/in/rob-enderle-03729/" target="_blank" rel="noreferrer noopener">Robert Enderle</a> of the Enderle Group said that IT leaders who are serious about security should stop relying on software-level sandboxing for untrusted code. Start looking at moving those processes into hardened Docker containers or V8 Isolates, he advised.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026-05-05, Version 26.0.0 (Current), @RafaelGSS]]></title>
<description><![CDATA[We're excited to announce the release of Node.js 26! Highlights include the Temporal API enabled by default,
updates to the V8 JavaScript engine to 14.6, Undici to 8.0, and several important deprecations and removals
as we continue to modernize the platform.
As a reminder, Node.js 26 will enter l...]]></description>
<link>https://tsecurity.de/de/3489876/downloads/2026-05-05-version-2600-current-rafaelgss/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3489876/downloads/2026-05-05-version-2600-current-rafaelgss/</guid>
<pubDate>Tue, 05 May 2026 16:31:00 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>We're excited to announce the release of Node.js 26! Highlights include the Temporal API enabled by default,<br>
updates to the V8 JavaScript engine to 14.6, Undici to 8.0, and several important deprecations and removals<br>
as we continue to modernize the platform.</p>
<p>As a reminder, Node.js 26 will enter long-term support (LTS) in October, but until then, it will be the "Current" release for the next six months.<br>
We encourage you to explore the new features and benefits offered by this latest release and evaluate their potential impact on your applications.</p>
<h3>Notable Changes</h3>
<h4>Temporal API</h4>
<p>The Temporal API is now enabled by default in Node.js 26. Temporal is a modern date/time API for JavaScript<br>
that provides a more robust and feature-rich alternative to the legacy <code>Date</code> object.</p>
<p>Contributed by Richard Lau in <a href="https://github.com/nodejs/node/pull/61806" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61806/hovercard">#61806</a>.</p>
<h4>V8 14.6</h4>
<p>The V8 engine is updated to version 14.6.202.33, which is part of Chromium 134.</p>
<p>This version also includes:</p>
<ul>
<li>Upsert (<a href="https://github.com/tc39/proposal-upsert">https://github.com/tc39/proposal-upsert</a>): <code>[Weak]Map.prototype.getOrInsert()</code>, <code>[Weak]Map.prototype.getOrInsertComputed()</code></li>
<li>Iterator sequencing (<a href="https://github.com/tc39/proposal-iterator-sequencing">https://github.com/tc39/proposal-iterator-sequencing</a>): <code>Iterator.concat()</code></li>
</ul>
<p>Contributed by Michaël Zasso in <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a>.</p>
<h4>Undici 8</h4>
<p>Undici has been updated to version 8.0.2, bringing new features and improvements to Node.js's HTTP client implementation.</p>
<h4>Deprecations and Removals</h4>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/dff46c07c3"><code>dff46c07c3</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>crypto</strong>: move DEP0182 to End-of-Life (Tobias Nießen) <a href="https://github.com/nodejs/node/pull/61084" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61084/hovercard">#61084</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/93c25815ee"><code>93c25815ee</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>http</strong>: move writeHeader to end-of-life (Sebastian Beltran) <a href="https://github.com/nodejs/node/pull/60635" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60635/hovercard">#60635</a></li>
</ul>
<p><code>http.Server.prototype.writeHeader()</code> is now fully removed. Use <code>http.Server.prototype.writeHead()</code> instead.</p>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/c755b0113c"><code>c755b0113c</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>stream</strong>: move _stream_* to end-of-life (Sebastian Beltran) <a href="https://github.com/nodejs/node/pull/60657" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60657/hovercard">#60657</a></li>
</ul>
<p>The legacy <code>_stream_wrap</code>, <code>_stream_readable</code>, <code>_stream_writable</code>, <code>_stream_duplex</code>, <code>_stream_transform</code>, and <code>_stream_passthrough</code> modules are now fully removed.</p>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/adac077484"><code>adac077484</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>crypto</strong>: runtime-deprecate DEP0203 and DEP0204 (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62453" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62453/hovercard">#62453</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ac6375417a"><code>ac6375417a</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>stream</strong>: promote DEP0201 to runtime deprecation (René) <a href="https://github.com/nodejs/node/pull/62173" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62173/hovercard">#62173</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/98907f560f"><code>98907f560f</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>module</strong>: runtime-deprecate module.register() (Geoffrey Booth) <a href="https://github.com/nodejs/node/pull/62401" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62401/hovercard">#62401</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/89f4b6cddb"><code>89f4b6cddb</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>module</strong>: remove --experimental-transform-types (Marco Ippolito) <a href="https://github.com/nodejs/node/pull/61803" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61803/hovercard">#61803</a></li>
</ul>
<h3>Semver-Major Commits</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/d3f79aa65d"><code>d3f79aa65d</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>assert</strong>: allow printf-style messages as assertion error (Ruben Bridgewater) <a href="https://github.com/nodejs/node/pull/58849" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/58849/hovercard">#58849</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f6ce381fec"><code>f6ce381fec</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>build</strong>: bump GCC requirement to 13.2 (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/62555" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62555/hovercard">#62555</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bff81fca46"><code>bff81fca46</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>build</strong>: enable Temporal by default (Richard Lau) <a href="https://github.com/nodejs/node/pull/61806" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61806/hovercard">#61806</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6ddb1643e1"><code>6ddb1643e1</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>build</strong>: enable V8_VERIFY_WRITE_BARRIERS in debug build (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a8ab08b373"><code>a8ab08b373</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>build</strong>: reset embedder string to "-node.0" (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0998c37eb6"><code>0998c37eb6</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>build</strong>: target Power 9 for AIX/IBM i (Richard Lau) <a href="https://github.com/nodejs/node/pull/62296" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62296/hovercard">#62296</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d73c49e849"><code>d73c49e849</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>build</strong>: drop support for Python 3.9 (Mike McCready) <a href="https://github.com/nodejs/node/pull/61177" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61177/hovercard">#61177</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3c92ee1008"><code>3c92ee1008</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>build</strong>: enable maglev for Linux on s390x (Richard Lau) <a href="https://github.com/nodejs/node/pull/60863" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60863/hovercard">#60863</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/908c468828"><code>908c468828</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>build</strong>: reset embedder string to "-node.0" (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/60488" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60488/hovercard">#60488</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6380fbb5ee"><code>6380fbb5ee</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>build</strong>: reset embedder string to "-node.0" (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/60111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60111/hovercard">#60111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/089d6c77e7"><code>089d6c77e7</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>(<a title="CVE-2026-21717" data-hovercard-type="advisory" data-hovercard-url="/advisories/GHSA-326m-34v3-gv5p/hovercard" href="https://github.com/advisories/GHSA-326m-34v3-gv5p">CVE-2026-21717</a>)</strong> <strong>build,test</strong>: test array index hash collision (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f9bd0165c4"><code>f9bd0165c4</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>build,win</strong>: fix Temporal build (StefanStojanovic) <a href="https://github.com/nodejs/node/pull/61806" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61806/hovercard">#61806</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6cc4cf8fe8"><code>6cc4cf8fe8</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>crypto</strong>: unify asymmetric key import through KeyObjectHandle::Init (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62499" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62499/hovercard">#62499</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/adac077484"><code>adac077484</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>crypto</strong>: runtime-deprecate DEP0203 and DEP0204 (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62453" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62453/hovercard">#62453</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/74509b166a"><code>74509b166a</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>crypto</strong>: decorate async crypto job errors with OpenSSL error details (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62348" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62348/hovercard">#62348</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/da5843b91d"><code>da5843b91d</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>crypto</strong>: default ML-KEM and ML-DSA pkcs8 export to seed-only format (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62178" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62178/hovercard">#62178</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dff46c07c3"><code>dff46c07c3</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>crypto</strong>: move DEP0182 to End-of-Life (Tobias Nießen) <a href="https://github.com/nodejs/node/pull/61084" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61084/hovercard">#61084</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/94cd600542"><code>94cd600542</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>crypto</strong>: fix DOMException name for non-extractable key error (Filip Skokan) <a href="https://github.com/nodejs/node/pull/60830" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60830/hovercard">#60830</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dae2219cca"><code>dae2219cca</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: V8: cherry-pick 0f024d4e66e0 (ishabi) <a href="https://github.com/nodejs/node/pull/62408" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62408/hovercard">#62408</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/15d406c1b1"><code>15d406c1b1</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: fix V8 race condition for AIX (Abdirahim Musse) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/46852d2d7a"><code>46852d2d7a</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: V8: cherry-pick cd2c216e7658 (LuYahan) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/784431d6fc"><code>784431d6fc</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: V8: backport 088b7112e7ab (Igor Sheludko) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3839c4a756"><code>3839c4a756</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: V8: cherry-pick 00f6e834029f (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44f64f1dd9"><code>44f64f1dd9</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: V8: backport bef0d9c1bc90 (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1f8f288e22"><code>1f8f288e22</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: V8: cherry-pick cf1bce40a5ef (Richard Lau) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d7eccac9ad"><code>d7eccac9ad</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: V8: cherry-pick daf4656ba85e (Milad Fa) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3ee1ea7d0b"><code>3ee1ea7d0b</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: V8: cherry-pick d83f479604c8 (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/80907c0239"><code>80907c0239</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: V8: cherry-pick edeb0a4fa181 (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5e0dc169e9"><code>5e0dc169e9</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: V8: cherry-pick aa0b288f87cc (Richard Lau) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8c1f7adbcd"><code>8c1f7adbcd</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: patch V8 to fix Windows build (StefanStojanovic) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3cbd3404d9"><code>3cbd3404d9</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: V8: cherry-pick highway@989a498fdf3 (Richard Lau) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9f2b7d4031"><code>9f2b7d4031</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: support madvise(3C) across ALL illumos revisions (Dan McDonald) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/947ec32118"><code>947ec32118</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: patch V8 for illumos (Dan McDonald) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0660b942b2"><code>0660b942b2</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: remove problematic comment from v8-internal (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bef7b31a3f"><code>bef7b31a3f</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: define V8_PRESERVE_MOST as no-op on Windows (Stefan Stojanovic) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a10bf1e6ce"><code>a10bf1e6ce</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: patch V8 to avoid duplicated zlib symbol (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cc547428e1"><code>cc547428e1</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: update V8 to 14.6.202.33 (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b81d2cbcae"><code>b81d2cbcae</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: update undici to 8.0.2 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62384" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62384/hovercard">#62384</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bf5c6a8bd4"><code>bf5c6a8bd4</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: V8: backport 151d0a44a1b2 (Abdirahim Musse) <a href="https://github.com/nodejs/node/pull/60488" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60488/hovercard">#60488</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b59af772dc"><code>b59af772dc</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: V8: cherry-pick 47800791b35c (Jakob Kummerow) <a href="https://github.com/nodejs/node/pull/60488" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60488/hovercard">#60488</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5e41e5228a"><code>5e41e5228a</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: patch V8 for illumos (Dan McDonald) <a href="https://github.com/nodejs/node/pull/59805" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/59805/hovercard">#59805</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2243e58e43"><code>2243e58e43</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: use std::map in MSVC STL for EphemeronRememberedSet (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/58070" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/58070/hovercard">#58070</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4157964c42"><code>4157964c42</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: remove problematic comment from v8-internal (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/58070" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/58070/hovercard">#58070</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7c8483a4e9"><code>7c8483a4e9</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: patch V8 to avoid duplicated zlib symbol (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/54077" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/54077/hovercard">#54077</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/53379f3706"><code>53379f3706</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: update V8 to 14.3.127.12 (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/60488" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60488/hovercard">#60488</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f819aec288"><code>f819aec288</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: V8: cherry-pick ff34ae20c8e3 (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/60111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60111/hovercard">#60111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1acd8df36f"><code>1acd8df36f</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: V8: backport fed47445bbdd (Abdirahim Musse) <a href="https://github.com/nodejs/node/pull/60111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60111/hovercard">#60111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/46f72577a4"><code>46f72577a4</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: patch V8 for illumos (Dan McDonald) <a href="https://github.com/nodejs/node/pull/59805" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/59805/hovercard">#59805</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/39eb88eaa8"><code>39eb88eaa8</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: use std::map in MSVC STL for EphemeronRememberedSet (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/58070" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/58070/hovercard">#58070</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ea3d14eadb"><code>ea3d14eadb</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: remove problematic comment from v8-internal (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/58070" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/58070/hovercard">#58070</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7bc0f245b4"><code>7bc0f245b4</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: patch V8 to avoid duplicated zlib symbol (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/54077" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/54077/hovercard">#54077</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c2843b722c"><code>c2843b722c</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>deps</strong>: update V8 to 14.2.231.9 (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/60111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60111/hovercard">#60111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b4ea323833"><code>b4ea323833</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>diagnostics_channel</strong>: ensure tracePromise consistency with non-Promises (René) <a href="https://github.com/nodejs/node/pull/61766" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61766/hovercard">#61766</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0c08835f71"><code>0c08835f71</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>doc</strong>: remove extensionless CJS exception for type:module packages (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62176" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62176/hovercard">#62176</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ef0f0b0865"><code>ef0f0b0865</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>doc</strong>: update supported Windows SDK version to 11 (Mike McCready) <a href="https://github.com/nodejs/node/pull/61973" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61973/hovercard">#61973</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a00d95c73d"><code>a00d95c73d</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>doc</strong>: drop p8 and z13 support (Milad Fa) <a href="https://github.com/nodejs/node/pull/61005" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61005/hovercard">#61005</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/93c25815ee"><code>93c25815ee</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>http</strong>: move writeHeader to end-of-life (Sebastian Beltran) <a href="https://github.com/nodejs/node/pull/60635" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60635/hovercard">#60635</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4346c0f7a7"><code>4346c0f7a7</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>http</strong>: fix handling of HTTP upgrades with bodies (Tim Perry) <a href="https://github.com/nodejs/node/pull/60016" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60016/hovercard">#60016</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fa70327610"><code>fa70327610</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>lib</strong>: return undefined for localStorage without file (Matteo Collina) <a href="https://github.com/nodejs/node/pull/61333" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61333/hovercard">#61333</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b328bf74bd"><code>b328bf74bd</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>lib,src</strong>: implement QuotaExceededError as DOMException-derived interface (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62293" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62293/hovercard">#62293</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/98907f560f"><code>98907f560f</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>module</strong>: runtime-deprecate module.register() (Geoffrey Booth) <a href="https://github.com/nodejs/node/pull/62401" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62401/hovercard">#62401</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/89f4b6cddb"><code>89f4b6cddb</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>module</strong>: remove --experimental-transform-types (Marco Ippolito) <a href="https://github.com/nodejs/node/pull/61803" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61803/hovercard">#61803</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5334433437"><code>5334433437</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>src</strong>: replace uses of deprecated v8::External APIs (gahaas) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/46e75f4874"><code>46e75f4874</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>src</strong>: stop using <code>v8::PropertyCallbackInfo&lt;T&gt;::This()</code> (Igor Sheludko) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/54fefda0aa"><code>54fefda0aa</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>src</strong>: avoid deprecated Wasm API (Clemens Backes) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/840f509bd1"><code>840f509bd1</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>src</strong>: avoid deprecated <code>FixedArray::Get</code> (Clemens Backes) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/75c3bcc3ec"><code>75c3bcc3ec</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>src</strong>: update NODE_MODULE_VERSION to 147 (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8480f87375"><code>8480f87375</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>src</strong>: remove deprecated and unused isolate fields (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/60488" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60488/hovercard">#60488</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/70b6bd8e19"><code>70b6bd8e19</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>src</strong>: update NODE_MODULE_VERSION to 144 (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/60488" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60488/hovercard">#60488</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d2bc5249b"><code>7d2bc5249b</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>src</strong>: include <code>node_api_types.h</code> instead of <code>node_api.h</code> in <code>node.h</code> (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/60496" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60496/hovercard">#60496</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/91ab1101bc"><code>91ab1101bc</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>src</strong>: update NODE_MODULE_VERSION to 142 (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/60111" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60111/hovercard">#60111</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ac6375417a"><code>ac6375417a</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>stream</strong>: promote DEP0201 to runtime deprecation (René) <a href="https://github.com/nodejs/node/pull/62173" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62173/hovercard">#62173</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c755b0113c"><code>c755b0113c</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>stream</strong>: move _stream_* to end-of-life (Sebastian Beltran) <a href="https://github.com/nodejs/node/pull/60657" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60657/hovercard">#60657</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fadb214d95"><code>fadb214d95</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>stream</strong>: readable read one buffer at a time (Robert Nagy) <a href="https://github.com/nodejs/node/pull/60441" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60441/hovercard">#60441</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4fe325d93d"><code>4fe325d93d</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>stream</strong>: preserve AsyncLocalStorage on finished only when needed (avcribl) <a href="https://github.com/nodejs/node/pull/59873" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/59873/hovercard">#59873</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7682e7e9c5"><code>7682e7e9c5</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>test</strong>: skip wasm allocation tests in workers (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ebfaf25870"><code>ebfaf25870</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>test</strong>: update wpt Wasm jsapi expectations (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ece6a17574"><code>ece6a17574</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>test</strong>: support presence of Temporal global (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/75b8d7a912"><code>75b8d7a912</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>test</strong>: add type tags to uses of v8::External (gahaas) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/092a448ad0"><code>092a448ad0</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>test</strong>: fix test-linux-perf-logger for V8 14.3 (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/60488" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60488/hovercard">#60488</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8eb9c8f794"><code>8eb9c8f794</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>tools</strong>: remove v8_initializers_slow workaround from v8.gyp (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a34fe77fe7"><code>a34fe77fe7</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>tools</strong>: add Rust args to <code>tools/make-v8.sh</code> (Richard Lau) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f4666bd6e3"><code>f4666bd6e3</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>tools</strong>: update V8 gypfiles for 14.6 (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3c23d217a6"><code>3c23d217a6</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>tools</strong>: update V8 gypfiles for 14.5 (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e508489e37"><code>e508489e37</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>tools</strong>: update V8 gypfiles for 14.4 (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/61898" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61898/hovercard">#61898</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dc97b507d0"><code>dc97b507d0</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>util</strong>: mark proxied objects as such when inspecting them (Ruben Bridgewater) <a href="https://github.com/nodejs/node/pull/61029" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61029/hovercard">#61029</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ddbe1365ff"><code>ddbe1365ff</code></a>] - <strong>(SEMVER-MAJOR)</strong> <strong>util</strong>: reduce TextEncoder.encodeInto function size (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/60339" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60339/hovercard">#60339</a></li>
</ul>
<h3>Semver-Minor Commits</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/d4fa60cf9f"><code>d4fa60cf9f</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: add raw key formats support to the KeyObject APIs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62240" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62240/hovercard">#62240</a></li>
</ul>
<h3>Semver-Patch Commits</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/4d8834fbef"><code>4d8834fbef</code></a>] - <strong>build</strong>: add rust target for macOS cross compiles (Richard Lau) <a href="https://github.com/nodejs/node/pull/63015" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/63015/hovercard">#63015</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a4edab8dfb"><code>a4edab8dfb</code></a>] - <strong>build</strong>: use <code>CARGO</code> environment variable if set (Richard Lau) <a href="https://github.com/nodejs/node/pull/62421" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62421/hovercard">#62421</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ecf8721076"><code>ecf8721076</code></a>] - <strong>build</strong>: add weak symbol detection to export script (Abdirahim Musse) <a href="https://github.com/nodejs/node/pull/62656" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62656/hovercard">#62656</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5b9f811662"><code>5b9f811662</code></a>] - <strong>build</strong>: filter hidden visibility symbols on AIX (Abdirahim Musse) <a href="https://github.com/nodejs/node/pull/62656" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62656/hovercard">#62656</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2e724793e6"><code>2e724793e6</code></a>] - <strong>build</strong>: aix add conditonal flags for clang builds (Abdirahim Musse) <a href="https://github.com/nodejs/node/pull/62656" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62656/hovercard">#62656</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f212aee483"><code>f212aee483</code></a>] - <strong>build</strong>: enable temporal on GHA macOS build (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/61691" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61691/hovercard">#61691</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/159ae48f8c"><code>159ae48f8c</code></a>] - <strong>build</strong>: add <code>cargo</code> and <code>rustc</code> checks for Temporal (Richard Lau) <a href="https://github.com/nodejs/node/pull/61467" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61467/hovercard">#61467</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a004535617"><code>a004535617</code></a>] - <strong>build</strong>: add temporal to linux GHA build (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/60942" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60942/hovercard">#60942</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9df9b66c18"><code>9df9b66c18</code></a>] - <strong>crypto</strong>: add support for Ed25519 context parameter (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62474" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62474/hovercard">#62474</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c3042c605b"><code>c3042c605b</code></a>] - <strong>crypto</strong>: recognize raw formats in keygen (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62480" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62480/hovercard">#62480</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ce0f498def"><code>ce0f498def</code></a>] - <strong>deps</strong>: V8: cherry-pick fcf8b990c73c (Abdirahim Musse) <a href="https://github.com/nodejs/node/pull/62894" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62894/hovercard">#62894</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b7fab70d56"><code>b7fab70d56</code></a>] - <em><strong>Revert</strong></em> "<strong>deps</strong>: V8: cherry-pick 7107287" (Richard Lau) <a href="https://github.com/nodejs/node/pull/62894" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62894/hovercard">#62894</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d936c30fb4"><code>d936c30fb4</code></a>] - <strong>deps</strong>: V8: cherry-pick 7107287 (Abdirahim Musse) <a href="https://github.com/nodejs/node/pull/62656" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62656/hovercard">#62656</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c91d00b6d4"><code>c91d00b6d4</code></a>] - <strong>deps</strong>: fix aix implicit declaration in OpenSSL (Abdirahim Musse) <a href="https://github.com/nodejs/node/pull/62656" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62656/hovercard">#62656</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0474a27c06"><code>0474a27c06</code></a>] - <strong>deps</strong>: libuv: revert 3a9a6e3e6b (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62511" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62511/hovercard">#62511</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7547e795ef"><code>7547e795ef</code></a>] - <strong>deps</strong>: update icu to 78.3 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62324" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62324/hovercard">#62324</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5bebd7eaea"><code>5bebd7eaea</code></a>] - <strong>deps</strong>: update libuv to 1.52.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61829" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61829/hovercard">#61829</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/87d7db1918"><code>87d7db1918</code></a>] - <strong>deps</strong>: patch V8 to 14.3.127.18 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61421" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61421/hovercard">#61421</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9d27d9a393"><code>9d27d9a393</code></a>] - <strong>deps</strong>: patch V8 to 14.3.127.17 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61058" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61058/hovercard">#61058</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bfc729cf19"><code>bfc729cf19</code></a>] - <strong>deps</strong>: patch V8 to 14.3.127.16 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/60819" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60819/hovercard">#60819</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8716146d5b"><code>8716146d5b</code></a>] - <strong>deps</strong>: patch V8 to 14.3.127.14 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/60743" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60743/hovercard">#60743</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/da71ab6895"><code>da71ab6895</code></a>] - <strong>deps</strong>: V8: cherry-pick highway@989a498fdf3 (Richard Lau) <a href="https://github.com/nodejs/node/pull/60682" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60682/hovercard">#60682</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/72d719dc00"><code>72d719dc00</code></a>] - <strong>deps</strong>: support madvise(3C) across ALL illumos revisions (Dan McDonald) <a href="https://github.com/nodejs/node/pull/58237" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/58237/hovercard">#58237</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ecca2b0d64"><code>ecca2b0d64</code></a>] - <strong>deps</strong>: define V8_PRESERVE_MOST as no-op on Windows (Stefan Stojanovic) <a href="https://github.com/nodejs/node/pull/56238" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/56238/hovercard">#56238</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/baefd4d5e2"><code>baefd4d5e2</code></a>] - <strong>deps</strong>: patch V8 to 14.2.231.17 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/60647" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60647/hovercard">#60647</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/76d6be5fc5"><code>76d6be5fc5</code></a>] - <strong>deps</strong>: patch V8 to 14.2.231.16 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/60544" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60544/hovercard">#60544</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e0ca993514"><code>e0ca993514</code></a>] - <strong>deps</strong>: patch V8 to 14.2.231.14 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/60413" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60413/hovercard">#60413</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/de8386de4d"><code>de8386de4d</code></a>] - <strong>deps</strong>: V8: cherry-pick f93055fbd5aa (Olivier Flückiger) <a href="https://github.com/nodejs/node/pull/60105" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60105/hovercard">#60105</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/710105bab5"><code>710105bab5</code></a>] - <strong>deps</strong>: support madvise(3C) across ALL illumos revisions (Dan McDonald) <a href="https://github.com/nodejs/node/pull/58237" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/58237/hovercard">#58237</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6e5f3b9fe1"><code>6e5f3b9fe1</code></a>] - <strong>deps</strong>: define V8_PRESERVE_MOST as no-op on Windows (Stefan Stojanovic) <a href="https://github.com/nodejs/node/pull/56238" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/56238/hovercard">#56238</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b2c5235254"><code>b2c5235254</code></a>] - <strong>doc</strong>: fix stray carriage return in packages.md (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62350" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62350/hovercard">#62350</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f38a739623"><code>f38a739623</code></a>] - <strong>doc</strong>: reserve NMV 146 for Electron 42 (Niklas Wenzel) <a href="https://github.com/nodejs/node/pull/62124" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62124/hovercard">#62124</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a57893b799"><code>a57893b799</code></a>] - <strong>doc</strong>: add Temporal section to Table of Contents (Richard Lau) <a href="https://github.com/nodejs/node/pull/61805" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61805/hovercard">#61805</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d4cc54b8c8"><code>d4cc54b8c8</code></a>] - <strong>doc</strong>: fix v24 changelog after security release (Marco Ippolito) <a href="https://github.com/nodejs/node/pull/61371" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61371/hovercard">#61371</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/659fd01b3e"><code>659fd01b3e</code></a>] - <strong>doc</strong>: fix v22 changelog after security release (Marco Ippolito) <a href="https://github.com/nodejs/node/pull/61371" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61371/hovercard">#61371</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6c96a63891"><code>6c96a63891</code></a>] - <strong>doc</strong>: fix v20 changelog after security release (Marco Ippolito) <a href="https://github.com/nodejs/node/pull/61371" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61371/hovercard">#61371</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a18f8c1693"><code>a18f8c1693</code></a>] - <strong>doc</strong>: reserve NMV 145 for Electron 41 (Niklas Wenzel) <a href="https://github.com/nodejs/node/pull/61291" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61291/hovercard">#61291</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/253b16fe14"><code>253b16fe14</code></a>] - <strong>doc</strong>: add note about rust toolchain version requirement (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/60942" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60942/hovercard">#60942</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0177491df2"><code>0177491df2</code></a>] - <strong>doc</strong>: restore REPLACEME on assert change (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/60848" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60848/hovercard">#60848</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dec0213c83"><code>dec0213c83</code></a>] - <strong>doc</strong>: add known issue to v24.11.0 release notes (Richard Lau) <a href="https://github.com/nodejs/node/pull/60467" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60467/hovercard">#60467</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f7ca0ae765"><code>f7ca0ae765</code></a>] - <strong>doc</strong>: remove Corepack documentation page (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/57663" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/57663/hovercard">#57663</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a7d9c49490"><code>a7d9c49490</code></a>] - <strong>doc</strong>: reserve NMV 143 for Electron 40 (Shelley Vohr) <a href="https://github.com/nodejs/node/pull/60386" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60386/hovercard">#60386</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/04a086a1f4"><code>04a086a1f4</code></a>] - <strong>esm</strong>: use wasm version of cjs-module-lexer (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/60663" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60663/hovercard">#60663</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a27052f2e0"><code>a27052f2e0</code></a>] - <em><strong>Revert</strong></em> "<strong>inspector</strong>: fix compressed responses" (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/61502" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61502/hovercard">#61502</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/186c7a9c74"><code>186c7a9c74</code></a>] - <strong>inspector</strong>: fix compressed responses (Ruben Nogueira) <a href="https://github.com/nodejs/node/pull/61226" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61226/hovercard">#61226</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/012bf70908"><code>012bf70908</code></a>] - <strong>process</strong>: optimize asyncHandledRejections by using FixedQueue (Gürgün Dayıoğlu) <a href="https://github.com/nodejs/node/pull/60854" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60854/hovercard">#60854</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1a88acbfa2"><code>1a88acbfa2</code></a>] - <strong>quic</strong>: fixup linting/formatting issues (James M Snell) <a href="https://github.com/nodejs/node/pull/62387" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62387/hovercard">#62387</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/79b960a2bc"><code>79b960a2bc</code></a>] - <strong>quic</strong>: update http3 impl details (James M Snell) <a href="https://github.com/nodejs/node/pull/62387" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62387/hovercard">#62387</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/57186e5827"><code>57186e5827</code></a>] - <strong>quic</strong>: fix a handful of bugs and missing functionality (James M Snell) <a href="https://github.com/nodejs/node/pull/62387" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62387/hovercard">#62387</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/637bda0238"><code>637bda0238</code></a>] - <strong>sqlite</strong>: enable Percentile extension (Jurj Andrei George) <a href="https://github.com/nodejs/node/pull/61295" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61295/hovercard">#61295</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e619adfb86"><code>e619adfb86</code></a>] - <strong>src</strong>: workaround AIX libc++ std::filesystem bug (Richard Lau) <a href="https://github.com/nodejs/node/pull/62788" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62788/hovercard">#62788</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/79262ff860"><code>79262ff860</code></a>] - <strong>src</strong>: do not enable wasm trap handler if there's not enough vmem (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/62132" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62132/hovercard">#62132</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2422ed8b5b"><code>2422ed8b5b</code></a>] - <strong>src</strong>: remove redundant <code>experimental_transform_types</code> from node_options.h (沈鸿飞) <a href="https://github.com/nodejs/node/pull/62058" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62058/hovercard">#62058</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a86db6be70"><code>a86db6be70</code></a>] - <strong>src</strong>: simplify handling of kNoAuthTagLength (Tobias Nießen) <a href="https://github.com/nodejs/node/pull/61192" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61192/hovercard">#61192</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d546e7fd0b"><code>d546e7fd0b</code></a>] - <strong>src</strong>: tag more v8 aligned pointer slots (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/60666" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60666/hovercard">#60666</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b8e264d3c3"><code>b8e264d3c3</code></a>] - <strong>src</strong>: tag v8 aligned pointer slots with embedder data type tags (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/60602" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60602/hovercard">#60602</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cd391b5f11"><code>cd391b5f11</code></a>] - <strong>test</strong>: wpt for Wasm jsapi including new ESM Integration tests (Guy Bedford) <a href="https://github.com/nodejs/node/pull/59034" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/59034/hovercard">#59034</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1baafcc882"><code>1baafcc882</code></a>] - <strong>test</strong>: update WPT resources, interfaces and WebCryptoAPI (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62389" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62389/hovercard">#62389</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6a84d4a17c"><code>6a84d4a17c</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to 832efc09b4caf6b4569fbf9dc01bec3082a (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62486" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62486/hovercard">#62486</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a98d9f6ad7"><code>a98d9f6ad7</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to 9cf7092bdd603554bd8b63c216e8943cf9b (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62383" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62383/hovercard">#62383</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f6d02af01f"><code>f6d02af01f</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to f82ce7af0b79ac154b12e27ed800aeb9741 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62258" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62258/hovercard">#62258</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5b5f069a27"><code>5b5f069a27</code></a>] - <strong>tools</strong>: bump nixpkgs-unstable pin to e38213b91d3786389a446dfce4ff5a8aaf6 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62052" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62052/hovercard">#62052</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/13eb80f3b7"><code>13eb80f3b7</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to d1c15b7d5806069da59e819999d70e1cec0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61931" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61931/hovercard">#61931</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4d1557a744"><code>4d1557a744</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to 2343bbb58f99267223bc2aac4fc9ea301a1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61831" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61831/hovercard">#61831</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ecd979c95a"><code>ecd979c95a</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to ae67888ff7ef9dff69b3cf0cc0fbfbcd3a7 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61733" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61733/hovercard">#61733</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7de56bdee2"><code>7de56bdee2</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to 6308c3b21396534d8aaeac46179c14c439a (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61606" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61606/hovercard">#61606</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e33ce7a6fe"><code>e33ce7a6fe</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to ab9fbbcf4858bd6d40ba2bbec37ceb4ab6e (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61513" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61513/hovercard">#61513</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ba05a66774"><code>ba05a66774</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to be5afa0fcb31f0a96bf9ecba05a516c66fc (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61420" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61420/hovercard">#61420</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bb5d066989"><code>bb5d066989</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to 3146c6aa9995e7351a398e17470e15305e6 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61340" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61340/hovercard">#61340</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d050aa87e8"><code>d050aa87e8</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to 16c7794d0a28b5a37904d55bcca36003b91 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61272" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61272/hovercard">#61272</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2696391b18"><code>2696391b18</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to 3edc4a30ed3903fdf6f90c837f961fa6b49 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61188" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61188/hovercard">#61188</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c5d3f5f9c8"><code>c5d3f5f9c8</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to 7d853e518814cca2a657b72eeba67ae20eb (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61137" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61137/hovercard">#61137</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dcb9573d0f"><code>dcb9573d0f</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to f997fa0f94fb1ce55bccb97f60d41412ae8 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61057" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61057/hovercard">#61057</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bd426739dc"><code>bd426739dc</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to a672be65651c80d3f592a89b3945466584a (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/60980" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60980/hovercard">#60980</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/85852a3221"><code>85852a3221</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to 59b6c96beacc898566c9be1052ae806f383 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/60900" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60900/hovercard">#60900</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1e7eb90b39"><code>1e7eb90b39</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to a8d610af3f1a5fb71e23e08434d8d61a466 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/60818" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60818/hovercard">#60818</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fb6b83c9ef"><code>fb6b83c9ef</code></a>] - <strong>tools</strong>: lint Temporal global (René) <a href="https://github.com/nodejs/node/pull/60793" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60793/hovercard">#60793</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/adb40439ca"><code>adb40439ca</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to 71cf367cc2c168b0c2959835659c38f0a34 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/60742" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60742/hovercard">#60742</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8a76958005"><code>8a76958005</code></a>] - <strong>tools</strong>: update nixpkgs-unstable to ffcdcf99d65c61956d882df249a9be53e59 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/60315" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60315/hovercard">#60315</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[WebAssembly im Check]]></title>
<description><![CDATA[WebAssembly (Wasm) ermöglicht es, Anwendungen direkt im Browser auszuführen. Die Technologie gilt daher als wichtige Ergänzung zu JavaScript und eröffnet neue Möglichkeiten für performante Webanwendungen. Doch wie funktioniert WebAssembly genau und welche Vorteile bietet es? In diesem Artikel erh...]]></description>
<link>https://tsecurity.de/de/3488456/server/webassembly-im-check/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3488456/server/webassembly-im-check/</guid>
<pubDate>Tue, 05 May 2026 08:15:15 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/webassembly-t.jpg" width="1200" height="630" alt=""><br>WebAssembly (Wasm) ermöglicht es, Anwendungen direkt im Browser auszuführen. Die Technologie gilt daher als wichtige Ergänzung zu JavaScript und eröffnet neue Möglichkeiten für performante Webanwendungen. Doch wie funktioniert WebAssembly genau und welche Vorteile bietet es? In diesem Artikel erhalten Sie eine verständliche Einführung in die Grundlagen, die Funktionsweise und typische Einsatzbereiche.]]></content:encoded>
</item>
<item>
<title><![CDATA[Rust 1.91.1]]></title>
<description><![CDATA[Enable file locking support in illumos. This fixes Cargo not locking the build directory on illumos.
Fix wasm_import_module attribute cross-crate. This fixes linker errors on WASM targets.]]></description>
<link>https://tsecurity.de/de/3487729/downloads/rust-1911/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487729/downloads/rust-1911/</guid>
<pubDate>Tue, 05 May 2026 02:03:35 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a></a></p>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/148322" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/148322/hovercard">Enable file locking support in illumos</a>. This fixes Cargo not locking the build directory on illumos.</li>
<li><a href="https://github.com/rust-lang/rust/pull/148363" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/148363/hovercard">Fix <code>wasm_import_module</code> attribute cross-crate</a>. This fixes linker errors on WASM targets.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rust 1.93.0]]></title>
<description><![CDATA[Language

Stabilize several s390x vector-related target features and the is_s390x_feature_detected! macro
Stabilize declaration of C-style variadic functions for the system ABI
Emit error when using some keyword as a cfg predicate
Stabilize asm_cfg
During const-evaluation, support copying pointer...]]></description>
<link>https://tsecurity.de/de/3487722/downloads/rust-1930/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487722/downloads/rust-1930/</guid>
<pubDate>Tue, 05 May 2026 02:03:26 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a></a></p>
<h2>Language</h2>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/145656" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/145656/hovercard">Stabilize several s390x <code>vector</code>-related target features and the <code>is_s390x_feature_detected!</code> macro</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/145954" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/145954/hovercard">Stabilize declaration of C-style variadic functions for the <code>system</code> ABI</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/146978" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/146978/hovercard">Emit error when using some keyword as a <code>cfg</code> predicate</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/147736" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/147736/hovercard">Stabilize <code>asm_cfg</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/148259" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/148259/hovercard">During const-evaluation, support copying pointers byte-by-byte</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/148602" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/148602/hovercard">LUB coercions now correctly handle function item types, and functions with differing safeties</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/148746" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/148746/hovercard">Allow <code>const</code> items that contain mutable references to <code>static</code> (which is <em>very</em> unsafe, but not <em>always</em> UB)</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/148407" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/148407/hovercard">Add warn-by-default <code>const_item_interior_mutations</code> lint to warn against calls which mutate interior mutable <code>const</code> items</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/141470" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/141470/hovercard">Add warn-by-default <code>function_casts_as_integer</code> lint</a></li>
</ul>
<p><a></a></p>
<h2>Compiler</h2>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/145974" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/145974/hovercard">Stabilize <code>-Cjump-tables=bool</code></a>. The flag was previously called <code>-Zno-jump-tables</code>.</li>
</ul>
<p><a></a></p>
<h2>Platform Support</h2>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/148435" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/148435/hovercard">Promote <code>riscv64a23-unknown-linux-gnu</code> to Tier 2 (without host tools)</a></li>
</ul>
<p>Refer to Rust's <a href="https://doc.rust-lang.org/rustc/platform-support.html" rel="nofollow">platform support page</a> for more information on Rust's tiered platform support.</p>
<p><a></a></p>
<h2>Libraries</h2>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/135634" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/135634/hovercard">Stop internally using <code>specialization</code> on the <code>Copy</code> trait as it is unsound in the presence of lifetime dependent <code>Copy</code> implementations. This may result in some performance regressions as some standard library APIs may now call <code>Clone::clone</code> instead of performing bitwise copies</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/144465" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/144465/hovercard">Allow the global allocator to use thread-local storage and <code>std::thread::current()</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/145628" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/145628/hovercard">Make <code>BTree::append</code> not update existing keys when appending an entry which already exists</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/145665" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/145665/hovercard">Don't require <code>T: RefUnwindSafe</code> for <code>vec::IntoIter&lt;T&gt;: UnwindSafe</code></a></li>
</ul>
<p><a></a></p>
<h2>Stabilized APIs</h2>
<ul>
<li><a href="https://doc.rust-lang.org/stable/core/primitive.slice.html#method.assume_init_drop" rel="nofollow"><code>&lt;[MaybeUninit&lt;T&gt;]&gt;::assume_init_drop</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/primitive.slice.html#method.assume_init_ref" rel="nofollow"><code>&lt;[MaybeUninit&lt;T&gt;]&gt;::assume_init_ref</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/core/primitive.slice.html#method.assume_init_mut" rel="nofollow"><code>&lt;[MaybeUninit&lt;T&gt;]&gt;::assume_init_mut</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.slice.html#method.write_copy_of_slice" rel="nofollow"><code>&lt;[MaybeUninit&lt;T&gt;]&gt;::write_copy_of_slice</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.slice.html#method.write_clone_of_slice" rel="nofollow"><code>&lt;[MaybeUninit&lt;T&gt;]&gt;::write_clone_of_slice</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/string/struct.String.html#method.into_raw_parts" rel="nofollow"><code>String::into_raw_parts</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/vec/struct.Vec.html#method.into_raw_parts" rel="nofollow"><code>Vec::into_raw_parts</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.isize.html#method.unchecked_neg" rel="nofollow"><code>&lt;iN&gt;::unchecked_neg</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.isize.html#method.unchecked_shl" rel="nofollow"><code>&lt;iN&gt;::unchecked_shl</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.isize.html#method.unchecked_shr" rel="nofollow"><code>&lt;iN&gt;::unchecked_shr</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.usize.html#method.unchecked_shl" rel="nofollow"><code>&lt;uN&gt;::unchecked_shl</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.usize.html#method.unchecked_shr" rel="nofollow"><code>&lt;uN&gt;::unchecked_shr</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.slice.html#method.as_array" rel="nofollow"><code>&lt;[T]&gt;::as_array</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.slice.html#method.as_mut_array" rel="nofollow"><code>&lt;[T]&gt;::as_mut_array</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.pointer.html#method.as_array" rel="nofollow"><code>&lt;*const [T]&gt;::as_array</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.pointer.html#method.as_mut_array" rel="nofollow"><code>&lt;*mut [T]&gt;::as_mut_array</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/collections/struct.VecDeque.html#method.pop_front_if" rel="nofollow"><code>VecDeque::pop_front_if</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/collections/struct.VecDeque.html#method.pop_back_if" rel="nofollow"><code>VecDeque::pop_back_if</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/time/struct.Duration.html#method.from_nanos_u128" rel="nofollow"><code>Duration::from_nanos_u128</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.char.html#associatedconstant.MAX_LEN_UTF8" rel="nofollow"><code>char::MAX_LEN_UTF8</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/primitive.char.html#associatedconstant.MAX_LEN_UTF16" rel="nofollow"><code>char::MAX_LEN_UTF16</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/fmt/fn.from_fn.html" rel="nofollow"><code>std::fmt::from_fn</code></a></li>
<li><a href="https://doc.rust-lang.org/stable/std/fmt/struct.FromFn.html" rel="nofollow"><code>std::fmt::FromFn</code></a></li>
</ul>
<p><a></a></p>
<h2>Cargo</h2>
<ul>
<li><a href="https://github.com/rust-lang/cargo/pull/16160/" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/cargo/pull/16160/hovercard">Enable CARGO_CFG_DEBUG_ASSERTIONS in build scripts based on profile</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16204/" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/cargo/pull/16204/hovercard">In <code>cargo tree</code>, support long forms for <code>--format</code> variables</a></li>
<li><a href="https://github.com/rust-lang/cargo/pull/16263/" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/cargo/pull/16263/hovercard">Add <code>--workspace</code> to <code>cargo clean</code></a></li>
</ul>
<p><a></a></p>
<h2>Rustdoc</h2>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/146495" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/146495/hovercard">Remove <code>#![doc(document_private_items)]</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/148176" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/148176/hovercard">Include attribute and derive macros in search filters for "macros"</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/148301" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/148301/hovercard">Include extern crates in search filters for <code>import</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/149197" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/149197/hovercard">Validate usage of crate-level doc attributes</a>. This means if any of <code>html_favicon_url</code>, <code>html_logo_url</code>, <code>html_playground_url</code>, <code>issue_tracker_base_url</code>, or <code>html_no_source</code> either has a missing value, an unexpected value, or a value of the wrong type, rustdoc will emit the deny-by-default lint <code>rustdoc::invalid_doc_attributes</code>.</li>
</ul>
<p><a></a></p>
<h2>Compatibility Notes</h2>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/139751" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/139751/hovercard">Introduce <code>pin_v2</code> into the builtin attributes namespace</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/142682" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/142682/hovercard">Update bundled musl to 1.2.5</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/147224" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/147224/hovercard">On Emscripten, the unwinding ABI used when compiling with <code>panic=unwind</code> was changed from the JS exception handling ABI to the wasm exception handling ABI.</a> If linking C/C++ object files with Rust objects, <code>-fwasm-exceptions</code> must be passed to the linker now. On nightly Rust, it is possible to get the old behavior with <code>-Zwasm-emscripten-eh=false -Zbuild-std</code>, but it will be removed in a future release.</li>
<li>The <code>#[test]</code> attribute, used to define tests, was previously ignored in various places where it had no meaning (e.g on trait methods or types). Putting the <code>#[test]</code> attribute in these places is no longer ignored, and will now result in an error; this may also result in errors when generating rustdoc. <a href="https://github.com/rust-lang/rust/pull/147841" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/147841/hovercard">Error when <code>test</code> attribute is applied to structs</a></li>
<li>Cargo now sets the <code>CARGO_CFG_DEBUG_ASSERTIONS</code> environment variable in more situations. This will cause crates depending on <code>static-init</code> versions 1.0.1 to 1.0.3 to fail compilation with "failed to resolve: use of unresolved module or unlinked crate <code>parking_lot</code>". See <a href="https://github.com/rust-lang/rust/issues/150646#issuecomment-3718964342" data-hovercard-type="issue" data-hovercard-url="/rust-lang/rust/issues/150646/hovercard">the linked issue</a> for details.</li>
<li><a href="https://github.com/rust-lang/rust/issues/150465/" data-hovercard-type="issue" data-hovercard-url="/rust-lang/rust/issues/150465/hovercard">User written types in the <code>offset_of!</code> macro are now checked to be well formed.</a></li>
<li><code>cargo publish</code> no longer emits <code>.crate</code> files as a final artifact for user access when the <code>build.build-dir</code> config is unset</li>
<li><a href="https://github.com/rust-lang/rust/pull/148122" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/148122/hovercard">Upgrade the <code>deref_nullptr</code> lint from warn-by-default to deny-by-default</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/143619" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/143619/hovercard">Add future-incompatibility warning for <code>...</code> function parameters without a pattern outside of <code>extern</code> blocks</a></li>
<li><a href="https://github.com/rust-lang/rust/pull/147017" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/147017/hovercard">Introduce future-compatibility warning for <code>repr(C)</code> enums whose discriminant values do not fit into a <code>c_int</code> or <code>c_uint</code></a></li>
<li><a href="https://github.com/rust-lang/rust/pull/147185" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/147185/hovercard">Introduce future-compatibility warning against ignoring <code>repr(C)</code> types as part of <code>repr(transparent)</code></a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rust 1.93.1]]></title>
<description><![CDATA[Don't try to recover keyword as non-keyword identifier, fixing an ICE that especially affected rustfmt.
Fix clippy::panicking_unwrap false-positive on field access with implicit deref.
Revert "Update wasm-related dependencies in CI", fixing file descriptor leaks on the wasm32-wasip2 target.]]></description>
<link>https://tsecurity.de/de/3487717/downloads/rust-1931/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487717/downloads/rust-1931/</guid>
<pubDate>Tue, 05 May 2026 02:03:19 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a></a></p>
<ul>
<li><a href="https://github.com/rust-lang/rust/pull/150590" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/150590/hovercard">Don't try to recover keyword as non-keyword identifier</a>, fixing an ICE that especially <a href="https://github.com/rust-lang/rustfmt/issues/6739" data-hovercard-type="issue" data-hovercard-url="/rust-lang/rustfmt/issues/6739/hovercard">affected rustfmt</a>.</li>
<li><a href="https://github.com/rust-lang/rust-clippy/pull/16196" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust-clippy/pull/16196/hovercard">Fix <code>clippy::panicking_unwrap</code> false-positive on field access with implicit deref</a>.</li>
<li><a href="https://github.com/rust-lang/rust/pull/152259" data-hovercard-type="pull_request" data-hovercard-url="/rust-lang/rust/pull/152259/hovercard">Revert "Update wasm-related dependencies in CI"</a>, fixing file descriptor leaks on the <code>wasm32-wasip2</code> target.</li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026-04-01, Version 25.9.0 (Current), @aduh95]]></title>
<description><![CDATA[Notable Changes
Test runner module mocking improvements
MockModuleOptions.defaultExport and MockModuleOptions.namedExports have been
consolidated into a single option MockModuleOptions.exports to align with user
expectations and other test runners.
A default property on MockModuleOptions.exports ...]]></description>
<link>https://tsecurity.de/de/3487687/downloads/2026-04-01-version-2590-current-aduh95/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487687/downloads/2026-04-01-version-2590-current-aduh95/</guid>
<pubDate>Tue, 05 May 2026 02:02:38 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Notable Changes</h3>
<h4>Test runner module mocking improvements</h4>
<p><code>MockModuleOptions.defaultExport</code> and <code>MockModuleOptions.namedExports</code> have been<br>
consolidated into a single option <code>MockModuleOptions.exports</code> to align with user<br>
expectations and other test runners.</p>
<p>A <code>default</code> property on <code>MockModuleOptions.exports</code>  represents the default<br>
export, and own enumerable properties are treated as named exports.</p>
<p>An automated migration is available to update user code:<br>
<a href="https://github.com/nodejs/userland-migrations/tree/main/recipes/mock-module-exports">https://github.com/nodejs/userland-migrations/tree/main/recipes/mock-module-exports</a></p>
<div class="highlight highlight-source-shell notranslate position-relative overflow-auto" data-snippet-clipboard-copy-content="npx codemod @nodejs/mock-module-exports"><pre>npx codemod @nodejs/mock-module-exports</pre></div>
<p>Contributed by sangwook in <a href="https://github.com/nodejs/node/pull/61727" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61727/hovercard">#61727</a>.</p>
<h4>Other notable changes</h4>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/312476cb84"><code>312476cb84</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>async_hooks</strong>: add using scopes to <code>AsyncLocalStorage</code> (Stephen Belanger) <a href="https://github.com/nodejs/node/pull/61674" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61674/hovercard">#61674</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/62d2cd473b"><code>62d2cd473b</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>cli</strong>: add <code>--max-heap-size</code> option (tannal) <a href="https://github.com/nodejs/node/pull/58708" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/58708/hovercard">#58708</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d0ebf0e44b"><code>d0ebf0e44b</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: add <code>TurboSHAKE</code> and <code>KangarooTwelve</code> Web Cryptography algorithms (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62183" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62183/hovercard">#62183</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f85b9d9fa8"><code>f85b9d9fa8</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>repl</strong>: add customizable error handling (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/62188" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62188/hovercard">#62188</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/67b854d407"><code>67b854d407</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>repl</strong>: remove dependency on <code>node:domain</code> (Matteo Collina) <a href="https://github.com/nodejs/node/pull/61227" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61227/hovercard">#61227</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/966b700623"><code>966b700623</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>sea</strong>: support code cache for ESM entrypoint in SEA (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/62158" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62158/hovercard">#62158</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e1f0d2a014"><code>e1f0d2a014</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>stream</strong>: add stream/iter Implementation (James M Snell) <a href="https://github.com/nodejs/node/pull/62066" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62066/hovercard">#62066</a></li>
</ul>
<h3>Commits</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/312476cb84"><code>312476cb84</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>async_hooks</strong>: add using scopes to AsyncLocalStorage (Stephen Belanger) <a href="https://github.com/nodejs/node/pull/61674" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61674/hovercard">#61674</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bfff8cb2ab"><code>bfff8cb2ab</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>benchmark</strong>: add benchmarks for experimental stream/iter (James M Snell) <a href="https://github.com/nodejs/node/pull/62066" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62066/hovercard">#62066</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c721d68502"><code>c721d68502</code></a>] - <strong>benchmark</strong>: fix destructuring in dgram/single-buffer (Ali Hassan) <a href="https://github.com/nodejs/node/pull/62084" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62084/hovercard">#62084</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e2f03c8e92"><code>e2f03c8e92</code></a>] - <strong>buffer</strong>: improve performance of multiple Buffer operations (Ali Hassan) <a href="https://github.com/nodejs/node/pull/61871" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61871/hovercard">#61871</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2fcd07f1ba"><code>2fcd07f1ba</code></a>] - <strong>build</strong>: support empty libname flags in <code>configure.py</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62477" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62477/hovercard">#62477</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b800c57fce"><code>b800c57fce</code></a>] - <strong>build</strong>: fix timezone-update path references (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/62280" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62280/hovercard">#62280</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7dc5a1e9b4"><code>7dc5a1e9b4</code></a>] - <strong>build</strong>: skip dockit on IBMi (SRAVANI GUNDEPALLI) <a href="https://github.com/nodejs/node/pull/62189" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62189/hovercard">#62189</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f0eea0f905"><code>f0eea0f905</code></a>] - <strong>build</strong>: fix --node-builtin-modules-path (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62115" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62115/hovercard">#62115</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/62d2cd473b"><code>62d2cd473b</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>cli</strong>: add --max-heap-size option (tannal) <a href="https://github.com/nodejs/node/pull/58708" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/58708/hovercard">#58708</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ac4b485698"><code>ac4b485698</code></a>] - <strong>crypto</strong>: update root certificates to NSS 3.121 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62485" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62485/hovercard">#62485</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d0ebf0e44b"><code>d0ebf0e44b</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62183" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62183/hovercard">#62183</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3009980d9d"><code>3009980d9d</code></a>] - <strong>crypto</strong>: add crypto::GetSSLCtx API for addon access to OpenSSL contexts (Tim Perry) <a href="https://github.com/nodejs/node/pull/62254" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62254/hovercard">#62254</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f5725ca81d"><code>f5725ca81d</code></a>] - <strong>crypto</strong>: reject ML-KEM/ML-DSA PKCS#8 import without seed in SubtleCrypto (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62218" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62218/hovercard">#62218</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f69ed4bc3f"><code>f69ed4bc3f</code></a>] - <strong>crypto</strong>: rename CShakeParams and KmacParams length to outputLength (Filip Skokan) <a href="https://github.com/nodejs/node/pull/61875" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61875/hovercard">#61875</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4d96e53570"><code>4d96e53570</code></a>] - <strong>crypto</strong>: refactor WebCrypto AEAD algorithms auth tag handling (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62169" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62169/hovercard">#62169</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/93d77719e8"><code>93d77719e8</code></a>] - <strong>crypto</strong>: read algorithm name property only once in normalizeAlgorithm (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62170" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62170/hovercard">#62170</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3d2e23a981"><code>3d2e23a981</code></a>] - <strong>deps</strong>: update ada to 3.4.4 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62414" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62414/hovercard">#62414</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/176d6d2205"><code>176d6d2205</code></a>] - <strong>deps</strong>: update timezone to 2026a (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62164" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62164/hovercard">#62164</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/95c7fc67ba"><code>95c7fc67ba</code></a>] - <strong>deps</strong>: update googletest to 2461743991f9aa53e9a3625eafcbacd81a3c74cd (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62484" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62484/hovercard">#62484</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e5e9f2044a"><code>e5e9f2044a</code></a>] - <strong>deps</strong>: update simdjson to 4.5.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62382" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62382/hovercard">#62382</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/905b94266a"><code>905b94266a</code></a>] - <strong>deps</strong>: update ngtcp2 to 1.21.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62051" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62051/hovercard">#62051</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/180c150122"><code>180c150122</code></a>] - <strong>deps</strong>: V8: cherry-pick cf1bce40a5ef (Richard Lau) <a href="https://github.com/nodejs/node/pull/62449" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62449/hovercard">#62449</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bc265aa003"><code>bc265aa003</code></a>] - <strong>deps</strong>: upgrade npm to 11.12.1 (npm team) <a href="https://github.com/nodejs/node/pull/62448" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62448/hovercard">#62448</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f1b28612c4"><code>f1b28612c4</code></a>] - <strong>deps</strong>: V8: cherry-pick b25cd62c7ba2 (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/62354" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62354/hovercard">#62354</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/757719d2af"><code>757719d2af</code></a>] - <strong>deps</strong>: disable rust icu compiled_data features (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/62284" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62284/hovercard">#62284</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3bdc955b63"><code>3bdc955b63</code></a>] - <strong>deps</strong>: update sqlite to 3.51.3 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62256" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62256/hovercard">#62256</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a9703d194a"><code>a9703d194a</code></a>] - <strong>deps</strong>: update googletest to 73a63ea05dc8ca29ec1d2c1d66481dd0de1950f1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61927" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61927/hovercard">#61927</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/85138935cb"><code>85138935cb</code></a>] - <strong>deps</strong>: update merve to 1.2.2 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62213" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62213/hovercard">#62213</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/231521e75e"><code>231521e75e</code></a>] - <strong>diagnostics_channel</strong>: add diagnostics channels for web locks (Ilyas Shabi) <a href="https://github.com/nodejs/node/pull/62123" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62123/hovercard">#62123</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0093863664"><code>0093863664</code></a>] - <strong>doc</strong>: deprecate <code>module.register()</code> (DEP0205) (Geoffrey Booth) <a href="https://github.com/nodejs/node/pull/62395" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62395/hovercard">#62395</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0b96ece6be"><code>0b96ece6be</code></a>] - <strong>doc</strong>: clarify that features cannot be both experimental and deprecated (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62456" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62456/hovercard">#62456</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8d3ea975f5"><code>8d3ea975f5</code></a>] - <strong>doc</strong>: fix 'transfered' typo in quic.md (lilianakatrina684-a11y) <a href="https://github.com/nodejs/node/pull/62492" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62492/hovercard">#62492</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/08ff16e0ba"><code>08ff16e0ba</code></a>] - <strong>doc</strong>: move sqlite type conversion section to correct level (René) <a href="https://github.com/nodejs/node/pull/62482" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62482/hovercard">#62482</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/61cc747dd8"><code>61cc747dd8</code></a>] - <strong>doc</strong>: add Rafael to last security release steward (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/62423" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62423/hovercard">#62423</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/64cfa5a6fa"><code>64cfa5a6fa</code></a>] - <strong>doc</strong>: use npm-published version of doc-kit (Aviv Keller) <a href="https://github.com/nodejs/node/pull/62139" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62139/hovercard">#62139</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1020321fb0"><code>1020321fb0</code></a>] - <strong>doc</strong>: fix overstated Date header requirement in response.sendDate (Kit Dallege) <a href="https://github.com/nodejs/node/pull/62206" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62206/hovercard">#62206</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9caa7855b2"><code>9caa7855b2</code></a>] - <strong>doc</strong>: fix guaranteed typo (lilianakatrina684-a11y) <a href="https://github.com/nodejs/node/pull/62374" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62374/hovercard">#62374</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e254f65306"><code>e254f65306</code></a>] - <strong>doc</strong>: enhance clarification about the main field (Mowafak Almahaini) <a href="https://github.com/nodejs/node/pull/62302" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62302/hovercard">#62302</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9e724b53f8"><code>9e724b53f8</code></a>] - <strong>doc</strong>: remove spawn with shell example from bat/cmd section (Kit Dallege) <a href="https://github.com/nodejs/node/pull/62243" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62243/hovercard">#62243</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7f37c17516"><code>7f37c17516</code></a>] - <strong>doc</strong>: minor typo fix (Jeff Matson) <a href="https://github.com/nodejs/node/pull/62358" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62358/hovercard">#62358</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/eb0ca98f01"><code>eb0ca98f01</code></a>] - <strong>doc</strong>: add path to vulnerabilities.json mention (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/62355" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62355/hovercard">#62355</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/198b6e0932"><code>198b6e0932</code></a>] - <strong>doc</strong>: deprecate CryptoKey use in node:crypto (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62321" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62321/hovercard">#62321</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/17e5aee6c5"><code>17e5aee6c5</code></a>] - <strong>doc</strong>: fix small environment_variables typo (chris) <a href="https://github.com/nodejs/node/pull/62279" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62279/hovercard">#62279</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/193d629895"><code>193d629895</code></a>] - <strong>doc</strong>: test and test-only targets do not run linter (Xavier Stouder) <a href="https://github.com/nodejs/node/pull/62120" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62120/hovercard">#62120</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4a1f20ec4a"><code>4a1f20ec4a</code></a>] - <strong>doc</strong>: clarify fs.ReadStream and fs.WriteStream are not constructable (Kit Dallege) <a href="https://github.com/nodejs/node/pull/62208" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62208/hovercard">#62208</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f976c9214d"><code>f976c9214d</code></a>] - <strong>doc</strong>: clarify that any truthy value of <code>shell</code> is part of DEP0190 (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62249" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62249/hovercard">#62249</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4d83972681"><code>4d83972681</code></a>] - <strong>doc</strong>: remove outdated Chrome 66 and ndb references from debugger (Kit Dallege) <a href="https://github.com/nodejs/node/pull/62202" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62202/hovercard">#62202</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/71f2eada5b"><code>71f2eada5b</code></a>] - <strong>doc</strong>: add throwIfNoEntry version history to fs.stat (kovan) <a href="https://github.com/nodejs/node/pull/62204" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62204/hovercard">#62204</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/670c80893b"><code>670c80893b</code></a>] - <strong>doc</strong>: add note (and caveat) for <code>mock.module</code> about customization hooks (Jacob Smith) <a href="https://github.com/nodejs/node/pull/62075" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62075/hovercard">#62075</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2ff5cb13f5"><code>2ff5cb13f5</code></a>] - <strong>doc,test</strong>: clarify --eval syntax for leading '-' scripts (kovan) <a href="https://github.com/nodejs/node/pull/62244" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62244/hovercard">#62244</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6c6c9004c4"><code>6c6c9004c4</code></a>] - <strong>esm</strong>: fix typo in worker loader hook comment (jakecastelli) <a href="https://github.com/nodejs/node/pull/62475" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62475/hovercard">#62475</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1cdd23c9f3"><code>1cdd23c9f3</code></a>] - <strong>esm</strong>: fix source phase identity bug in loadCache eviction (Guy Bedford) <a href="https://github.com/nodejs/node/pull/62415" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62415/hovercard">#62415</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4f4ff15794"><code>4f4ff15794</code></a>] - <strong>esm</strong>: fix path normalization in <code>finalizeResolution</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62080" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62080/hovercard">#62080</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/088167d102"><code>088167d102</code></a>] - <strong>events</strong>: avoid cloning listeners array on every emit (Gürgün Dayıoğlu) <a href="https://github.com/nodejs/node/pull/62261" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62261/hovercard">#62261</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0250b436ee"><code>0250b436ee</code></a>] - <strong>fs</strong>: fix cpSync to handle non-ASCII characters (Stefan Stojanovic) <a href="https://github.com/nodejs/node/pull/61950" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61950/hovercard">#61950</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b67a8fb171"><code>b67a8fb171</code></a>] - <strong>inspector</strong>: add Target.getTargets and extract TargetManager (Kohei) <a href="https://github.com/nodejs/node/pull/62487" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62487/hovercard">#62487</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ffcc5a5722"><code>ffcc5a5722</code></a>] - <strong>lib</strong>: make SubtleCrypto.supports enumerable (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62307" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62307/hovercard">#62307</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/92ef2ad8fa"><code>92ef2ad8fa</code></a>] - <strong>lib</strong>: prefer primordials in SubtleCrypto (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62226" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62226/hovercard">#62226</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/40a43ac4d0"><code>40a43ac4d0</code></a>] - <strong>module</strong>: fix coverage of mocked CJS modules imported from ESM (Marco) <a href="https://github.com/nodejs/node/pull/62133" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62133/hovercard">#62133</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3ef0a5b90e"><code>3ef0a5b90e</code></a>] - <strong>quic</strong>: remove CryptoKey support from session keys option (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62335" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62335/hovercard">#62335</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3c8dd8eb8e"><code>3c8dd8eb8e</code></a>] - <strong>repl</strong>: use vm DONT_CONTEXTIFY context (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/62371" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62371/hovercard">#62371</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f85b9d9fa8"><code>f85b9d9fa8</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>repl</strong>: add customizable error handling (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/62188" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62188/hovercard">#62188</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e4c164e045"><code>e4c164e045</code></a>] - <strong>repl</strong>: handle exceptions from async context after close (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/62165" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62165/hovercard">#62165</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/67b854d407"><code>67b854d407</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>repl</strong>: remove dependency on domain module (Matteo Collina) <a href="https://github.com/nodejs/node/pull/61227" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61227/hovercard">#61227</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/966b700623"><code>966b700623</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>sea</strong>: support code cache for ESM entrypoint in SEA (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/62158" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62158/hovercard">#62158</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fe82baf970"><code>fe82baf970</code></a>] - <strong>src</strong>: improve EC JWK import performance (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62396" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62396/hovercard">#62396</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d490b171e0"><code>d490b171e0</code></a>] - <strong>src</strong>: handle null backing store in ArrayBufferViewContents::Read (Mert Can Altin) <a href="https://github.com/nodejs/node/pull/62343" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62343/hovercard">#62343</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0e4af848bc"><code>0e4af848bc</code></a>] - <strong>src</strong>: convert context_frame field in AsyncWrap to internal field (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/62103" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62103/hovercard">#62103</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/02980b8c8f"><code>02980b8c8f</code></a>] - <strong>src</strong>: enable compilation/linking with OpenSSL 4.0 (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62410" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62410/hovercard">#62410</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/064f7c2fa6"><code>064f7c2fa6</code></a>] - <strong>src</strong>: use stack allocation in indexOf latin1 path (Mert Can Altin) <a href="https://github.com/nodejs/node/pull/62268" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62268/hovercard">#62268</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ede52bc2dc"><code>ede52bc2dc</code></a>] - <strong>src,sqlite</strong>: fix filterFunc dangling reference (Edy Silva) <a href="https://github.com/nodejs/node/pull/62281" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62281/hovercard">#62281</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e1f0d2a014"><code>e1f0d2a014</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>stream</strong>: add stream/iter Implementation (James M Snell) <a href="https://github.com/nodejs/node/pull/62066" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62066/hovercard">#62066</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/03839fb087"><code>03839fb087</code></a>] - <strong>stream</strong>: preserve error over AbortError in pipeline (Marco) <a href="https://github.com/nodejs/node/pull/62113" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62113/hovercard">#62113</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0000d2f011"><code>0000d2f011</code></a>] - <strong>stream</strong>: replace bind with arrow function for onwrite callback (Ali Hassan) <a href="https://github.com/nodejs/node/pull/62087" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62087/hovercard">#62087</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3796a73719"><code>3796a73719</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to 2cb332d710 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62483" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62483/hovercard">#62483</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ad8309415b"><code>ad8309415b</code></a>] - <strong>test</strong>: update WPT for url to fc3e651593 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62379" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62379/hovercard">#62379</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bed89b037e"><code>bed89b037e</code></a>] - <strong>test</strong>: wait for reattach before initial break on restart (Yuya Inoue) <a href="https://github.com/nodejs/node/pull/62471" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62471/hovercard">#62471</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c9ffffcc55"><code>c9ffffcc55</code></a>] - <strong>test</strong>: disable flaky WPT Blob test on AIX (James M Snell) <a href="https://github.com/nodejs/node/pull/62470" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62470/hovercard">#62470</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fd41ef31f6"><code>fd41ef31f6</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>test</strong>: add tests for experimental stream/iter implementation (James M Snell) <a href="https://github.com/nodejs/node/pull/62066" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62066/hovercard">#62066</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1b9d8d3eec"><code>1b9d8d3eec</code></a>] - <strong>test</strong>: avoid flaky run wait in debugger restart test (Yuya Inoue) <a href="https://github.com/nodejs/node/pull/62112" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62112/hovercard">#62112</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cb08a29d51"><code>cb08a29d51</code></a>] - <strong>test</strong>: skip test-cluster-dgram-reuse on AIX 7.3 (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/62238" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62238/hovercard">#62238</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/abea0af8a9"><code>abea0af8a9</code></a>] - <strong>test</strong>: add WebCrypto Promise.prototype.then pollution regression tests (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62226" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62226/hovercard">#62226</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/47a2132269"><code>47a2132269</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to 6a1c545d77 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62187" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62187/hovercard">#62187</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2c63d3006c"><code>2c63d3006c</code></a>] - <strong>test_runner</strong>: add exports option for module mocks (sangwook) <a href="https://github.com/nodejs/node/pull/61727" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61727/hovercard">#61727</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44ac0e1302"><code>44ac0e1302</code></a>] - <strong>test_runner</strong>: make it compatible with fake timers (Matteo Collina) <a href="https://github.com/nodejs/node/pull/59272" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/59272/hovercard">#59272</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1865691275"><code>1865691275</code></a>] - <strong>test_runner</strong>: set non-zero exit code when suite errors occur (Edy Silva) <a href="https://github.com/nodejs/node/pull/62282" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62282/hovercard">#62282</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0252b2bab8"><code>0252b2bab8</code></a>] - <strong>tools</strong>: bump picomatch from 4.0.3 to 4.0.4 in /tools/eslint (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62439" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62439/hovercard">#62439</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3368155267"><code>3368155267</code></a>] - <strong>tools</strong>: bump yaml from 2.8.2 to 2.8.3 in /tools/doc (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62437" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62437/hovercard">#62437</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5e47c359f5"><code>5e47c359f5</code></a>] - <strong>tools</strong>: adopt the <code>--check-for-duplicates</code> NCU flag (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62478" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62478/hovercard">#62478</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4a604e82d0"><code>4a604e82d0</code></a>] - <strong>tools</strong>: bump picomatch in /tools/doc (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62438" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62438/hovercard">#62438</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d1a98b4ddb"><code>d1a98b4ddb</code></a>] - <strong>tools</strong>: bump flatted from 3.4.1 to 3.4.2 in /tools/eslint (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62375" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62375/hovercard">#62375</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c32daa1ab4"><code>c32daa1ab4</code></a>] - <strong>tools</strong>: bump eslint deps (Huáng Jùnliàng) <a href="https://github.com/nodejs/node/pull/62356" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62356/hovercard">#62356</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7a2fcc6d41"><code>7a2fcc6d41</code></a>] - <strong>tools</strong>: do not swallow error in <code>lint-nix</code> workflow (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62292" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62292/hovercard">#62292</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c41a2871b5"><code>c41a2871b5</code></a>] - <strong>tools</strong>: add eslint-plugin-regexp (Huáng Jùnliàng) <a href="https://github.com/nodejs/node/pull/62093" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62093/hovercard">#62093</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/56dfeb06df"><code>56dfeb06df</code></a>] - <strong>tools</strong>: fix timeout errors in <code>lint-nix</code> job (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62265" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62265/hovercard">#62265</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/22fc8078e8"><code>22fc8078e8</code></a>] - <strong>tools</strong>: bump flatted from 3.3.3 to 3.4.1 in /tools/eslint (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62255/hovercard">#62255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/409b0663bd"><code>409b0663bd</code></a>] - <strong>tools</strong>: bump undici from 6.23.0 to 6.24.1 in /tools/doc (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62250" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62250/hovercard">#62250</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/67c69750f4"><code>67c69750f4</code></a>] - <strong>tools</strong>: validate all commits that are pushed to <code>main</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62246" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62246/hovercard">#62246</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d9db8cd21"><code>7d9db8cd21</code></a>] - <strong>tools</strong>: keep GN files when updating Merve (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62167" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62167/hovercard">#62167</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6c8fa42ba2"><code>6c8fa42ba2</code></a>] - <strong>typings</strong>: rationalise TypedArray types (René) <a href="https://github.com/nodejs/node/pull/62174" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62174/hovercard">#62174</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/531c64d04e"><code>531c64d04e</code></a>] - <strong>url</strong>: enable simdutf for ada (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/61477" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61477/hovercard">#61477</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2000caccde"><code>2000caccde</code></a>] - <strong>util</strong>: allow color aliases in styleText (sangwook) <a href="https://github.com/nodejs/node/pull/62180" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62180/hovercard">#62180</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0aed332ab4"><code>0aed332ab4</code></a>] - <strong>wasm</strong>: support js string constant esm import (Guy Bedford) <a href="https://github.com/nodejs/node/pull/62198" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62198/hovercard">#62198</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d3fd4a978b"><code>d3fd4a978b</code></a>] - <strong>worker</strong>: heap profile optimizations (Ilyas Shabi) <a href="https://github.com/nodejs/node/pull/62201" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62201/hovercard">#62201</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e992a34a18"><code>e992a34a18</code></a>] - <strong>zlib</strong>: fix use-after-free when reset() is called during write (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62325" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62325/hovercard">#62325</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[2026-04-15, Version 24.15.0 'Krypton' (LTS), @aduh95]]></title>
<description><![CDATA[Notable Changes

[3d87ecacbc] - (SEMVER-MINOR) cli: add --max-heap-size option (tannal) #58708
[83c38672f7] - cli: add --require-module/--no-require-module (Joyee Cheung) #60959
[54ef940e01] - (SEMVER-MINOR) crypto: add raw key formats support to the KeyObject APIs (Filip Skokan) #62240
[f4a3edc4...]]></description>
<link>https://tsecurity.de/de/3487681/downloads/2026-04-15-version-24150-krypton-lts-aduh95/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3487681/downloads/2026-04-15-version-24150-krypton-lts-aduh95/</guid>
<pubDate>Tue, 05 May 2026 02:02:29 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Notable Changes</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/3d87ecacbc"><code>3d87ecacbc</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>cli</strong>: add --max-heap-size option (tannal) <a href="https://github.com/nodejs/node/pull/58708" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/58708/hovercard">#58708</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/83c38672f7"><code>83c38672f7</code></a>] - <strong>cli</strong>: add --require-module/--no-require-module (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/60959" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60959/hovercard">#60959</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/54ef940e01"><code>54ef940e01</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: add raw key formats support to the KeyObject APIs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62240" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62240/hovercard">#62240</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f4a3edc47a"><code>f4a3edc47a</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>fs</strong>: add <code>throwIfNoEntry</code> option for fs.stat and fs.promises.stat (Juan José) <a href="https://github.com/nodejs/node/pull/61178" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61178/hovercard">#61178</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5cdcba17cc"><code>5cdcba17cc</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>http2</strong>: add http1Options for HTTP/1 fallback configuration (Amol Yadav) <a href="https://github.com/nodejs/node/pull/61713" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61713/hovercard">#61713</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8b6be3fe14"><code>8b6be3fe14</code></a>] - <strong>module</strong>: mark require(esm) as stable (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/60959" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60959/hovercard">#60959</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/68fbc0c6cc"><code>68fbc0c6cc</code></a>] - <strong>module</strong>: mark module compile cache as stable (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/60971" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60971/hovercard">#60971</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c851e76f8c"><code>c851e76f8c</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>net</strong>: add <code>setTOS</code> and <code>getTOS</code> to <code>Socket</code> (Amol Yadav) <a href="https://github.com/nodejs/node/pull/61503" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61503/hovercard">#61503</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6ac4304c87"><code>6ac4304c87</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>sqlite</strong>: add limits property to DatabaseSync (Mert Can Altin) <a href="https://github.com/nodejs/node/pull/61298" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61298/hovercard">#61298</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/aaf9af1672"><code>aaf9af1672</code></a>] - <strong>sqlite</strong>: mark as release candidate (Matteo Collina) <a href="https://github.com/nodejs/node/pull/61262" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61262/hovercard">#61262</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/eb77a7a297"><code>eb77a7a297</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>src</strong>: add C++ support for diagnostics channels (RafaelGSS) <a href="https://github.com/nodejs/node/pull/61869" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61869/hovercard">#61869</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6834ca13bb"><code>6834ca13bb</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>stream</strong>: rename <code>Duplex.toWeb()</code> type option to <code>readableType</code> (René) <a href="https://github.com/nodejs/node/pull/61632" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61632/hovercard">#61632</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f5f21d36a6"><code>f5f21d36a6</code></a>] - <strong>test_runner</strong>: add exports option for module mocks (sangwook) <a href="https://github.com/nodejs/node/pull/61727" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61727/hovercard">#61727</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1f2025fd1e"><code>1f2025fd1e</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>test_runner</strong>: expose worker ID for concurrent test execution (Ali Hassan) <a href="https://github.com/nodejs/node/pull/61394" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61394/hovercard">#61394</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1ca20fc33d"><code>1ca20fc33d</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>test_runner</strong>: show interrupted test on SIGINT (Matteo Collina) <a href="https://github.com/nodejs/node/pull/61676" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61676/hovercard">#61676</a></li>
</ul>
<h3>Commits</h3>
<ul>
<li>[<a href="https://github.com/nodejs/node/commit/148373cea1"><code>148373cea1</code></a>] - <strong>assert,util</strong>: improve comparison performance (Ruben Bridgewater) <a href="https://github.com/nodejs/node/pull/61176" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61176/hovercard">#61176</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e5558b0859"><code>e5558b0859</code></a>] - <strong>assert,util</strong>: fix deep comparing invalid dates skipping properties (Ruben Bridgewater) <a href="https://github.com/nodejs/node/pull/61076" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61076/hovercard">#61076</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/83cffd92b5"><code>83cffd92b5</code></a>] - <strong>async_hooks</strong>: enabledHooksExist shall return if hooks are enabled (Gerhard Stöbich) <a href="https://github.com/nodejs/node/pull/61054" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61054/hovercard">#61054</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2c9436b43d"><code>2c9436b43d</code></a>] - <strong>benchmark</strong>: fix destructuring in dgram/single-buffer (Ali Hassan) <a href="https://github.com/nodejs/node/pull/62084" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62084/hovercard">#62084</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/837acd7382"><code>837acd7382</code></a>] - <strong>benchmark</strong>: add startup benchmark for ESM entrypoint (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/61769" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61769/hovercard">#61769</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a6ced7d272"><code>a6ced7d272</code></a>] - <strong>buffer</strong>: improve performance of multiple Buffer operations (Ali Hassan) <a href="https://github.com/nodejs/node/pull/61871" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61871/hovercard">#61871</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a82003bf8b"><code>a82003bf8b</code></a>] - <strong>buffer</strong>: optimize buffer.concat performance (Mert Can Altin) <a href="https://github.com/nodejs/node/pull/61721" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61721/hovercard">#61721</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/83dfd0be1d"><code>83dfd0be1d</code></a>] - <strong>buffer</strong>: disallow ArrayBuffer transfer on pooled buffer (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/61372" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61372/hovercard">#61372</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ed2d0cb1bf"><code>ed2d0cb1bf</code></a>] - <strong>build</strong>: support empty libname flags in <code>configure.py</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62477" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62477/hovercard">#62477</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/09f7920267"><code>09f7920267</code></a>] - <strong>build</strong>: fix timezone-update path references (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/62280" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62280/hovercard">#62280</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/af46b15b91"><code>af46b15b91</code></a>] - <strong>build</strong>: use path-ignore in GHA coverage-windows.yml (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/61811" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61811/hovercard">#61811</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2cf77eadd1"><code>2cf77eadd1</code></a>] - <strong>build</strong>: generate_config_gypi.py generates valid JSON (Shelley Vohr) <a href="https://github.com/nodejs/node/pull/61791" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61791/hovercard">#61791</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e0220f0c35"><code>e0220f0c35</code></a>] - <strong>build</strong>: build with v8 gdbjit support on supported platform (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/61010" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61010/hovercard">#61010</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5505511dcb"><code>5505511dcb</code></a>] - <strong>build</strong>: enable -DV8_ENABLE_CHECKS flag (Ryuhei Shima) <a href="https://github.com/nodejs/node/pull/61327" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61327/hovercard">#61327</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5f8ecf3940"><code>5f8ecf3940</code></a>] - <strong>build</strong>: add --debug-symbols to build with -g without enabling DCHECKs (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/61100" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61100/hovercard">#61100</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ab18c0867b"><code>ab18c0867b</code></a>] - <strong>build</strong>: fix --node-builtin-modules-path (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62115" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62115/hovercard">#62115</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bfa60d5782"><code>bfa60d5782</code></a>] - <strong>build</strong>: fix GN for new merve dep (Shelley Vohr) <a href="https://github.com/nodejs/node/pull/61984" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61984/hovercard">#61984</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0d1975fe3a"><code>0d1975fe3a</code></a>] - <strong>build,win</strong>: add WinGet Visual Studio 2022 Build Tools Edition config (Mike McCready) <a href="https://github.com/nodejs/node/pull/61652" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61652/hovercard">#61652</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/10b2bb5fa6"><code>10b2bb5fa6</code></a>] - <strong>child_process</strong>: add tracing channel for spawn (Marco) <a href="https://github.com/nodejs/node/pull/61836" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61836/hovercard">#61836</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3d87ecacbc"><code>3d87ecacbc</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>cli</strong>: add --max-heap-size option (tannal) <a href="https://github.com/nodejs/node/pull/58708" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/58708/hovercard">#58708</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/83c38672f7"><code>83c38672f7</code></a>] - <strong>cli</strong>: add --require-module/--no-require-module (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/60959" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60959/hovercard">#60959</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9d37233824"><code>9d37233824</code></a>] - <strong>crypto</strong>: update root certificates to NSS 3.121 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62485" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62485/hovercard">#62485</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b0cbfe38a4"><code>b0cbfe38a4</code></a>] - <strong>crypto</strong>: add crypto::GetSSLCtx API for addon access to OpenSSL contexts (Tim Perry) <a href="https://github.com/nodejs/node/pull/62254" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62254/hovercard">#62254</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dc034a4ac9"><code>dc034a4ac9</code></a>] - <strong>crypto</strong>: reject ML-KEM/ML-DSA PKCS#8 import without seed in SubtleCrypto (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62218" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62218/hovercard">#62218</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8aa6e706df"><code>8aa6e706df</code></a>] - <strong>crypto</strong>: refactor WebCrypto AEAD algorithms auth tag handling (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62169" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62169/hovercard">#62169</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/20cb932bcf"><code>20cb932bcf</code></a>] - <strong>crypto</strong>: read algorithm name property only once in normalizeAlgorithm (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62170" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62170/hovercard">#62170</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e2934162b4"><code>e2934162b4</code></a>] - <strong>crypto</strong>: add missing AES dictionaries (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62099" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62099/hovercard">#62099</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8b8db52f65"><code>8b8db52f65</code></a>] - <strong>crypto</strong>: fix importKey required argument count check (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62099" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62099/hovercard">#62099</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bd5458db29"><code>bd5458db29</code></a>] - <strong>crypto</strong>: fix missing nullptr check on RSA_new() (ndossche) <a href="https://github.com/nodejs/node/pull/61888" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61888/hovercard">#61888</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7302c7ed22"><code>7302c7ed22</code></a>] - <strong>crypto</strong>: fix handling of null BUF_MEM* in ToV8Value() (Nora Dossche) <a href="https://github.com/nodejs/node/pull/61885" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61885/hovercard">#61885</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8d0c22ea20"><code>8d0c22ea20</code></a>] - <strong>crypto</strong>: fix potential null pointer dereference when BIO_meth_new() fails (Nora Dossche) <a href="https://github.com/nodejs/node/pull/61788" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61788/hovercard">#61788</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/72aad8b40f"><code>72aad8b40f</code></a>] - <strong>crypto</strong>: always return certificate serial numbers as uppercase (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/61752" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61752/hovercard">#61752</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2395fc0f4d"><code>2395fc0f4d</code></a>] - <strong>crypto</strong>: rename CShakeParams and KmacParams length to outputLength (Filip Skokan) <a href="https://github.com/nodejs/node/pull/61875" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61875/hovercard">#61875</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/541be3aaf2"><code>541be3aaf2</code></a>] - <strong>crypto</strong>: recognize raw formats in keygen (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62480" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62480/hovercard">#62480</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/54ef940e01"><code>54ef940e01</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>crypto</strong>: add raw key formats support to the KeyObject APIs (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62240" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62240/hovercard">#62240</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bef1949823"><code>bef1949823</code></a>] - <strong>deps</strong>: V8: cherry-pick 33e7739c134d (Thibaud Michaud) <a href="https://github.com/nodejs/node/pull/62567" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62567/hovercard">#62567</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2e1a565a55"><code>2e1a565a55</code></a>] - <strong>deps</strong>: update ada to 3.4.4 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62414" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62414/hovercard">#62414</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d0418bad10"><code>d0418bad10</code></a>] - <strong>deps</strong>: update timezone to 2026a (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62164" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62164/hovercard">#62164</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/53aad66415"><code>53aad66415</code></a>] - <strong>deps</strong>: update googletest to 2461743991f9aa53e9a3625eafcbacd81a3c74cd (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62484" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62484/hovercard">#62484</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/90fab71a84"><code>90fab71a84</code></a>] - <strong>deps</strong>: update simdjson to 4.5.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62382" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62382/hovercard">#62382</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a416ddf6d9"><code>a416ddf6d9</code></a>] - <strong>deps</strong>: V8: cherry-pick cf1bce40a5ef (Richard Lau) <a href="https://github.com/nodejs/node/pull/62449" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62449/hovercard">#62449</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4d9123e57d"><code>4d9123e57d</code></a>] - <strong>deps</strong>: upgrade npm to 11.12.1 (npm team) <a href="https://github.com/nodejs/node/pull/62448" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62448/hovercard">#62448</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/952d715028"><code>952d715028</code></a>] - <strong>deps</strong>: update sqlite to 3.51.3 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62256" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62256/hovercard">#62256</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f3fd7ed426"><code>f3fd7ed426</code></a>] - <strong>deps</strong>: update googletest to 73a63ea05dc8ca29ec1d2c1d66481dd0de1950f1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61927" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61927/hovercard">#61927</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/71a2f82d7c"><code>71a2f82d7c</code></a>] - <strong>deps</strong>: upgrade npm to 11.11.1 (npm team) <a href="https://github.com/nodejs/node/pull/62216" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62216/hovercard">#62216</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/84f60c26f7"><code>84f60c26f7</code></a>] - <strong>deps</strong>: update amaro to 1.1.8 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62151" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62151/hovercard">#62151</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/43159d0e5f"><code>43159d0e5f</code></a>] - <strong>deps</strong>: update sqlite to 3.52.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62150" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62150/hovercard">#62150</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b887657b38"><code>b887657b38</code></a>] - <strong>deps</strong>: V8: cherry-pick aa0b288f87cc (Richard Lau) <a href="https://github.com/nodejs/node/pull/62136" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62136/hovercard">#62136</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7ab885b323"><code>7ab885b323</code></a>] - <strong>deps</strong>: update ada to 3.4.3 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62049" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62049/hovercard">#62049</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/671ddec2b9"><code>671ddec2b9</code></a>] - <strong>deps</strong>: update minimatch to 10.2.4 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62016" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62016/hovercard">#62016</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/290fe37d4d"><code>290fe37d4d</code></a>] - <strong>deps</strong>: update simdjson to 4.3.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61930" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61930/hovercard">#61930</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a13bee76b5"><code>a13bee76b5</code></a>] - <strong>deps</strong>: update acorn-walk to 8.3.5 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61928" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61928/hovercard">#61928</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f0e40b35b9"><code>f0e40b35b9</code></a>] - <strong>deps</strong>: update acorn to 8.16.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61925" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61925/hovercard">#61925</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/463dfa023a"><code>463dfa023a</code></a>] - <strong>deps</strong>: update minimatch to 10.2.2 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61830" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61830/hovercard">#61830</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4b2e4bb108"><code>4b2e4bb108</code></a>] - <strong>deps</strong>: update nbytes to 0.1.3 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61879" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61879/hovercard">#61879</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5626cb83d0"><code>5626cb83d0</code></a>] - <strong>deps</strong>: remove stale OpenSSL arch configs (René) <a href="https://github.com/nodejs/node/pull/61834" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61834/hovercard">#61834</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/52668874fd"><code>52668874fd</code></a>] - <strong>deps</strong>: update llhttp to 9.3.1 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61827" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61827/hovercard">#61827</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b3387b07b1"><code>b3387b07b1</code></a>] - <strong>deps</strong>: update googletest to 5a9c3f9e8d9b90bbbe8feb32902146cb8f7c1757 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61731" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61731/hovercard">#61731</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/196268cb4c"><code>196268cb4c</code></a>] - <strong>deps</strong>: V8: cherry-pick c5ff7c4d6cde (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/61372" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61372/hovercard">#61372</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/36869b52de"><code>36869b52de</code></a>] - <strong>deps</strong>: update merve to 1.2.2 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62213" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62213/hovercard">#62213</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3cbac055de"><code>3cbac055de</code></a>] - <strong>deps</strong>: update merve to 1.2.0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62149" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62149/hovercard">#62149</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7757cc3495"><code>7757cc3495</code></a>] - <strong>deps</strong>: V8: backport 6a0a25abaed3 (Vivian Wang) <a href="https://github.com/nodejs/node/pull/61670" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61670/hovercard">#61670</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/359797c2fb"><code>359797c2fb</code></a>] - <strong>deps,src</strong>: prepare for cpplint update (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/60901" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60901/hovercard">#60901</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ace802e59b"><code>ace802e59b</code></a>] - <strong>diagnostics_channel</strong>: add diagnostics channels for web locks (Ilyas Shabi) <a href="https://github.com/nodejs/node/pull/62123" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62123/hovercard">#62123</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a072411b03"><code>a072411b03</code></a>] - <strong>doc</strong>: remove spawn with shell example from bat/cmd section (Kit Dallege) <a href="https://github.com/nodejs/node/pull/62243" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62243/hovercard">#62243</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0b152449af"><code>0b152449af</code></a>] - <strong>doc</strong>: fix typo in --disable-wasm-trap-handler description (Dmytro Semchuk) <a href="https://github.com/nodejs/node/pull/61820" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61820/hovercard">#61820</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/73ea387ad7"><code>73ea387ad7</code></a>] - <strong>doc</strong>: remove obsolete Boxstarter automated install (Mike McCready) <a href="https://github.com/nodejs/node/pull/61785" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61785/hovercard">#61785</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7f234add8e"><code>7f234add8e</code></a>] - <strong>doc</strong>: deprecate <code>module.register()</code> (DEP0205) (Geoffrey Booth) <a href="https://github.com/nodejs/node/pull/62395" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62395/hovercard">#62395</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/12fc3c6a30"><code>12fc3c6a30</code></a>] - <strong>doc</strong>: clarify that features cannot be both experimental and deprecated (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62456" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62456/hovercard">#62456</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1ecc5962a2"><code>1ecc5962a2</code></a>] - <strong>doc</strong>: fix 'transfered' typo in quic.md (lilianakatrina684-a11y) <a href="https://github.com/nodejs/node/pull/62492" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62492/hovercard">#62492</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/56741a1303"><code>56741a1303</code></a>] - <strong>doc</strong>: move sqlite type conversion section to correct level (René) <a href="https://github.com/nodejs/node/pull/62482" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62482/hovercard">#62482</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/12b04d17d5"><code>12b04d17d5</code></a>] - <strong>doc</strong>: add Rafael to last security release steward (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/62423" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62423/hovercard">#62423</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c4567e4a8d"><code>c4567e4a8d</code></a>] - <strong>doc</strong>: fix overstated Date header requirement in response.sendDate (Kit Dallege) <a href="https://github.com/nodejs/node/pull/62206" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62206/hovercard">#62206</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/384a41047f"><code>384a41047f</code></a>] - <strong>doc</strong>: enhance clarification about the main field (Mowafak Almahaini) <a href="https://github.com/nodejs/node/pull/62302" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62302/hovercard">#62302</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/93d19b1a1c"><code>93d19b1a1c</code></a>] - <strong>doc</strong>: minor typo fix (Jeff Matson) <a href="https://github.com/nodejs/node/pull/62358" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62358/hovercard">#62358</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3db35d2c59"><code>3db35d2c59</code></a>] - <strong>doc</strong>: add path to vulnerabilities.json mention (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/62355" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62355/hovercard">#62355</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/57b105c9d5"><code>57b105c9d5</code></a>] - <strong>doc</strong>: deprecate CryptoKey use in node:crypto (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62321" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62321/hovercard">#62321</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/490168c993"><code>490168c993</code></a>] - <strong>doc</strong>: fix small environment_variables typo (chris) <a href="https://github.com/nodejs/node/pull/62279" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62279/hovercard">#62279</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0291be584b"><code>0291be584b</code></a>] - <strong>doc</strong>: test and test-only targets do not run linter (Xavier Stouder) <a href="https://github.com/nodejs/node/pull/62120" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62120/hovercard">#62120</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ba0a82a1e1"><code>ba0a82a1e1</code></a>] - <strong>doc</strong>: clarify fs.ReadStream and fs.WriteStream are not constructable (Kit Dallege) <a href="https://github.com/nodejs/node/pull/62208" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62208/hovercard">#62208</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/125bdbf504"><code>125bdbf504</code></a>] - <strong>doc</strong>: clarify that any truthy value of <code>shell</code> is part of DEP0190 (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62249" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62249/hovercard">#62249</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a141ad0aeb"><code>a141ad0aeb</code></a>] - <strong>doc</strong>: remove outdated Chrome 66 and ndb references from debugger (Kit Dallege) <a href="https://github.com/nodejs/node/pull/62202" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62202/hovercard">#62202</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/44bde8e573"><code>44bde8e573</code></a>] - <strong>doc</strong>: add note (and caveat) for <code>mock.module</code> about customization hooks (Jacob Smith) <a href="https://github.com/nodejs/node/pull/62075" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62075/hovercard">#62075</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8c46a1ca1a"><code>8c46a1ca1a</code></a>] - <strong>doc</strong>: copyedit <code>addons.md</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62071" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62071/hovercard">#62071</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7f989f02f7"><code>7f989f02f7</code></a>] - <strong>doc</strong>: correct <code>util.convertProcessSignalToExitCode</code> validation behavior (René) <a href="https://github.com/nodejs/node/pull/62134" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62134/hovercard">#62134</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a4466ebdac"><code>a4466ebdac</code></a>] - <strong>doc</strong>: add efekrskl as triager (Efe) <a href="https://github.com/nodejs/node/pull/61876" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61876/hovercard">#61876</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/db516eca3a"><code>db516eca3a</code></a>] - <strong>doc</strong>: fix markdown for <code>expectFailure</code> values (Jacob Smith) <a href="https://github.com/nodejs/node/pull/62100" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62100/hovercard">#62100</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ad97045125"><code>ad97045125</code></a>] - <strong>doc</strong>: include url.resolve() in DEP0169 application deprecation (Mike McCready) <a href="https://github.com/nodejs/node/pull/62002" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62002/hovercard">#62002</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/309f37ba42"><code>309f37ba42</code></a>] - <strong>doc</strong>: expand SECURITY.md with non-vulnerability examples (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/61972" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61972/hovercard">#61972</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dbb3551b7b"><code>dbb3551b7b</code></a>] - <strong>doc</strong>: separate in-types and out-types in SQLite conversion docs (René) <a href="https://github.com/nodejs/node/pull/62034" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62034/hovercard">#62034</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/191c433db8"><code>191c433db8</code></a>] - <strong>doc</strong>: fix small logic error in DETECT_MODULE_SYNTAX (René) <a href="https://github.com/nodejs/node/pull/62025" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62025/hovercard">#62025</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8511b1c784"><code>8511b1c784</code></a>] - <strong>doc</strong>: fix module.stripTypeScriptTypes indentation (René) <a href="https://github.com/nodejs/node/pull/61992" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61992/hovercard">#61992</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dd1139f52c"><code>dd1139f52c</code></a>] - <strong>doc</strong>: update DEP0040 (punycode) to application type deprecation (Mike McCready) <a href="https://github.com/nodejs/node/pull/61916" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61916/hovercard">#61916</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/54009e9c62"><code>54009e9c62</code></a>] - <strong>doc</strong>: explicitly mention Slack handle (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/61986" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61986/hovercard">#61986</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/78fa1a1a49"><code>78fa1a1a49</code></a>] - <strong>doc</strong>: support toolchain Visual Studio 2022 &amp; 2026 + Windows 11 SDK (Mike McCready) <a href="https://github.com/nodejs/node/pull/61864" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61864/hovercard">#61864</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d8204d3cdb"><code>d8204d3cdb</code></a>] - <strong>doc</strong>: rename invalid <code>function</code> parameter (René) <a href="https://github.com/nodejs/node/pull/61942" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61942/hovercard">#61942</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a5a14482fb"><code>a5a14482fb</code></a>] - <strong>doc</strong>: clarify status of feature request issues (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/61505" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61505/hovercard">#61505</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bd0688feb6"><code>bd0688feb6</code></a>] - <strong>doc</strong>: add esm and cjs examples to node:vm (Alfredo González) <a href="https://github.com/nodejs/node/pull/61498" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61498/hovercard">#61498</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/240b512f9f"><code>240b512f9f</code></a>] - <strong>doc</strong>: clarify build environment is trusted in threat model (Matteo Collina) <a href="https://github.com/nodejs/node/pull/61865" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61865/hovercard">#61865</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5dd48e3456"><code>5dd48e3456</code></a>] - <strong>doc</strong>: remove incorrect mention of <code>module</code> in <code>typescript.md</code> (Rob Palmer) <a href="https://github.com/nodejs/node/pull/61839" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61839/hovercard">#61839</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9502c22055"><code>9502c22055</code></a>] - <strong>doc</strong>: simplify addAbortListener example (Chemi Atlow) <a href="https://github.com/nodejs/node/pull/61842" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61842/hovercard">#61842</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6fec397828"><code>6fec397828</code></a>] - <strong>doc</strong>: clean up globals.md (René) <a href="https://github.com/nodejs/node/pull/61822" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61822/hovercard">#61822</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a810f5ccef"><code>a810f5ccef</code></a>] - <strong>doc</strong>: clarify async caveats for <code>events.once()</code> (René) <a href="https://github.com/nodejs/node/pull/61572" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61572/hovercard">#61572</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2bf990bb1a"><code>2bf990bb1a</code></a>] - <strong>doc</strong>: update Juan's security steward info (Juan José) <a href="https://github.com/nodejs/node/pull/61754" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61754/hovercard">#61754</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0312db948d"><code>0312db948d</code></a>] - <strong>doc</strong>: fix methods being documented as properties in <code>process.md</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/61765" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61765/hovercard">#61765</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e558b26e7f"><code>e558b26e7f</code></a>] - <strong>doc</strong>: add riscv64 info into platform list (Lu Yahan) <a href="https://github.com/nodejs/node/pull/42251" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/42251/hovercard">#42251</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/49254e3dc0"><code>49254e3dc0</code></a>] - <strong>doc</strong>: fix dropdown menu being obscured at &lt;600px due to stacking context (Jeff) <a href="https://github.com/nodejs/node/pull/61735" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61735/hovercard">#61735</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4ff01b5c10"><code>4ff01b5c10</code></a>] - <strong>doc</strong>: fix spacing in process message event (Aviv Keller) <a href="https://github.com/nodejs/node/pull/61756" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61756/hovercard">#61756</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/94097a79d6"><code>94097a79d6</code></a>] - <strong>doc</strong>: move describe/it aliases section before expectFailure (Luca Raveri) <a href="https://github.com/nodejs/node/pull/61567" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61567/hovercard">#61567</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b7cd31acbe"><code>b7cd31acbe</code></a>] - <strong>doc</strong>: fix broken links of net.md (YuSheng Chen) <a href="https://github.com/nodejs/node/pull/61673" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61673/hovercard">#61673</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ae5e353fe2"><code>ae5e353fe2</code></a>] - <strong>doc</strong>: clean up Windows code snippet in <code>child_process.md</code> (reillylm) <a href="https://github.com/nodejs/node/pull/61422" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61422/hovercard">#61422</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ea9beb6a3c"><code>ea9beb6a3c</code></a>] - <strong>doc</strong>: update to Visual Studio 2026 manual install (Mike McCready) <a href="https://github.com/nodejs/node/pull/61655" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61655/hovercard">#61655</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/42057c84e2"><code>42057c84e2</code></a>] - <strong>doc,module</strong>: add missing doc for syncHooks.deregister() (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/61959" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61959/hovercard">#61959</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a035bd5235"><code>a035bd5235</code></a>] - <strong>doc,test</strong>: clarify --eval syntax for leading '-' scripts (kovan) <a href="https://github.com/nodejs/node/pull/62244" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62244/hovercard">#62244</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/deb0b78460"><code>deb0b78460</code></a>] - <strong>esm</strong>: fix typo in worker loader hook comment (jakecastelli) <a href="https://github.com/nodejs/node/pull/62475" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62475/hovercard">#62475</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b93bf7dbfc"><code>b93bf7dbfc</code></a>] - <strong>esm</strong>: fix source phase identity bug in loadCache eviction (Guy Bedford) <a href="https://github.com/nodejs/node/pull/62415" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62415/hovercard">#62415</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/679d18b57f"><code>679d18b57f</code></a>] - <strong>esm</strong>: fix path normalization in <code>finalizeResolution</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62080" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62080/hovercard">#62080</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/171e9fc268"><code>171e9fc268</code></a>] - <strong>esm</strong>: update outdated FIXME comment in translators.js (Karan Mangtani) <a href="https://github.com/nodejs/node/pull/61715" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61715/hovercard">#61715</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cc19728228"><code>cc19728228</code></a>] - <strong>events</strong>: avoid cloning listeners array on every emit (Gürgün Dayıoğlu) <a href="https://github.com/nodejs/node/pull/62261" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62261/hovercard">#62261</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/458c92be52"><code>458c92be52</code></a>] - <strong>events</strong>: don't call resume after close (Сковорода Никита Андреевич) <a href="https://github.com/nodejs/node/pull/60548" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60548/hovercard">#60548</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4691f3e7fb"><code>4691f3e7fb</code></a>] - <strong>fs</strong>: fix cpSync to handle non-ASCII characters (Stefan Stojanovic) <a href="https://github.com/nodejs/node/pull/61950" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61950/hovercard">#61950</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f4a3edc47a"><code>f4a3edc47a</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>fs</strong>: add <code>throwIfNoEntry</code> option for fs.stat and fs.promises.stat (Juan José) <a href="https://github.com/nodejs/node/pull/61178" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61178/hovercard">#61178</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/58e4d50cd0"><code>58e4d50cd0</code></a>] - <strong>http</strong>: fix use-after-free when freeParser is called during llhttp_execute (Gerhard Stöbich) <a href="https://github.com/nodejs/node/pull/62095" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62095/hovercard">#62095</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0a4ad85ab0"><code>0a4ad85ab0</code></a>] - <strong>http</strong>: validate ClientRequest path on set (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62030" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62030/hovercard">#62030</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f8178ac3e6"><code>f8178ac3e6</code></a>] - <strong>http</strong>: validate headers in writeEarlyHints (Richard Clarke) <a href="https://github.com/nodejs/node/pull/61897" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61897/hovercard">#61897</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/899884d0ed"><code>899884d0ed</code></a>] - <strong>http</strong>: remove redundant keepAliveTimeoutBuffer assignment (Efe) <a href="https://github.com/nodejs/node/pull/61743" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61743/hovercard">#61743</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/08d2e40694"><code>08d2e40694</code></a>] - <strong>http</strong>: attach error handler to socket synchronously in onSocket (RajeshKumar11) <a href="https://github.com/nodejs/node/pull/61770" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61770/hovercard">#61770</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1c2064c1f8"><code>1c2064c1f8</code></a>] - <strong>http</strong>: fix keep-alive socket reuse race in requestOnFinish (Martin Slota) <a href="https://github.com/nodejs/node/pull/61710" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61710/hovercard">#61710</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/38e9c66e0f"><code>38e9c66e0f</code></a>] - <strong>http2</strong>: add strictSingleValueFields option to relax header validation (Tim Perry) <a href="https://github.com/nodejs/node/pull/59917" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/59917/hovercard">#59917</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5cdcba17cc"><code>5cdcba17cc</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>http2</strong>: add http1Options for HTTP/1 fallback configuration (Amol Yadav) <a href="https://github.com/nodejs/node/pull/61713" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61713/hovercard">#61713</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/687c0acd00"><code>687c0acd00</code></a>] - <strong>http2</strong>: fix FileHandle leak in respondWithFile (sangwook) <a href="https://github.com/nodejs/node/pull/61707" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61707/hovercard">#61707</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0c8f802ec2"><code>0c8f802ec2</code></a>] - <strong>inspector</strong>: add Target.getTargets and extract TargetManager (Kohei) <a href="https://github.com/nodejs/node/pull/62487" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62487/hovercard">#62487</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7de8a303c1"><code>7de8a303c1</code></a>] - <strong>inspector</strong>: unwrap internal/debugger/inspect imports (René) <a href="https://github.com/nodejs/node/pull/61974" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61974/hovercard">#61974</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/59ac10a4fd"><code>59ac10a4fd</code></a>] - <strong>lib</strong>: make SubtleCrypto.supports enumerable (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62307" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62307/hovercard">#62307</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9dc102ba90"><code>9dc102ba90</code></a>] - <strong>lib</strong>: prefer primordials in SubtleCrypto (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62226" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62226/hovercard">#62226</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/78a9aa8f32"><code>78a9aa8f32</code></a>] - <strong>lib</strong>: fix source map url parse in dynamic imports (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/61990" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61990/hovercard">#61990</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/16b8cc6643"><code>16b8cc6643</code></a>] - <strong>lib</strong>: improve argument handling in Blob constructor (Ms2ger) <a href="https://github.com/nodejs/node/pull/61980" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61980/hovercard">#61980</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a03b5d39b8"><code>a03b5d39b8</code></a>] - <strong>lib</strong>: reduce cycles in esm loader and load it in snapshot (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/61769" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61769/hovercard">#61769</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1017bf5f86"><code>1017bf5f86</code></a>] - <strong>lib</strong>: remove top-level getOptionValue() calls in lib/internal/modules (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/61769" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61769/hovercard">#61769</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d79984b41b"><code>d79984b41b</code></a>] - <strong>lib</strong>: optimize styleText when validateStream is false (Rafael Gonzaga) <a href="https://github.com/nodejs/node/pull/61792" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61792/hovercard">#61792</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6462b89d10"><code>6462b89d10</code></a>] - <strong>meta</strong>: bump actions/download-artifact from 7.0.0 to 8.0.0 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62063" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62063/hovercard">#62063</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5bb89916ea"><code>5bb89916ea</code></a>] - <strong>meta</strong>: bump actions/upload-artifact from 6.0.0 to 7.0.0 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62062" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62062/hovercard">#62062</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b067d74d94"><code>b067d74d94</code></a>] - <strong>meta</strong>: bump step-security/harden-runner from 2.14.2 to 2.15.0 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62064" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62064/hovercard">#62064</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/830e5cd125"><code>830e5cd125</code></a>] - <strong>meta</strong>: bump github/codeql-action from 4.32.0 to 4.32.4 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/61911" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61911/hovercard">#61911</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/16c839a3dd"><code>16c839a3dd</code></a>] - <strong>meta</strong>: bump step-security/harden-runner from 2.14.1 to 2.14.2 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/61909" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61909/hovercard">#61909</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/498abf661e"><code>498abf661e</code></a>] - <strong>meta</strong>: bump actions/stale from 10.1.1 to 10.2.0 (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/61908" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61908/hovercard">#61908</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/78ac17f426"><code>78ac17f426</code></a>] - <strong>module</strong>: fix coverage of mocked CJS modules imported from ESM (Marco) <a href="https://github.com/nodejs/node/pull/62133" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62133/hovercard">#62133</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/46cfad4138"><code>46cfad4138</code></a>] - <strong>module</strong>: run require.resolve through module.registerHooks() (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/62028" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62028/hovercard">#62028</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8b6be3fe14"><code>8b6be3fe14</code></a>] - <strong>module</strong>: mark require(esm) as stable (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/60959" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60959/hovercard">#60959</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/68fbc0c6cc"><code>68fbc0c6cc</code></a>] - <strong>module</strong>: mark module compile cache as stable (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/60971" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60971/hovercard">#60971</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c851e76f8c"><code>c851e76f8c</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>net</strong>: add <code>setTOS</code> and <code>getTOS</code> to <code>Socket</code> (Amol Yadav) <a href="https://github.com/nodejs/node/pull/61503" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61503/hovercard">#61503</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c206ecb31"><code>4c206ecb31</code></a>] - <strong>quic</strong>: remove CryptoKey support from session keys option (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62335" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62335/hovercard">#62335</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2f9c085cf5"><code>2f9c085cf5</code></a>] - <strong>sqlite</strong>: handle stmt invalidation (Guilherme Araújo) <a href="https://github.com/nodejs/node/pull/61877" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61877/hovercard">#61877</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6ac4304c87"><code>6ac4304c87</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>sqlite</strong>: add limits property to DatabaseSync (Mert Can Altin) <a href="https://github.com/nodejs/node/pull/61298" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61298/hovercard">#61298</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/aaf9af1672"><code>aaf9af1672</code></a>] - <strong>sqlite</strong>: mark as release candidate (Matteo Collina) <a href="https://github.com/nodejs/node/pull/61262" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61262/hovercard">#61262</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7d67e5d693"><code>7d67e5d693</code></a>] - <strong>src</strong>: convert context_frame field in AsyncWrap to internal field (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/62103" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62103/hovercard">#62103</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d8ea1aaa8a"><code>d8ea1aaa8a</code></a>] - <strong>src</strong>: make AsyncWrap subclass internal field counts explicit (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/62103" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62103/hovercard">#62103</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1dbf3bedbe"><code>1dbf3bedbe</code></a>] - <strong>src</strong>: improve EC JWK import performance (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62396" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62396/hovercard">#62396</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cd84af747b"><code>cd84af747b</code></a>] - <strong>src</strong>: handle null backing store in ArrayBufferViewContents::Read (Mert Can Altin) <a href="https://github.com/nodejs/node/pull/62343" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62343/hovercard">#62343</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4f553cdc01"><code>4f553cdc01</code></a>] - <strong>src</strong>: enable compilation/linking with OpenSSL 4.0 (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62410" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62410/hovercard">#62410</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/70f8057258"><code>70f8057258</code></a>] - <strong>src</strong>: use stack allocation in indexOf latin1 path (Mert Can Altin) <a href="https://github.com/nodejs/node/pull/62268" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62268/hovercard">#62268</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d788467b6a"><code>d788467b6a</code></a>] - <strong>src</strong>: expose async context frame debugging helper to JS (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/62103" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62103/hovercard">#62103</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4213f893ec"><code>4213f893ec</code></a>] - <strong>src</strong>: release context frame in AsyncWrap::EmitDestroy (Gerhard Stöbich) <a href="https://github.com/nodejs/node/pull/61995" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61995/hovercard">#61995</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/79fb8cbcf5"><code>79fb8cbcf5</code></a>] - <strong>src</strong>: use validate_ascii_with_errors instead of validate_ascii (Сковорода Никита Андреевич) <a href="https://github.com/nodejs/node/pull/61122" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61122/hovercard">#61122</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2df328d59e"><code>2df328d59e</code></a>] - <strong>src</strong>: fix flags argument offset in JSUdpWrap (Weixie Cui) <a href="https://github.com/nodejs/node/pull/61948" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61948/hovercard">#61948</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/eb77a7a297"><code>eb77a7a297</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>src</strong>: add C++ support for diagnostics channels (RafaelGSS) <a href="https://github.com/nodejs/node/pull/61869" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61869/hovercard">#61869</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6cda3d30c0"><code>6cda3d30c0</code></a>] - <strong>src</strong>: remove unnecessary <code>c_str()</code> conversions in diagnostic messages (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/61786" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61786/hovercard">#61786</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/26c6045363"><code>26c6045363</code></a>] - <strong>src</strong>: use bool literals in TraceEnvVarOptions (Tobias Nießen) <a href="https://github.com/nodejs/node/pull/61425" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61425/hovercard">#61425</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3c8f700fd7"><code>3c8f700fd7</code></a>] - <strong>src</strong>: track allocations made by zstd streams (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/61717" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61717/hovercard">#61717</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/94dbb36d4d"><code>94dbb36d4d</code></a>] - <strong>src</strong>: do not store compression methods on Brotli classes (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/61717" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61717/hovercard">#61717</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bef661f182"><code>bef661f182</code></a>] - <strong>src</strong>: extract zlib allocation tracking into its own class (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/61717" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61717/hovercard">#61717</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e8079a8297"><code>e8079a8297</code></a>] - <strong>src</strong>: release memory for zstd contexts in <code>Close()</code> (Anna Henningsen) <a href="https://github.com/nodejs/node/pull/61717" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61717/hovercard">#61717</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6e1197a3cc"><code>6e1197a3cc</code></a>] - <strong>src</strong>: add more checks and clarify docs for external references (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/61719" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61719/hovercard">#61719</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c28a22c4be"><code>c28a22c4be</code></a>] - <strong>src</strong>: fix cjs_lexer external reference registration (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/61718" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61718/hovercard">#61718</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9e2c5fd7c9"><code>9e2c5fd7c9</code></a>] - <strong>src</strong>: simply uint32 to string as it must not fail (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/60846" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60846/hovercard">#60846</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/df435d32b8"><code>df435d32b8</code></a>] - <strong>src</strong>: build v8 tick processor as built-in source text modules (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/60518" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60518/hovercard">#60518</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2cb3573735"><code>2cb3573735</code></a>] - <strong>src,sqlite</strong>: fix filterFunc dangling reference (Edy Silva) <a href="https://github.com/nodejs/node/pull/62281" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62281/hovercard">#62281</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c44f53b544"><code>c44f53b544</code></a>] - <strong>stream</strong>: preserve error over AbortError in pipeline (Marco) <a href="https://github.com/nodejs/node/pull/62113" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62113/hovercard">#62113</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dc541370b4"><code>dc541370b4</code></a>] - <strong>stream</strong>: replace bind with arrow function for onwrite callback (Ali Hassan) <a href="https://github.com/nodejs/node/pull/62087" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62087/hovercard">#62087</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f6cdfbfaa7"><code>f6cdfbfaa7</code></a>] - <strong>stream</strong>: optimize webstreams pipeTo (Mattias Buelens) <a href="https://github.com/nodejs/node/pull/62079" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62079/hovercard">#62079</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fcf2a9f788"><code>fcf2a9f788</code></a>] - <strong>stream</strong>: fix brotli error handling in web compression streams (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62107" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62107/hovercard">#62107</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/cdec579c6b"><code>cdec579c6b</code></a>] - <strong>stream</strong>: improve Web Compression spec compliance (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62107" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62107/hovercard">#62107</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dbe5898379"><code>dbe5898379</code></a>] - <strong>stream</strong>: fix UTF-8 character corruption in fast-utf8-stream (Matteo Collina) <a href="https://github.com/nodejs/node/pull/61745" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61745/hovercard">#61745</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/531e62cd74"><code>531e62cd74</code></a>] - <strong>stream</strong>: fix TransformStream race on cancel with pending write (Marco) <a href="https://github.com/nodejs/node/pull/62040" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62040/hovercard">#62040</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a3751f2249"><code>a3751f2249</code></a>] - <strong>stream</strong>: accept ArrayBuffer in CompressionStream and DecompressionStream (조수민) <a href="https://github.com/nodejs/node/pull/61913" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61913/hovercard">#61913</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/65aa8f68d0"><code>65aa8f68d0</code></a>] - <strong>stream</strong>: fix pipeTo to defer writes per WHATWG spec (Matteo Collina) <a href="https://github.com/nodejs/node/pull/61800" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61800/hovercard">#61800</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/15f32b4935"><code>15f32b4935</code></a>] - <strong>stream</strong>: fix decoded fromList chunk boundary check (Thomas Watson) <a href="https://github.com/nodejs/node/pull/61884" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61884/hovercard">#61884</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/569767e52e"><code>569767e52e</code></a>] - <strong>stream</strong>: add fast paths for webstreams read and pipeTo (Matteo Collina) <a href="https://github.com/nodejs/node/pull/61807" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61807/hovercard">#61807</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6834ca13bb"><code>6834ca13bb</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>stream</strong>: rename <code>Duplex.toWeb()</code> type option to <code>readableType</code> (René) <a href="https://github.com/nodejs/node/pull/61632" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61632/hovercard">#61632</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5ed5474437"><code>5ed5474437</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to 2cb332d710 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62483" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62483/hovercard">#62483</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3c9c0f8577"><code>3c9c0f8577</code></a>] - <strong>test</strong>: fix test-buffer-zero-fill-cli to be effective (Сковорода Никита Андреевич) <a href="https://github.com/nodejs/node/pull/60623" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60623/hovercard">#60623</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/19a52a1abe"><code>19a52a1abe</code></a>] - <strong>test</strong>: update WPT for url to fc3e651593 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62379" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62379/hovercard">#62379</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/111ba9bd5b"><code>111ba9bd5b</code></a>] - <strong>test</strong>: wait for reattach before initial break on restart (Yuya Inoue) <a href="https://github.com/nodejs/node/pull/62471" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62471/hovercard">#62471</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0897c6cc08"><code>0897c6cc08</code></a>] - <strong>test</strong>: disable flaky WPT Blob test on AIX (James M Snell) <a href="https://github.com/nodejs/node/pull/62470" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62470/hovercard">#62470</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1c3d93bfab"><code>1c3d93bfab</code></a>] - <strong>test</strong>: avoid flaky run wait in debugger restart test (Yuya Inoue) <a href="https://github.com/nodejs/node/pull/62112" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62112/hovercard">#62112</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/83416a640a"><code>83416a640a</code></a>] - <strong>test</strong>: skip test-cluster-dgram-reuse on AIX 7.3 (Stewart X Addison) <a href="https://github.com/nodejs/node/pull/62238" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62238/hovercard">#62238</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/af8d0922dd"><code>af8d0922dd</code></a>] - <strong>test</strong>: add WebCrypto Promise.prototype.then pollution regression tests (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62226" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62226/hovercard">#62226</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fc9a60ec74"><code>fc9a60ec74</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to 6a1c545d77 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62187" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62187/hovercard">#62187</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/12ba2d74fe"><code>12ba2d74fe</code></a>] - <strong>test</strong>: update WPT for url to c928b19ab0 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62148" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62148/hovercard">#62148</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4e15e5b647"><code>4e15e5b647</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to c9e955840a (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62147" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62147/hovercard">#62147</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/dc66a05558"><code>dc66a05558</code></a>] - <strong>test</strong>: improve WPT report runner (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62107" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62107/hovercard">#62107</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9536e5621b"><code>9536e5621b</code></a>] - <strong>test</strong>: update WPT compression to ae05f5cb53 (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62107" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62107/hovercard">#62107</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fb1c0bda0a"><code>fb1c0bda0a</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to 42e47329fd (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/62048" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62048/hovercard">#62048</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d886f27485"><code>d886f27485</code></a>] - <strong>test</strong>: fix skipping behavior for <code>test-runner-run-files-undefined</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62026" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62026/hovercard">#62026</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f79df03e0b"><code>f79df03e0b</code></a>] - <strong>test</strong>: remove unnecessary <code>process.exit</code> calls from test files (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62020" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62020/hovercard">#62020</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1319295467"><code>1319295467</code></a>] - <strong>test</strong>: skip <code>test-url</code> on <code>--shared-ada</code> builds (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62019" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62019/hovercard">#62019</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/2ea06727c6"><code>2ea06727c6</code></a>] - <strong>test</strong>: skip strace test with shared openssl (Richard Lau) <a href="https://github.com/nodejs/node/pull/61987" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61987/hovercard">#61987</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c0680d5df7"><code>c0680d5df7</code></a>] - <strong>test</strong>: avoid flaky debugger restart waits (Yuya Inoue) <a href="https://github.com/nodejs/node/pull/61773" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61773/hovercard">#61773</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/22b748ef72"><code>22b748ef72</code></a>] - <strong>test</strong>: fix typos in test files (Daijiro Wachi) <a href="https://github.com/nodejs/node/pull/61408" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61408/hovercard">#61408</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a20bf9a84d"><code>a20bf9a84d</code></a>] - <strong>test</strong>: allow filtering async internal frames in assertSnapshot (Joyee Cheung) <a href="https://github.com/nodejs/node/pull/61769" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61769/hovercard">#61769</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/ec2913f036"><code>ec2913f036</code></a>] - <strong>test</strong>: unify assertSnapshot stacktrace transform (Chengzhong Wu) <a href="https://github.com/nodejs/node/pull/61665" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61665/hovercard">#61665</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/460f41233d"><code>460f41233d</code></a>] - <strong>test</strong>: check stability block position in API markdown (René) <a href="https://github.com/nodejs/node/pull/58590" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/58590/hovercard">#58590</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9ad02065d5"><code>9ad02065d5</code></a>] - <strong>test</strong>: adapt buffer test for v8 sandbox (Shelley Vohr) <a href="https://github.com/nodejs/node/pull/61772" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61772/hovercard">#61772</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5cf001736e"><code>5cf001736e</code></a>] - <strong>test</strong>: update FileAPI tests from WPT (Ms2ger) <a href="https://github.com/nodejs/node/pull/61750" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61750/hovercard">#61750</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/84c7a23223"><code>84c7a23223</code></a>] - <strong>test</strong>: update WPT for WebCryptoAPI to 7cbe7e8ed9 (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61729" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61729/hovercard">#61729</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/276a32fd10"><code>276a32fd10</code></a>] - <strong>test</strong>: update WPT for url to efb889eb4c (Node.js GitHub Bot) <a href="https://github.com/nodejs/node/pull/61728" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61728/hovercard">#61728</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f5f21d36a6"><code>f5f21d36a6</code></a>] - <strong>test_runner</strong>: add exports option for module mocks (sangwook) <a href="https://github.com/nodejs/node/pull/61727" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61727/hovercard">#61727</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bfc8a12977"><code>bfc8a12977</code></a>] - <strong>test_runner</strong>: make it compatible with fake timers (Matteo Collina) <a href="https://github.com/nodejs/node/pull/59272" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/59272/hovercard">#59272</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/e0cde40e1d"><code>e0cde40e1d</code></a>] - <strong>test_runner</strong>: set non-zero exit code when suite errors occur (Edy Silva) <a href="https://github.com/nodejs/node/pull/62282" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62282/hovercard">#62282</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d74efd6834"><code>d74efd6834</code></a>] - <strong>test_runner</strong>: run afterEach on runtime skip (Igor Shevelenkov) <a href="https://github.com/nodejs/node/pull/61525" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61525/hovercard">#61525</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8287ca749e"><code>8287ca749e</code></a>] - <strong>test_runner</strong>: expose expectFailure message (sangwook) <a href="https://github.com/nodejs/node/pull/61563" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61563/hovercard">#61563</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1f2025fd1e"><code>1f2025fd1e</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>test_runner</strong>: expose worker ID for concurrent test execution (Ali Hassan) <a href="https://github.com/nodejs/node/pull/61394" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61394/hovercard">#61394</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b1199c7bb4"><code>b1199c7bb4</code></a>] - <strong>test_runner</strong>: replace native methods with primordials (Ayoub Mabrouk) <a href="https://github.com/nodejs/node/pull/61219" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61219/hovercard">#61219</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1ca20fc33d"><code>1ca20fc33d</code></a>] - <strong>(SEMVER-MINOR)</strong> <strong>test_runner</strong>: show interrupted test on SIGINT (Matteo Collina) <a href="https://github.com/nodejs/node/pull/61676" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61676/hovercard">#61676</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/207ba4f89f"><code>207ba4f89f</code></a>] - <strong>test_runner</strong>: fix suite rerun (Moshe Atlow) <a href="https://github.com/nodejs/node/pull/61775" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61775/hovercard">#61775</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/9927335c11"><code>9927335c11</code></a>] - <strong>tls</strong>: forward keepAlive, keepAliveInitialDelay, noDelay to socket (Sergey Zelenov) <a href="https://github.com/nodejs/node/pull/62004" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62004/hovercard">#62004</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a1c3c901c0"><code>a1c3c901c0</code></a>] - <strong>tools</strong>: bump picomatch from 4.0.3 to 4.0.4 in /tools/eslint (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62439" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62439/hovercard">#62439</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/1c6f5ed7c2"><code>1c6f5ed7c2</code></a>] - <strong>tools</strong>: adopt the <code>--check-for-duplicates</code> NCU flag (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62478" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62478/hovercard">#62478</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b53377e8fe"><code>b53377e8fe</code></a>] - <strong>tools</strong>: bump flatted from 3.4.1 to 3.4.2 in /tools/eslint (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62375" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62375/hovercard">#62375</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f102e79b80"><code>f102e79b80</code></a>] - <strong>tools</strong>: bump eslint deps (Huáng Jùnliàng) <a href="https://github.com/nodejs/node/pull/62356" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62356/hovercard">#62356</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f5d74f8216"><code>f5d74f8216</code></a>] - <strong>tools</strong>: add eslint-plugin-regexp (Huáng Jùnliàng) <a href="https://github.com/nodejs/node/pull/62093" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62093/hovercard">#62093</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bc5b9a04ad"><code>bc5b9a04ad</code></a>] - <strong>tools</strong>: bump flatted from 3.3.3 to 3.4.1 in /tools/eslint (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62255" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62255/hovercard">#62255</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bad48b9700"><code>bad48b9700</code></a>] - <strong>tools</strong>: validate all commits that are pushed to <code>main</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62246" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62246/hovercard">#62246</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/795d663ff4"><code>795d663ff4</code></a>] - <strong>tools</strong>: keep GN files when updating Merve (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62167" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62167/hovercard">#62167</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0b6fa913f1"><code>0b6fa913f1</code></a>] - <strong>tools</strong>: revert timezone update GHA workflow to ubuntu-latest (Richard Lau) <a href="https://github.com/nodejs/node/pull/62140" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62140/hovercard">#62140</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/840e098e99"><code>840e098e99</code></a>] - <strong>tools</strong>: improve error handling in test426 update script (Rich Trott) <a href="https://github.com/nodejs/node/pull/62121" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62121/hovercard">#62121</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bd34e53a8e"><code>bd34e53a8e</code></a>] - <strong>tools</strong>: bump the eslint group across 1 directory with 2 updates (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62092" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62092/hovercard">#62092</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/54dc797644"><code>54dc797644</code></a>] - <strong>tools</strong>: fix daily wpt workflow nighly release version lookup (Filip Skokan) <a href="https://github.com/nodejs/node/pull/62076" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62076/hovercard">#62076</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/30476ddff7"><code>30476ddff7</code></a>] - <strong>tools</strong>: fix example in release proposal linter (Richard Lau) <a href="https://github.com/nodejs/node/pull/62074" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62074/hovercard">#62074</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/5245900c05"><code>5245900c05</code></a>] - <strong>tools</strong>: bump minimatch from 3.1.3 to 3.1.5 in /tools/clang-format (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/62013" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62013/hovercard">#62013</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/59ad1e4503"><code>59ad1e4503</code></a>] - <strong>tools</strong>: bump eslint to v10, babel to v8.0.0-rc.2 (Huáng Jùnliàng) <a href="https://github.com/nodejs/node/pull/61905" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61905/hovercard">#61905</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/6f93c4b287"><code>6f93c4b287</code></a>] - <strong>tools</strong>: fix parsing of commit trailers in <code>lint-release-proposal</code> GHA (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/62077" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62077/hovercard">#62077</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/de1bcfd54c"><code>de1bcfd54c</code></a>] - <strong>tools</strong>: bump minimatch from 3.1.2 to 3.1.3 in <code>/tools/clang-format</code> (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/61977" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61977/hovercard">#61977</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/492868a7aa"><code>492868a7aa</code></a>] - <strong>tools</strong>: fix permissions for merve update script (Richard Lau) <a href="https://github.com/nodejs/node/pull/62023" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62023/hovercard">#62023</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/774d0be1b3"><code>774d0be1b3</code></a>] - <strong>tools</strong>: revert tools GHA workflow to ubuntu-latest (Richard Lau) <a href="https://github.com/nodejs/node/pull/62024" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62024/hovercard">#62024</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/d91a689d6f"><code>d91a689d6f</code></a>] - <strong>tools</strong>: bump minimatch from 3.1.2 to 3.1.3 in /tools/eslint (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/61976" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61976/hovercard">#61976</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/34b6305933"><code>34b6305933</code></a>] - <strong>tools</strong>: roll back to x86 runner on <code>scorecard.yml</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/61944" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61944/hovercard">#61944</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/937cd97a63"><code>937cd97a63</code></a>] - <strong>tools</strong>: fix auto-start-ci (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/61900" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61900/hovercard">#61900</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/0958f9a9c7"><code>0958f9a9c7</code></a>] - <strong>tools</strong>: do not checkout repo in <code>auto-start-ci.yml</code> (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/61874" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61874/hovercard">#61874</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/c7607b9208"><code>c7607b9208</code></a>] - <strong>tools</strong>: automate updates for test/fixtures/test426 (Rich Trott) <a href="https://github.com/nodejs/node/pull/60978" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60978/hovercard">#60978</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/00df3c1273"><code>00df3c1273</code></a>] - <strong>tools</strong>: bump unist-util-visit in /tools/doc in the doc group (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/61646" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61646/hovercard">#61646</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/fe15b0d65e"><code>fe15b0d65e</code></a>] - <strong>tools</strong>: bump the eslint group in /tools/eslint with 6 updates (dependabot[bot]) <a href="https://github.com/nodejs/node/pull/61628" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61628/hovercard">#61628</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/bc38db51fc"><code>bc38db51fc</code></a>] - <strong>tools</strong>: fix small inconsistencies in JSON doc output (Antoine du Hamel) <a href="https://github.com/nodejs/node/pull/61757" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61757/hovercard">#61757</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/3e7010d47f"><code>3e7010d47f</code></a>] - <strong>tools</strong>: refloat 10 Node.js patches to cpplint.py (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/60901" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60901/hovercard">#60901</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/583e6c67ea"><code>583e6c67ea</code></a>] - <strong>tools</strong>: update cpplint to 2.0.2 (Michaël Zasso) <a href="https://github.com/nodejs/node/pull/60901" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/60901/hovercard">#60901</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/4c12ab8abc"><code>4c12ab8abc</code></a>] - <strong>typings</strong>: rationalise TypedArray types (René) <a href="https://github.com/nodejs/node/pull/62174" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62174/hovercard">#62174</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8357ebfe54"><code>8357ebfe54</code></a>] - <strong>url</strong>: suppress warnings from url.format/url.resolve inside node_modules (René) <a href="https://github.com/nodejs/node/pull/62005" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62005/hovercard">#62005</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/aad7b3cfca"><code>aad7b3cfca</code></a>] - <strong>url</strong>: enable simdutf for ada (Yagiz Nizipli) <a href="https://github.com/nodejs/node/pull/61477" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61477/hovercard">#61477</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/7b28fb9812"><code>7b28fb9812</code></a>] - <strong>util</strong>: allow color aliases in styleText (sangwook) <a href="https://github.com/nodejs/node/pull/62180" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62180/hovercard">#62180</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/8bbe0138ce"><code>8bbe0138ce</code></a>] - <strong>util</strong>: add fast path to stripVTControlCharacters (Hiroki Osame) <a href="https://github.com/nodejs/node/pull/61833" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61833/hovercard">#61833</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/f7a408d6f7"><code>f7a408d6f7</code></a>] - <strong>wasm</strong>: support js string constant esm import (Guy Bedford) <a href="https://github.com/nodejs/node/pull/62198" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62198/hovercard">#62198</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a0316d33b5"><code>a0316d33b5</code></a>] - <strong>watch</strong>: get flags from execArgv (Efe) <a href="https://github.com/nodejs/node/pull/61779" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61779/hovercard">#61779</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/eee96f7f5d"><code>eee96f7f5d</code></a>] - <strong>worker</strong>: heap profile optimizations (Ilyas Shabi) <a href="https://github.com/nodejs/node/pull/62201" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62201/hovercard">#62201</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/deeeb22e1a"><code>deeeb22e1a</code></a>] - <strong>worker</strong>: eliminate race condition in process.cwd() (giulioAZ) <a href="https://github.com/nodejs/node/pull/61664" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61664/hovercard">#61664</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/b15ea64ed9"><code>b15ea64ed9</code></a>] - <strong>zlib</strong>: fix use-after-free when reset() is called during write (Matteo Collina) <a href="https://github.com/nodejs/node/pull/62325" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/62325/hovercard">#62325</a></li>
<li>[<a href="https://github.com/nodejs/node/commit/a9c5bd29c9"><code>a9c5bd29c9</code></a>] - <strong>zlib</strong>: add support for brotli compression dictionary (Andy Weiss) <a href="https://github.com/nodejs/node/pull/61763" data-hovercard-type="pull_request" data-hovercard-url="/nodejs/node/pull/61763/hovercard">#61763</a></li>
</ul>]]></content:encoded>
</item>
<item>
<title><![CDATA[개발의 민주화를 이끄는 바이브 코딩 도구 19선]]></title>
<description><![CDATA[AI가 인간이 한 달 동안 작성할 코드를 몇 분 만에 만들어준다면 마다할 사람이 있을까. 마법 같은 기술을 싫어할 이유가 있을까. 바이브 코딩을 둘러싼 기대는 등장 초기부터 개발자와 비즈니스 사용자 모두에게 이런 가능성을 제시해왔다.



그리고 이제 그 기대가 현실이 될 만큼 기술이 성숙했다는 평가가 나온다.



물론 신중한 리더들이 “숨겨진 함정은 없는가? 혹시 위험한 기술은 아닌가?”라고 의문을 제기하는 것도 타당하다. AI는 인간이 작성한 코드를 학습해 발전해왔고, 인간은 실수를 하기 때문이다. 실제로 일부 바이브 코...]]></description>
<link>https://tsecurity.de/de/3485500/it-nachrichten/19/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3485500/it-nachrichten/19/</guid>
<pubDate>Mon, 04 May 2026 11:01:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>AI가 인간이 한 달 동안 작성할 코드를 몇 분 만에 만들어준다면 마다할 사람이 있을까. 마법 같은 기술을 싫어할 이유가 있을까. 바이브 코딩을 둘러싼 기대는 등장 초기부터 개발자와 비즈니스 사용자 모두에게 이런 가능성을 제시해왔다.</p>



<p>그리고 이제 그 기대가 현실이 될 만큼 기술이 성숙했다는 평가가 나온다.</p>



<p>물론 신중한 리더들이 “숨겨진 함정은 없는가? 혹시 위험한 기술은 아닌가?”라고 의문을 제기하는 것도 타당하다. AI는 인간이 작성한 코드를 학습해 발전해왔고, 인간은 실수를 하기 때문이다. 실제로 일부 바이브 코딩 사용자와 업계 전문가들은 문서화되지 않은 엔드포인트나 민감 데이터 유출과 같은 취약점이 존재할 수 있다고 지적한다.</p>



<p>그럼에도 불구하고 많은 사용자들은 바이브 코딩을 적극적으로 도입하고 있으며, 긍정적인 결과를 보고하고 있다. 이들은 새로운 도구들이 “놀라울 정도로 강력하다”고 평가한다. 간단한 설명만으로 몇 분 안에 프로토타입을 만들고, 몇 차례 반복을 거쳐 최소 기능 제품(MVP)까지 구현할 수 있다. 과거에는 몇 주가 걸리던 작업이 단시간에 가능해진 셈이다. 특히 비즈니스 사용자의 경우 개발 리소스를 확보하는 과정에서 발생하던 각종 절차와 제약도 크게 줄일 수 있다. 물론 오류나 누락이 발생할 수 있지만, 이는 인간 개발팀에서도 충분히 발생할 수 있는 수준이라는 시각도 있다.</p>



<p>결국 현실은 분명하다. 바이브 코딩은 기업이 실험을 시작할 만큼 충분히 실용적인 기술로 자리 잡았다. 다만 플랫폼마다 특성은 크게 다르다. 일부는 대규모 코드베이스를 다루는 전문 개발자를 지원하는 데 적합하고, 다른 일부는 개발 경험이 많지 않지만 원하는 결과를 알고 있는 사용자들을 돕는 데 초점을 맞춘다. 특정 프로그래밍 언어에 익숙하지 않거나 프로그래밍 자체에 대한 이해가 부족한 사용자도 활용할 수 있다. 더 나아가 컴퓨터 사용이 익숙하지 않은 초보자까지 겨냥한 도구도 등장하고 있다.</p>



<p>차별화 요소는 사용자 경험 수준에만 국한되지 않는다. 일부 도구는 전문 개발자의 생산성을 극대화하는 ‘보조 도구’ 역할에 집중하는 반면, 다른 도구는 데이터베이스부터 프런트엔드까지 전체 애플리케이션을 자동으로 생성한다. 특히 후자의 경우 대규모 사용자 환경에 바로 적용하기에는 한계가 있을 수 있지만, 경영진이나 투자자에게 제시할 프로토타입 제작에는 매우 효과적이다. 또한 소규모 사용자 환경에서는 충분히 실용적으로 활용될 수 있다.</p>



<p>그렇다면 이 도구들은 실제로 충분히 완성도 높은 수준일까. 단점을 보완해 활용할 수 있을까. 이를 확인하는 방법은 단 하나, 직접 실행해보고 결과를 확인하는 것이다.</p>



<p>다음은 주목할 만한 바이브 코딩 도구 19종을 알파벳 순으로 정리한 목록이다. 이들 모두 애플리케이션 개발 과정에 ‘마법 같은 경험’을 제공하겠다는 공통된 목표를 내세우고 있다.</p>



<h2 class="wp-block-heading">베이스44 (Base44)</h2>



<p><a href="https://base44.com/" target="_blank" rel="nofollow">베이스44</a>(Base44, 현재는 윅스(Wix)가 인수)는 ‘빌더 챗(Builder Chat)’에서 데이터 아키텍처를 중심으로 논의를 시작하는 방식으로 동작한다. 이후 사용자가 입력한 설명을 바탕으로 리액트(React)와 테일윈드(Tailwind) 기반 프런트엔드와 디노(Deno) 백엔드를 결합해 애플리케이션을 생성한다. 전자상거래, 콘텐츠 관리, 생산성 등 다양한 활용 사례에 맞는 템플릿을 제공해 개발 속도를 높일 수 있다. 또한 드래그앤드롭 방식의 시각적 UI 편집기를 통해 세부 요소를 빠르게 수정할 수 있어, 텍스트로 변경 사항을 일일이 설명하는 방식보다 효율적이다.</p>



<h2 class="wp-block-heading">베티 블록스(Betty Blocks)</h2>



<p><a href="https://www.bettyblocks.com/" target="_blank" rel="nofollow">베티 블록스</a>(Betty Blocks)는 ‘시민 개발자’를 주요 타깃으로 하는 노코드 플랫폼이다. 이는 프로그래밍 경험은 없지만 조직 내 요구사항을 잘 이해하고 있는 사용자들을 의미한다. 해당 플랫폼은 사용자의 설명을 기반으로 리액트 코드를 생성하며, 이를 코드 저장소로 내보내 추가 개발에 활용하거나 WASM 형태로 컴파일해 배포할 수 있다. 또한 시각적 인터페이스를 통해 세부 조정이 가능한 ‘로우코드’ 기능도 함께 제공한다.</p>



<h2 class="wp-block-heading">블링크(Blink)</h2>



<p><a href="https://blink.new/" target="_blank" rel="nofollow">블링크</a>(Blink)는 코드 생성 에이전트로, 두 가지 모드에서 타입스크립트(TypeScript) 기반 리액트 애플리케이션을 생성한다. 하나는 실제 개발을 수행하는 ‘에이전트 모드’, 다른 하나는 논의와 설계를 위한 ‘채팅 모드’다. 개발자는 채팅을 통해 방향을 설정한 뒤 두 모드를 오가며 작업을 진행한다. 완성된 애플리케이션은 블링크의 내부 CDN에서 호스팅할 수 있으며, 자체 서버나 클라우드 환경으로 내보내는 것도 가능하다.</p>



<h2 class="wp-block-heading">볼트(Bolt)</h2>



<p><a href="https://bolt.new/" data-type="link" data-id="https://bolt.new/" target="_blank" rel="nofollow">볼트</a>(Bolt)는 다양한 백엔드 AI 코딩 모델을 하나의 시각적 인터페이스에서 활용할 수 있도록 설계된 노코드 채팅 서비스다. 앤트로픽의 클로드, 구글 제미나이 등 주요 모델을 포함해 여러 코딩 에이전트를 선택적으로 사용할 수 있다. 특히 디자인 레이어를 분리해 공통 디자인을 정의하고, 이를 모든 생성 애플리케이션에 일관되게 적용할 수 있는 것이 특징이다. MIT 라이선스로 공개된 <a href="https://github.com/stackblitz/bolt.new" rel="nofollow">오픈소스 버전</a>도 제공된다.</p>



<h2 class="wp-block-heading">버블(Bubble)</h2>



<p>버블(Bubble)은 단순한 채팅 기반 인터페이스를 넘어 다양한 시각적 기능을 제공하는 노코드 도구다. 전체 UI를 직접 조정할 수 있는 시각적 편집기와 함께, 내부 동작 구조를 확인할 수 있는 워크플로우 뷰를 제공한다. 이를 통해 사용자는 결과를 추측하는 수준을 넘어 실제 동작을 이해하고 제어할 수 있다. 궁극적으로 인간과 AI가 협력하는 개발 환경을 구현하는 것을 목표로 한다.</p>



<h2 class="wp-block-heading">클로드 코드(Claude Code)</h2>



<p>AI 기업 앤트로픽의 <a href="https://claude.com/product/claude-code" target="_blank" rel="nofollow">클로드 코드</a>는 새로운 애플리케이션 생성은 물론 기존 코드 수정까지 다양한 개발 요구를 처리하는 데 강점을 보인다. 백엔드는 VS코드(VSCode) 등 주요 IDE와 연동되며, 터미널 창이나 슬랙(Slack) 채널을 통해 접근하는 사용자도 많다. 특히 대규모 코드베이스에서 문제 해결의 출발점을 찾는 용도로 자주 활용된다. 사용자들은 클로드가 각 조직의 코딩 표준에 유연하게 적응하는 점을 높이 평가한다.</p>



<h2 class="wp-block-heading">컨티뉴(Continue)</h2>



<p><a href="https://github.com/continuedev/continue" target="_blank" rel="nofollow">컨티뉴</a>(Continue)는 오픈소스 기반 에이전트로, 추가적인 지원이 필요한 전문 개발자에게 적합한 도구다. 코드 저장소를 지속적으로 모니터링하면서 새로운 풀 리퀘스트 등 특정 이벤트가 발생하면 AI 에이전트를 호출해 반복 작업을 처리한다. 모든 작업을 자동화하기보다는 단순하고 반복적인 업무를 대신 수행해 개발자가 창의적인 작업에 집중할 수 있도록 돕는 것이 목표다. 다양한 IDE와 AI API와의 연동도 지원한다.</p>



<h2 class="wp-block-heading">크리에이트(Create.xyz)</h2>



<p><a href="http://create.xyz/" target="_blank" rel="nofollow">크리에이트</a>(Create.xyz)는 ‘애니띵(Anything)’이라는 이름의 도구를 통해 간단한 텍스트 입력만으로 다양한 리액트/테일윈드 애플리케이션을 생성할 수 있도록 한다. 데이터베이스 접근 등 주요 기능은 미리 설계된 컴포넌트로 구성되며, 브라우저와 모바일 환경 모두에서 원활하게 작동한다. 이후 개발자는 생성된 코드에 직접 접근해 필요한 부분을 수정하거나 추가 기능을 구현할 수 있다.</p>



<h2 class="wp-block-heading">커서(Cursor)</h2>



<p><a href="https://cursor.com/" target="_blank" rel="nofollow">커서</a>(Cursor)는 기존 개발 환경에서 활용할 수 있는 AI 기반 개발 도우미로, 많은 숙련 개발자들 사이에서 높은 평가를 받고 있다. 새로운 코드 작성, 기존 코드 검토, 슬랙 등 협업 채널에서 발생하는 이슈 추적까지 다양한 역할을 수행한다. 여러 파일을 동시에 처리하고 전체 코드베이스를 분석해 실행 계획을 제시한 뒤 실제 작업까지 수행하는 것이 특징이다. 전통적인 개발 환경을 기반으로 하기 때문에 ‘노코드’ 도구로 보기는 어렵지만, 실제로는 개발자가 직접 작성하는 코드의 양을 크게 줄여준다.</p>



<h2 class="wp-block-heading">이머전트(Emergent)</h2>



<p><a href="http://emergent.sh/" target="_blank" rel="nofollow">이머전트</a>(Emergent)는 여러 AI 에이전트를 결합한 웹 애플리케이션으로, 사용자의 텍스트 설명을 기반으로 프런트엔드(React), 백엔드(Node.js), 데이터베이스(MongoDB), 그리고 다양한 API(Stripe 등 통합 포함)까지 한 번에 생성한다. 단순한 보조 기능을 넘어 개발 과정의 복잡성을 사용자에게서 완전히 숨기는 것이 목표다. 비개발자는 원하는 애플리케이션을 직접 구축할 수 있고, 개발자는 빠르게 프로토타입을 제작해 실제 서비스에 가까운 형태로 배포할 수 있다.</p>



<h2 class="wp-block-heading">킬로 코드(Kilo Code)</h2>



<p><a href="https://kilo.ai/" target="_blank" rel="nofollow">킬로 코드</a>(Kilo Code)는 대규모 코드베이스를 유지·확장하는 개발자를 위한 오픈소스 코딩 에이전트다. ‘오케스트레이터 모드(Orchestrator Mode)’를 통해 작업 계획을 수립할 수 있으며, 코드 리뷰 기능은 오류를 이중으로 점검한다. 또한 ‘메모리 뱅크(Memory Bank)’를 통해 프로젝트 아키텍처에 대한 핵심 정보를 저장·관리할 수 있다. 500개 이상의 AI 모델과 연동을 지원해 특정 플랫폼에 종속되지 않고, 상황에 맞는 최적의 모델을 선택할 수 있는 유연성도 제공한다.</p>



<h2 class="wp-block-heading">린디(Lindy)</h2>



<p><a href="https://www.lindy.ai/" target="_blank" rel="nofollow">린디</a>(Lindy)는 슬랙 메시지나 코드 저장소의 새로운 커밋과 같은 이벤트를 트리거로 동작하는 ‘에이전트’ 생성에 초점을 맞춘 도구다. 이러한 이벤트는 주요 클라우드 서비스와 지라(Jira), 조호(Zoho) 등 업무 관리 플랫폼을 포함한 수백 개 웹 애플리케이션에서 발생한다. 사전 정의된 템플릿을 활용하면 일반적인 애플리케이션을 보다 빠르게 구축할 수 있으며, 대표적인 활용 사례로는 고객 지원 에이전트가 꼽힌다.</p>



<h2 class="wp-block-heading">러버블(Lovable)</h2>



<p><a href="https://lovable.dev/" target="_blank" rel="nofollow">러버블</a>(Lovable)은 대화를 통해 요구사항을 파악한 뒤 자체 클라우드 환경에서 애플리케이션 생성과 배포까지 자동으로 수행하는 노코드 플랫폼이다. UI(리액트와 테일윈드), 비즈니스 로직, 데이터베이스(주로 Supabase)를 모두 처리한다. 비교적 완성도 높은 인터페이스와 함께 보안 및 접근 제어 기능을 갖춘 엔터프라이즈급 프로토타입을 빠르게 구축할 수 있는 것이 특징이다.</p>



<h2 class="wp-block-heading">리플릿(Replit)</h2>



<p><a href="https://replit.com/" target="_blank" rel="nofollow">리플릿</a>(Replit)은 최대 30개 프로그래밍 언어를 지원하는 노코드 솔루션으로, 주요 언어는 물론 다양한 비주류 언어까지 폭넓게 지원한다. 기본 인터페이스는 노코드 챗봇 형태지만, 생성된 코드는 이후 저장소에 저장돼 전통적인 방식으로 추가 개발이 가능하다. 데이터베이스 계층을 분리해 운영 환경과 테스트 환경을 구분하는 등 보다 전통적인 개발 접근도 지원한다. 또한 팀 단위 협업 기능을 통해 구성원들이 함께 대화하며 애플리케이션을 개선할 수 있다.</p>



<h2 class="wp-block-heading">소프트젠(Softgen)</h2>



<p><a href="https://softgen.ai/" target="_blank" rel="nofollow">소프트젠</a>(Softgen)은 간단한 텍스트 설명을 기반으로 Next.js 웹 애플리케이션을 생성하는 도구다. 클로드 4.5, 제미나이 등 주요 AI 모델과 연동해 최소 기능 제품(MVP)을 빠르게 구축할 수 있다. 사용량 기반 과금 방식을 적용해 애플리케이션에 필요한 토큰만큼만 비용을 지불하면 된다.</p>



<h2 class="wp-block-heading">솔리드(Solid)</h2>



<p>기본적인 애플리케이션 생성이 점차 쉬워진 가운데, 솔리드(Solid)는 ‘엔터프라이즈급’ 배포에 초점을 맞추고 있다. 고도화된 보안 모델과 분산 배포 환경을 지원하는 것이 특징이다. 문서에서는 AI와 반복적으로 협업하며 강점을 활용하는 방식을 강조하는데, 주로 리액트/테일윈드 기반 프런트엔드와 노드JS 상에서 타입스크립트로 구현된 백엔드, 그리고 포스트그레SQL 데이터베이스 조합을 중심으로 구성된다.</p>



<h2 class="wp-block-heading">템포 랩스(Tempo Labs)</h2>



<p><a href="https://www.tempo.new/" target="_blank" rel="nofollow">템포 랩스</a>(Tempo Labs)는 시각적 편집기를 통해 개발 속도를 크게 높이는 데 초점을 맞춘 도구다. 간단한 UI 작업은 AI에 의존하지 않고 직접 수행할 수 있으며, 디자인 중심의 개발 환경을 제공한다. 프로젝트별로 표준 UI 요소 라이브러리를 유지하고, 기존 리액트 코드베이스를 불러와 사전 개발된 컴포넌트와 템플릿으로 확장할 수 있다. 직관적인 인터페이스를 통해 ‘바이브 코딩’ 경험을 극대화하는 것이 특징이다.</p>



<h2 class="wp-block-heading">버셀(Vercel)</h2>



<p>버셀(Vercel)의 <a href="https://v0.app/" target="_blank" rel="nofollow">v0 시스템</a>은 다양한 템플릿을 기반으로 애플리케이션 설계를 시작할 수 있도록 지원한다. 기본 인터페이스는 여전히 채팅 형태지만, 템플릿은 설계 아이디어를 제공하는 동시에 명세 작성의 공통 언어 역할을 한다. 또한 디자인 템플릿을 활용해 여러 애플리케이션 간 UI 일관성을 유지할 수 있으며, 모바일 브라우저에 최적화된 구조를 통해 모바일 대응 웹사이트를 쉽게 구축할 수 있다.</p>



<h2 class="wp-block-heading">윈드서프(Windsurf)</h2>



<p><a href="https://windsurf.com/" target="_blank" rel="nofollow">윈드서프</a>(Windsurf)는 대규모 코드베이스를 다루는 팀을 위한 AI 내장형 IDE다. 버그 수정이나 기능 추가와 같은 복잡한 작업을 여러 단계에 걸쳐 처리할 수 있도록 설계됐다. 전통적인 개발 방식을 보완하는 형태의 바이브 코딩 도구라고 할 수 있다. 특히 탭(Tab) 키를 활용한 인터페이스가 특징으로, 제안된 수정안을 단계별로 확인하며 승인할 수 있다. 이 IDE는 이러한 다단계 작업 흐름을 ‘캐스케이드(cascade)’라고 부른다.<br>dl-ciokorea@foundryco.com</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[19 vibe coding tools for democratizing app development]]></title>
<description><![CDATA[Who doesn’t want an AI to pump out more code in minutes than a human might write in a month? Who doesn’t like magic? That’s what the hype around vibe coding has asked of developers and business users alike since its inception.



But now the tools might have matured enough to deliver.



Yes, cau...]]></description>
<link>https://tsecurity.de/de/3480063/it-nachrichten/19-vibe-coding-tools-for-democratizing-app-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3480063/it-nachrichten/19-vibe-coding-tools-for-democratizing-app-development/</guid>
<pubDate>Fri, 01 May 2026 12:17:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Who doesn’t want an AI to pump out more code in minutes than a human might write in a month? Who doesn’t like magic? That’s what the hype around vibe coding has asked of developers and business users alike since its inception.</p>



<p>But now the tools might have matured enough to deliver.</p>



<p>Yes, cautious leaders are right in wondering, “What’s the catch? Is this a trap?” After all, the AIs learned to code from examining code created by humans, and humans fail. So it should be no surprise that some vibe coders and industry experts are reporting vulnerabilities such as undocumented endpoints and sensitive data leakage.</p>



<p>Still, many are diving right into the vibe-code deep end and are reporting positive results. The new tools, they say, are amazing. Vibe coders can build a prototype in minutes and a minimum viable product in a few iterations. In goes a few handwavy sentences, and out comes something that used to take weeks to produce — not to mention all the red tape in tapping development time, if you’re a business user. Sure there can be errors and omissions, but are they any worse than what a team of humans might inadvertently include or overlook?</p>



<p>The reality is that vibe coding is legit enough that enterprises need to start experimenting. The platforms offer numerous differences. Some are better suited to helping professional developers who often need to work with large code bases. Others want to help not-so-professional programmers who know what they want but aren’t ready to write it all by themselves. Maybe they don’t know a particular programming language or maybe they don’t know much about programming at all. Still others are aimed at complete novices who can barely turn on a computer.</p>



<p>And it’s not just the level of experience that distinguishes them. Some tackle smaller wishes —the kind of tools that professional developers can use as a “force multiplier.” Others create entire applications, from database to front-end, and they’re best for people who want to create a prototype. The architecture may not be ready to scale for a large user base, but they’re ideal for presenting to the boss or some investors. They can also do a pretty good job with a smaller collection of users.</p>



<p>Are any good enough? Can we work around their flaws? The only way to find out is to fire them up and look at the results.</p>



<p>Here is a list of 19 vibe coding tools worth checking out, in alphabetical order. They all promise to provide some amount of app-dev magic.</p>



<h2 class="wp-block-heading">Base44/Wix</h2>



<p>The process at <a href="https://base44.com/" rel="nofollow">Base44</a> (now owned by Wix) begins with a Builder Chat in which the discussion focuses on the data architecture. From there, your words guide a tool that merges React and Tailwind code for the front-end with a Deno backend. To speed things up, templates can jumpstart common use cases — ecommerce, content management, productivity, etc. Many parts of the UI can be adjusted with a drag-and-drop visual editor that can be much faster than trying to describe all your changes with words.</p>



<h2 class="wp-block-heading">Betty Blocks</h2>



<p>The developers of the <a href="https://www.bettyblocks.com/" rel="nofollow">Betty Blocks</a> no-code system say they’re targeting “citizen developers” —non-programmers who know what their corner of the enterprise needs. The platform takes a description and then produces React code that can be exported to a code repository for future development or be compiled down to WASM level deployment. They also offer a “low-code” approach that gives a visual interface for further tweaking and refinement.</p>



<h2 class="wp-block-heading">Blink</h2>



<p>The code generation agent from <a href="https://blink.new/" rel="nofollow">Blink</a> produces TypeScript React applications starting with two modes: agent mode, for building; and chat mode, for discussing and planning. Developers start with chatting and then toggle back and forth. Blink will host any application with its internal CDN or allow you to export it to your own servers or cloud.</p>



<h2 class="wp-block-heading">Bolt</h2>



<p>The no-code chat service from <a href="https://bolt.new/" rel="nofollow">Bolt</a> is designed to provide a single visual interface to various backend coding AIs. It’s possible to work with different coding agents, including some of the best-known ones, such as Anthropic’s Claude and Google’s Gemini. The design layer is broken out making it possible to create a standard design that is then adopted by any app that’s produced by the AI. An <a href="https://github.com/stackblitz/bolt.new" rel="nofollow">open-source version</a> released under the MIT license is also available.</p>



<h2 class="wp-block-heading">Bubble</h2>



<p>The no-code tool from <a href="http://bubble.io/" rel="nofollow">Bubble</a> includes several features that let human users do more than just chat. A full visual editor lets developers adjust the interface directly. A workflow view outlines much of what’s going on underneath, again making it possible for the user to do more than guess. The goal is to make humans more of a partner.</p>



<h2 class="wp-block-heading">Claude Code</h2>



<p>Anthropic’s main LLM, <a href="https://claude.com/product/claude-code" rel="nofollow">Claude</a>, is skilled in answering many programming needs, including either creating new applications or fixing old ones. The backend connects to many traditional IDEs, such as VSCode, but many users connect with Claude through a terminal window or even a Slack channel. One common use is to search through a large code base for the right place to begin fixing an issue. Many praise how it adapts to your local coding standards.</p>



<h2 class="wp-block-heading">Continue</h2>



<p>The <a href="https://github.com/continuedev/continue" rel="nofollow">open-source agent from Continue</a> is best for professional developers who need a bit of extra help vibe coding. The tool will watch a code base for triggers, such as new pull releases, and then invoke AI agents to handle many of the chores. The goal isn’t to do everything, just the most boring things, so humans can be creative. The tool integrates with many IDEs and AI APIs.</p>



<h2 class="wp-block-heading">Create</h2>



<p>The tool from <a href="http://create.xyz/" rel="nofollow">Create.xyz</a> is called Anything because they want users to be able to create any possible React/Tailwind app from a simple text prompt. The results are crafted from many stylized components for tasks such as database access that run well in either the browser or a mobile platform. Developers can then dive into the code and add any human touches.</p>



<h2 class="wp-block-heading">Cursor</h2>



<p>Many old-school developers love <a href="https://cursor.com/" rel="nofollow">Cursor</a> because it’s designed to be the assistant they’ve never had. It writes new code, audits old code, and tracks issues evolving over channels like Slack. The tool can juggle multiple files and analyze entire codebases before proposing a plan of action and then executing it. It’s not exactly fair to call it “no-code” because it’s designed to work in a traditional development environment, but many users aren’t writing much code anymore because Cursor does so much.</p>



<h2 class="wp-block-heading">Emergent</h2>



<p>The web application from <a href="http://emergent.sh/" rel="nofollow">Emergent</a> is a front-end for a team of AI agents that will turn your text description into a frontend (React), backend (Node.js), databases (MongoDB), and collection of APIs with full integrations (Stripe, etc.).The goal is not just to perform hand-holding, but to hide all the complexity of development behind a big facade. Non-developers can build everything they want while developers can knock off prototypes — all deployed in close to production-ready form.</p>



<h2 class="wp-block-heading">Kilo Code</h2>



<p>The open-source coding agent from <a href="https://kilo.ai/" rel="nofollow">Kilo</a> has a number of features that will appeal to coders maintaining and extending larger code bases. Orchestrator Mode, for instance, helps create work plans while Code Review double checks for errors. A Memory Bank stores high-level details about the project’s architecture. Connections to more than 500 models avoids lock in and lets you choose the right model that’s delivering just what you want.</p>



<h2 class="wp-block-heading">Lindy</h2>



<p>The tool from <a href="https://www.lindy.ai/" rel="nofollow">Lindy</a> focuses on creating “agents” that tend to be bits of code that sit in the background and respond to triggers like a Slack message or a new commit to a repository. There are hundreds of different web applications that can generate these events, including all major clouds and office organization sites such as Jira or Zoho. Many of the standard applications can be built more quickly by leveraging pre-defined templates. Some of the most common use cases include support agents.</p>



<h2 class="wp-block-heading">Lovable</h2>



<p>The no-code interface from <a href="https://lovable.dev/" rel="nofollow">Lovable</a> chats with you for a bit and then builds the app and deployment in Lovable’s cloud. It handles the UI (React plus Tailwind), business logic, and database (mainly Supabase). The result is one of the fastest ways to spin up an enterprise-ready prototype with a fairly polished interface and many of the security and access control features required for bigger environments.</p>



<h2 class="wp-block-heading">Replit</h2>



<p>The no-code solution from <a href="https://replit.com/" rel="nofollow">Replit</a> delivers code in up to 30 programming languages, supporting all the major languages and many of the minor ones. The main interface is a no-code chatbot, but after that it dumps the code in a repository where it can be further refined using traditional methods. The database layer is broken out and treated separately, which allows for a more traditional approach by enabling options such as a separate database for production and testing. There are enterprise features that allow a team to collaborate as they chat together to improve the app.</p>



<h2 class="wp-block-heading">Softgen</h2>



<p>The tool for creating full Next.js web apps from <a href="https://softgen.ai/" rel="nofollow">Softgen</a> works with several of the major models, such as Claude 4.5 or Gemini, to turn a basic text description into a full minimum viable product. A pay-as-you-go option allows you to pay for only the tokens your application requires.</p>



<h2 class="wp-block-heading">Solid</h2>



<p>Creating basic applications isn’t too hard anymore. <a href="https://trysolid.com/" rel="nofollow">Solid</a> emphasizes creating apps that offer “enterprise-grade” deployments with top-notch security models and distributed deployment. The documentation emphasizes working iteratively with the AI and playing to its strengths, which is crafting a React/Tailwind front end with a wide variety of backends that generally mean TypeScript code running on Node.js with PostgreSQL.</p>



<h2 class="wp-block-heading">Tempo Labs</h2>



<p>The visual editor from Tempo Labs aims to allow human users to create a React app ten times faster. Simple visual tasks can be performed without relying on the AI. The tool emphasizes design and maintains a library of standard elements for each project. Any React code base can be imported and extended with predeveloped components and templates. It’s an editor that lets you vibe.</p>



<h2 class="wp-block-heading">Vercel</h2>



<p>The<a href="https://v0.app/" rel="nofollow"> v0 system </a>from Vercel offers a large collection of templates as a foundation for any app designer. The main interface is still a chat box that accepts any designs, but the templates act as both inspiration and a shared language for writing the specifications. There are also design templates that make it simpler to harmonize several different applications by allowing you to define a look once and then reuse it easily. The templates are also focused on mobile browsers to make it simpler to create mobile-ready sites.</p>



<h2 class="wp-block-heading">Windsurf</h2>



<p>Teams working with big code bases can use <a href="https://windsurf.com/" rel="nofollow">Windsurf</a>, an IDE with embedded AI that’s designed to handle longer, multi-step plans for fixing bugs or adding features to a code base. It’s vibe coding, but focused on assisting traditional techniques. The tab key in the Windsurf IDE is quite powerful. As you hit the tab key, it moves from suggested fix to suggested fix waiting for you to signal your approval by hitting it again. The IDE aims to produce multistep plans that it calls “cascades.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The front-end architecture trilemma: Reactivity vs. hypermedia vs. local-first apps]]></title>
<description><![CDATA[While the software development industry has been gorging on large language models (LLMs), the front-end ecosystem has quietly fractured into three competing but interrelated architectural paradigms. Between the dominance of reactive frameworks, the hypermedia-driven simplicity of true REST, and t...]]></description>
<link>https://tsecurity.de/de/3470575/ai-nachrichten/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3470575/ai-nachrichten/the-front-end-architecture-trilemma-reactivity-vs-hypermedia-vs-local-first-apps/</guid>
<pubDate>Tue, 28 Apr 2026 11:17:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>While the software development industry has been gorging on <a href="https://www.infoworld.com/article/2335213/large-language-models-the-foundations-of-generative-ai.html">large language models</a> (LLMs), the front-end ecosystem has quietly fractured into three competing but interrelated architectural paradigms. Between the dominance of <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">reactive frameworks</a>, the <a href="https://www.infoworld.com/article/4150864/htmx-4-0-hypermedia-finds-a-new-gear.html">hypermedia-driven simplicity</a> of true REST, and the decentralized resilience of <a href="https://www.infoworld.com/article/4140734/the-revenge-of-sql-how-a-50-year-old-language-reinvents-itself.html">SQL everywhere</a>, developers are no longer just choosing a library, they are choosing where the data lives: at the server, at the client, or both.</p>



<h2 class="wp-block-heading"><a></a>Three competing architectures, more or less</h2>



<p>Web developers are long familiar with <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html">React</a> and the galaxy of similar reactive frameworks like <a href="https://www.infoworld.com/article/3962039/what-you-need-to-know-about-angular-react-vue-and-svelte-popular-javascript-frameworks-compared.html">Angular, Vue, and Svelte</a>. For nearly a decade, these have dominated the narrative with their competition and co-inspiration. HTMX and hypermedia-driven applications have championed a return to the true RESTful thin client, alongside alternatives like Hotwire and Unpoly.</p>



<p>We could in a sense see reactivity and hypermedia as two opposing camps. Somewhere in between is the local-first SQL movement, which proposes putting SQL directly in the browser. The waters are a bit muddy because local SQL can and does work right alongside React.</p>



<p>It’s still safe to say that a reactive framework paired with a JSON API back end that talks to a datastore (SQL or otherwise) is still the de facto standard. But that monolithic story is starting to fracture in some very interesting ways.</p>



<h2 class="wp-block-heading"><a></a>Where the weight of the data lies</h2>



<p>Data of course is the central mass of web applications. Where it lives and how it moves produce the gravity around which everything else must revolve. Each of these architectures proposes to handle that gravity in its own way, with different benefits and tradeoffs.</p>



<p><strong>Hypermedia (e.g., HTMX):</strong> Keep the data largely off the client. The client is just a visual representation of the server data. The back-end “API” is responsible for producing the data-driven markup. Any kind of datastore can be used by the API server.</p>



<p><strong>React and friends:</strong> A sophisticated, stateful engine runs in the client, and the developer syncs that state with the back end via RESTful JSON API calls. The back-end server tends to be dumb, responsible largely for just invoking other services to provide business logic or data persistence.</p>



<p><strong>Local-first SQL: </strong>The data is distributed to the clients, like with React and friends, but in a much different way. Although the data is automatically synced directly to a datastore (like Postgres), the back-end API server is used only for specialized service calls—not for data persistence.</p>



<p>To summarize:</p>



<ul class="wp-block-list">
<li><strong>HTMX:</strong> Data gravity is at the server.</li>



<li><strong>React:</strong> Data gravity is split between the server and the client.</li>



<li><strong>Local-first:</strong> Data gravity is at the client.</li>
</ul>



<h2 class="wp-block-heading"><a></a>Comparing the approaches</h2>



<p>Besides the technical stats, the developer experience for each of these paradigms is quite different. However, while each paradigm feels different, they intersect in some interesting ways. Let’s take a closer look.</p>



<h3 class="wp-block-heading"><a></a>React and friends</h3>



<p><a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">Reactivity</a> is the world we have been working in for 15 years. We’ve got a whole universe of frameworks: <a href="https://react.dev/">React</a>, <a href="https://angular.dev/">Angular</a>, <a href="https://vuejs.org/">Vue</a>, <a href="https://svelte.dev/">Svelte</a>, <a href="https://www.solidjs.com/">Solid</a>, and full-stack variants like <a href="https://nextjs.org/">Next.js</a>, <a href="https://nuxt.com/">Nuxt</a>, <a href="https://svelte.dev/docs/kit/introduction">SvelteKit</a>, <a href="https://astro.build/">Astro</a>, etc. The beauty of these is in the <a href="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html" data-type="link" data-id="https://www.infoworld.com/article/2335507/reactive-javascript-the-evolution-of-front-end-architecture.html">core reactive idea</a>. You have a state that consists of the variables and the UI is updated automatically. The UI is a pure function of state: <code>$UI = f(state)</code>.</p>



<p>The downside is the gradual, almost imperceptible <a href="https://www.infoworld.com/article/4145032/we-mistook-event-handling-for-architecture.html">layering of intense complexity</a> over the top of it all. This complexity seems at first just incidental, but it is in fact a direct outcome of the basic premise: building a state engine on the browser.</p>



<p>The result is you have <em>two </em>states: the browser and the database. The reactive engine becomes a negotiation layer. Add to that the various inherent complexities of managing the browser state, and the result is quite a lot for front-end developers to wrap their heads around.</p>



<p>In the effort to manage such complexity, wring more performance, and improve developer experience, we have wound up with quite a sprawling empire of tools and techniques. Even just for React we have <a href="https://react.dev/reference/rsc/server-components">React Server Components</a>, complex state-management libraries like <a href="https://redux.js.org/">Redux</a> or <a href="https://zustand.docs.pmnd.rs/learn/getting-started/introduction">Zustand</a>, and orchestration layers like <a href="https://tanstack.com/query/latest">TanStack Query</a> for manual cache invalidation.</p>



<p>On the back end, we talk to <a href="https://www.infoworld.com/article/2255837/what-is-json-a-better-format-for-data-exchange.html">JSON APIs</a> (or <a href="https://www.infoworld.com/article/2267992/what-is-graphql-better-apis-by-design.html">GraphQL</a>), which can become unwieldy as a kind of boilerplate layer, but has in its favor an almost universal understanding.</p>



<h3 class="wp-block-heading">HTMX and similar (Hotwired, Unpoly)</h3>



<p><a href="https://www.infoworld.com/article/2334868/htmx-dynamic-html-without-the-javascript.html">HTMX</a> is like using HTML that has superpowers. You can do a huge amount of what you use reactive frameworks for, including all the AJAX and a lot of the partial rendering and effects, with just a few extra attributes sprinkled judiciously.</p>



<p>You spend a lot of time on the server, using a template engine like <a href="https://github.com/pugjs/pug">Pug</a>, <a href="https://www.thymeleaf.org/">Thymeleaf</a>, or <a href="https://github.com/Kotlin/kotlinx.html">Kotlin DSL</a>. These are where you bring together the data from the persistence service and combine it with markup. The markup you generate includes the HTMX attributes.</p>



<p>You tend to decompose the templates, i.e., break them up into dedicated chunks. The idea is you want to have a chunk that can be used within the larger UI to create the whole layout, along with the ability to use that chunk alone when (and if) it is called upon for an AJAX response.</p>



<p>Hypermedia with HTMX is a very powerful model. You are actually using REST, meaning you are transmitting a representational state.</p>



<p><a href="https://hotwired.dev/">Hotwire</a> and <a href="https://unpoly.com/">Unpoly</a> are similar libraries. In the case of Hotwire, you can achieve quite a bit of functionality and performance even without changing your HTML, just by using <a href="https://turbo.hotwired.dev/handbook/frames">Turbo Frames</a> to intercept link clicks and form submissions, automatically turning standard page navigation into partial DOM updates.</p>



<p>The beauty of the hypermedia approaches is that you gain a lot with a little. You are staying as much as possible in HTML, the very poster child of simplicity. On the other hand, you are giving up some of the sheer sophisticated power of reactive frameworks.</p>



<h3 class="wp-block-heading"><a></a>Local-first apps</h3>



<p>Local-first development is the new kid on the block. Like React and friends, local-first keeps the data in two places, but it does so in a radically different way. In its most essential form, it means running a database in the browser that is kept aligned with the remote datastore via a syncing engine. This kind of thing has been done before with <a href="https://www.infoworld.com/article/2260280/what-is-nosql-databases-for-a-cloud-scale-future.html">NoSQL</a> databases like <a href="https://couchdb.apache.org/">CouchDB</a> or with the <a href="https://developer.mozilla.org/en-US/docs/Web/API/IndexedDB_API">IndexedDB API</a>, but the modern browser takes it to another level with a <a href="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html">Wasm</a>-based database engine, like SQLite.</p>



<p>The user gets a small view of the full data, called a partial replication or a bucket (also called a “shape”). The front-end app interacts directly with that data, and the infrastructure automatically does the work of keeping everything synced. A big benefit here is strong offline support (because the client device is carrying around an actual database).</p>



<p>This is a massive departure from the request-response cycle. In local-first, you don’t fetch data; you subscribe to it. The network becomes a background daemon that reconciles local and remote state using CRDTs (conflict-free replicated data types). CRDTs ensure that if two users edit a task while offline, the merge is seamless rather than messy.</p>



<p>There is also a degree of simplification in using SQL everywhere, though that is offset by a rather unfamiliar and involved architectural setup. A syncing engine like <a href="https://www.powersync.com/">PowerSync</a> or <a href="https://electric-sql.com/">Electric SQL</a> is required, and it has a set of rules that must be maintained. Plus the auth and interaction between the database and the syncing engine must be configured.</p>



<p>Local-first eliminates both the API server and the HTML template server. It pushes the entire data negotiation layer into the automated syncing engine that runs off developer-defined rules.</p>



<p>Interestingly, local-first SQL can be used as a data driver for React (and other reactive engines) or plain vanilla HTML + JS. As such, it is an interesting alternative take on the architecture of the web, which is agnostic about the front end.</p>



<p>Perhaps the strangest arrangement to contemplate is using HTMX and local-first SQL together. This is like a mad scientist architecture, which of course means developers are doing it. In this setup, the back-end HTMX template engine is actually a service worker running the SQL engine. In theory, you get the simplicity of HTMX and the ultra-speed + offline functionality of local SQL. </p>



<h2 class="wp-block-heading"><a></a>Reactivity, hypermedia, or local-first? How to choose</h2>



<p>We remain in the era of the default choice being React plus a JSON API. From there you might experiment with innovative frameworks like <a href="https://www.infoworld.com/article/2265950/hands-on-with-svelte.html">Svelte</a> or <a href="https://www.infoworld.com/article/2271109/hands-on-with-the-solid-javascript-framework.html">Solid</a>. If you are looking for an ingenious way to leverage RESTful simplicity, HTMX or Hotwired are must-tries. Local-first SQL is an exotic animal, fit for the likes of <a href="https://linear.app/now/scaling-the-linear-sync-engine">Linear</a> or <a href="https://www.notion.com/blog/how-we-made-notion-available-offline">Notion</a> right now, but somewhat daring for most of us doing standard production work.</p>



<p>More broadly, the emergence of this trilemma signals the end of the “one true way” for web development. We are moving away from the library wars and into a world of architectural choice.</p>



<p>The choice between reactivity, hypermedia, and local-first isn’t just about code. It’s about where you want to place the data.</p>



<ul class="wp-block-list">
<li>If you want the data to be a server-side document, choose hypermedia.</li>



<li>If you want the data to be a shared memory state, choose reactivity.</li>



<li>If you want the data to be a distributed database, choose local-first.</li>
</ul>



<p>And of course, it is possible to put the approaches together to strive for a blend of the right benefits for your project.</p>



<p>As the JSON-over-the-wire monolith continues to fragment, the best architects won’t be the ones who know the most hooks or the most attributes. They will be the ones who understand the weight of their data and choose the architecture that lets the data move most freely. The framework wars are over, but the battle for the network has just begun. </p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Uplink 2026 - Expanding Processing’s Future With a Rust Rendering Engine]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 2x - Views:11 https://media.ccc.de/v/lgm-2026-110668-expanding-processing-s-future-with-a-rust-rendering-engine

Processing is one of the most influential approaches to creative coding and computer science education. Since its first release in 2001, it has popula...]]></description>
<link>https://tsecurity.de/de/3461558/it-security-video/uplink-2026-expanding-processings-future-with-a-rust-rendering-engine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3461558/it-security-video/uplink-2026-expanding-processings-future-with-a-rust-rendering-engine/</guid>
<pubDate>Fri, 24 Apr 2026 15:02:04 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 2x - Views:11 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/w1boKF_pwf0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>https://media.ccc.de/v/lgm-2026-110668-expanding-processing-s-future-with-a-rust-rendering-engine<br />
<br />
Processing is one of the most influential approaches to creative coding and computer science education. Since its first release in 2001, it has popularized methodologies centered on visual feedback, iterative experimentation, and immediate creative expression—making programming accessible to students, artists, and designers who might not see themselves as “coders.”<br />
<br />
After 25 years the technological landscape has expectedly completely shifted. We live in a world of graphics APIs designed around modern GPU hardware design and new use cases like GPGPU. LLVM has enabled many programming languages to run on many architectures, and WASM means your compiled code can run in the browser.<br />
<br />
Come to this technical talk to learn about how we are solving many longstanding technical challenges with an elegant architectural decision. Find out how our desire to bring modern rendering into Processing meaningfully expanded the potentialities of our project by tapping into the rich Rust ecosystem, and the Bevy game engine.<br />
<br />
Moon Davé<br />
<br />
https://pretalx.c3voc.de/lgm-2026/talk/GVYNF9/<br />
<br />
#lgm2026<br />
<br />
Licensed to the public under https://creativecommons.org/licenses/by/4.0/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Expanding Processing’s Future With a Rust Rendering Engine (lgm2026)]]></title>
<description><![CDATA[Processing is one of the most influential approaches to creative coding and computer science education. Since its first release in 2001, it has popularized methodologies centered on visual feedback, iterative experimentation, and immediate creative expression—making programming accessible to stud...]]></description>
<link>https://tsecurity.de/de/3461530/it-security-video/expanding-processings-future-with-a-rust-rendering-engine-lgm2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3461530/it-security-video/expanding-processings-future-with-a-rust-rendering-engine-lgm2026/</guid>
<pubDate>Fri, 24 Apr 2026 14:48:11 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Processing is one of the most influential approaches to creative coding and computer science education. Since its first release in 2001, it has popularized methodologies centered on visual feedback, iterative experimentation, and immediate creative expression—making programming accessible to students, artists, and designers who might not see themselves as “coders.”

After 25 years the technological landscape has expectedly completely shifted. We live in a world of graphics APIs designed around modern GPU hardware design and new use cases like GPGPU. LLVM has enabled many programming languages to run on many architectures, and WASM means your compiled code can run in the browser.

Come to this technical talk to learn about how we are solving many longstanding technical challenges with an elegant architectural decision. Find out how our desire to bring modern rendering into Processing meaningfully expanded the potentialities of our project by tapping into the rich Rust ecosystem, and the Bevy game engine.

Licensed to the public under https://creativecommons.org/licenses/by/4.0/
about this event: https://pretalx.c3voc.de/lgm-2026/talk/GVYNF9/]]></content:encoded>
</item>
<item>
<title><![CDATA[WebAssembly im Check]]></title>
<description><![CDATA[WebAssembly (Wasm) ermöglicht es, Anwendungen direkt im Browser auszuführen. Die Technologie gilt daher als wichtige Ergänzung zu JavaScript und eröffnet neue Möglichkeiten für performante Webanwendungen. Doch wie funktioniert WebAssembly genau und welche Vorteile bietet es? In diesem Artikel erh...]]></description>
<link>https://tsecurity.de/de/3454858/server/webassembly-im-check/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3454858/server/webassembly-im-check/</guid>
<pubDate>Wed, 22 Apr 2026 14:47:23 +0200</pubDate>
<category>🐧 Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://www.ionos.de/digitalguide/fileadmin/DigitalGuide/Teaser/backlinks-aufbauen.jpg" width="1200" height="630" alt=""><br>WebAssembly (Wasm) ermöglicht es, Anwendungen direkt im Browser auszuführen. Die Technologie gilt daher als wichtige Ergänzung zu JavaScript und eröffnet neue Möglichkeiten für performante Webanwendungen. Doch wie funktioniert WebAssembly genau und welche Vorteile bietet es? In diesem Artikel erhalten Sie eine verständliche Einführung in die Grundlagen, die Funktionsweise und typische Einsatzbereiche.]]></content:encoded>
</item>
<item>
<title><![CDATA[Exciting Python features are on the way]]></title>
<description><![CDATA[Transformative new Python features are coming in Python 3.15. In addition to lazy imports and an immutable frozendict type, the new Python release will deliver significant improvements to the native JIT compiler and introduce a more explicit agenda for how Python will support WebAssembly.



Top ...]]></description>
<link>https://tsecurity.de/de/3441427/ai-nachrichten/exciting-python-features-are-on-the-way/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3441427/ai-nachrichten/exciting-python-features-are-on-the-way/</guid>
<pubDate>Fri, 17 Apr 2026 11:33:26 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Transformative new Python features are coming in <a href="https://docs.python.org/3.15/whatsnew/3.15.html#">Python 3.15</a>. In addition to lazy imports and an immutable <code>frozendict</code> type, the new Python release will deliver significant improvements to the <a href="https://www.infoworld.com/article/4110565/get-started-with-pythons-new-native-jit.html">native JIT compiler</a> and introduce a more explicit agenda for how Python will support <a href="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html" data-type="link" data-id="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html">WebAssembly</a>.</p>



<h2 class="wp-block-heading">Top picks for Python readers on InfoWorld</h2>



<p><a href="https://www.infoworld.com/article/4145854/speed-boost-your-python-programs-with-new-lazy-imports.html" data-type="link" data-id="https://www.infoworld.com/article/4145854/speed-boost-your-python-programs-with-new-lazy-imports.html">Speed-boost your Python programs with the new lazy imports feature</a><br>Starting with Python 3.15, Python imports can work lazily, deferring the cost of loading big libraries. And you don’t have to rewrite your Python apps to use it.</p>



<p><a href="https://www.infoworld.com/article/4150052/how-python-is-getting-serious-about-wasm.html" data-type="link" data-id="https://www.infoworld.com/article/4150052/how-python-is-getting-serious-about-wasm.html">How Python is getting serious about Wasm</a><br>Python is slowly but surely becoming a first-class citizen in the WebAssembly world. A new Python Enhancement Proposal, PEP 816, describes how that will happen.</p>



<p><a href="https://www.infoworld.com/article/4152654/get-started-with-pythons-new-frozendict-type.html" data-type="link" data-id="https://www.infoworld.com/article/4152654/get-started-with-pythons-new-frozendict-type.html">Get started with Python’s new frozendict type</a><br>A new immutable dictionary type in Python 3.15 fills a long-desired niche in Python — and can be used in more places than ordinary dictionaries.</p>



<p><a href="https://www.infoworld.com/article/2258733/how-to-use-python-dataclasses.html" data-type="link" data-id="https://www.infoworld.com/article/2258733/how-to-use-python-dataclasses.html">How to use Python dataclasses</a><br>Python dataclasses work behind the scenes to make your Python classes less verbose and more powerful all at once.</p>



<h2 class="wp-block-heading">More good reads and Python updates elsewhere</h2>



<p><a href="https://blog.python.org/2026/04/rust-for-cpython-2026-04" data-type="link" data-id="https://blog.python.org/2026/04/rust-for-cpython-2026-04">Progress on the “Rust for CPython” project</a><br>The plan to enhance the Python interpreter by using the Rust language stirred controversy. Now it’s taking a new shape: use Rust to build components of the Python standard library.</p>



<p><a href="https://adamj.eu/tech/2026/04/03/python-introducing-profiling-explorer" data-type="link" data-id="https://adamj.eu/tech/2026/04/03/python-introducing-profiling-explorer">Profiling-explorer: Spelunk data generated by Python’s profilers</a><br>Python’s built-in profilers generate reports in the opaque pstats format. This tool turns those binary blobs into interactive, explorable views.</p>



<p><a href="https://lwn.net/Articles/1064693" data-type="link" data-id="https://lwn.net/Articles/1064693">The many failures that led to the LiteLLM compromise</a><br>How did a popular Python package for working with multiple LLMs turn into a vector for malware? This article reveals the many weak links that made it possible. </p>



<p><a href="https://armanckeser.com/writing/jellyfin-flow" data-type="link" data-id="https://armanckeser.com/writing/jellyfin-flow">Slightly off-topic: Why open source contributions sit untouched for months on end</a><br>CPython has more than 2,200 open pull requests. The fix, according to this blog, isn’t adding more maintainers, but “changing how work flows through the one maintainer you have.” </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[VirusTotal Inside the Agent Loop]]></title>
<description><![CDATA[At VirusTotal, we are closely following how AI agents are evolving and how we can be useful in that space. Part of that is analysis: the new generation of AI-native artifacts (skills, plugins, IDE extensions, agent configs) that attackers are starting to weaponize as supply-chain vectors. The oth...]]></description>
<link>https://tsecurity.de/de/3439223/malware-trojaner-viren/virustotal-inside-the-agent-loop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3439223/malware-trojaner-viren/virustotal-inside-the-agent-loop/</guid>
<pubDate>Thu, 16 Apr 2026 17:03:28 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>At VirusTotal, we are closely following how AI agents are evolving and how we can be useful in that space. Part of that is analysis: the new generation of AI-native artifacts (skills, plugins, IDE extensions, agent configs) that attackers are starting to weaponize as supply-chain vectors. The other is access: making VirusTotal usable from inside agents, so reputation and Code Insight become part of their decisions, not something a human checks afterwards.</p>
<p>This post focuses on that second part.</p>
<p>Two small experiments, both published under king-tero, the GitHub account of my personal AI agent, which does community tooling on the side. There's a small recursion here: an AI agent writing security plugins for AI agent ecosystems.</p>
<ul>
  <li>
    VT-sentinel (OpenClaw plugin)
    <a href="https://github.com/king-tero/VT-sentinel">https://github.com/king-tero/VT-sentinel</a>
    <ul>
      <li><code>openclaw plugins install clawhub:openclaw-plugin-vt-sentinel</code></li>
    </ul>
  </li>
  <li>
    hermes-virustotal (Hermes plugin)
    <a href="https://github.com/king-tero/hermes-virustotal">https://github.com/king-tero/hermes-virustotal</a>
    <ul>
      <li><code>hermes plugins install king-tero/hermes-virustotal</code></li>
    </ul>
  </li>
</ul>
<p>They're community projects, not official VirusTotal releases, MIT-licensed, and works in progress. They are built on top of the new VirusTotal API for AI agents (VTAI), which is designed specifically for this use case and brings two practical advantages: responses are compact and usable inside an LLM context, and agents have their own identity and audit trail.</p>

<p>Both plugins follow the same idea: put reputation where decisions happen. The agent does not need to look things up separately. The verdict and context are already there, next to the file it is about to use.</p>

<h2>VT-sentinel for OpenClaw</h2>

<p>VT-sentinel watches the directories the agent actually uses (<code>Downloads</code>, <code>/tmp</code>, workspace) and scans files with VirusTotal and Code Insight as they appear. Known-bad files can be quarantined, and suspicious executions blocked.</p>

<p>A few details:</p>

<ul>
  <li>Instruction files (<code>SKILL.md</code>, <code>HOOK.md</code>, <code>AGENTS.md</code>, etc.) default to hash-only lookups. Private prompts are not auto-uploaded.</li>
  <li>Sensitive content (PDFs, Office docs, unknown archives) defaults to explicit per-category consent before upload.</li>
  <li>Nine tools register with the gateway (<code>vt_scan_file</code>, <code>vt_check_hash</code>, <code>vt_sentinel_status</code>, <code>vt_sentinel_configure</code>, …), so both the agent and the user can query state on demand.</li>
  <li>Three presets (<code>balanced</code>, <code>privacy_first</code>, <code>strict_security</code>) cover a reasonable range of risk appetites.</li>
</ul>

<h2>hermes-virustotal for the Hermes agent</h2>

<p>hermes-virustotal takes a slightly different angle. It's a plugin for the Hermes agent that:</p>

<ul>
  <li>Exposes <code>vt_check_hash</code> and <code>vt_check_file</code> as explicit tools the model can call.</li>
  <li>Hooks <code>pre_tool_call</code> so anything written via <code>write_file</code>, <code>patch</code>, or <code>execute_code</code> is hashed, recorded, and annotated with its VirusTotal verdict.</li>
  <li>Hooks <code>pre_llm_call</code> to inject a compact advisor block into the model's context: recent paths, hashes, verdicts, and Code Insight snippets, scoped to the current session and aged out when stale.</li>
</ul>

<p>The upload policy is sensible: binaries (ELF, PE, Mach-O, WASM, Java class, DEX) are auto-submitted so the community can analyze potential new malware; scripts, source, markdown and text are never auto-uploaded; archives are opt-in; and there's a built-in blocklist covering <code>.env*</code>, <code>*.key</code>, <code>*.pem</code>, <code>id_rsa*</code>, <code>.ssh/*</code> and similar paths. By default it fails open (the agent keeps working if VT is unreachable) and <code>VTAI_ENFORCE_KNOWN_MALICIOUS=1</code> turns on hard blocking, limited to exact hashes VirusTotal has already flagged.</p>

<h2>This space is still early</h2>

<p>If you are running OpenClaw or Hermes and want VirusTotal inside the agent loop, try them. Break them. Send PRs. More to come.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Is Aquila (Dmitry) from WASM Forum Community the Author of the Carberp Banking Malware?]]></title>
<description><![CDATA[Dear blog readers, I recently did something very interesting and I decided to share my results and findings. What I did was the following. While doing a  technical collection round for malicious software I came across to Carberp’s source where…
Read more →
The post Is Aquila (Dmitry) from WASM Fo...]]></description>
<link>https://tsecurity.de/de/3438974/it-security-nachrichten/is-aquila-dmitry-from-wasm-forum-community-the-author-of-the-carberp-banking-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3438974/it-security-nachrichten/is-aquila-dmitry-from-wasm-forum-community-the-author-of-the-carberp-banking-malware/</guid>
<pubDate>Thu, 16 Apr 2026 15:45:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Dear blog readers, I recently did something very interesting and I decided to share my results and findings. What I did was the following. While doing a  technical collection round for malicious software I came across to Carberp’s source where…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/is-aquila-dmitry-from-wasm-forum-community-the-author-of-the-carberp-banking-malware/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/is-aquila-dmitry-from-wasm-forum-community-the-author-of-the-carberp-banking-malware/">Is Aquila (Dmitry) from WASM Forum Community the Author of the Carberp Banking Malware?</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rust team warns of WebAssembly change]]></title>
<description><![CDATA[WebAssembly targets for Rust will soon face a change that could risk breaking existing projects, according to an April 4 bulletin in the official Rust blog. The bulletin notes that all WebAssembly targets in Rust have been linked using the --allow-undefined flag to wasm-ld, but this flag is being...]]></description>
<link>https://tsecurity.de/de/3412756/ai-nachrichten/rust-team-warns-of-webassembly-change/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3412756/ai-nachrichten/rust-team-warns-of-webassembly-change/</guid>
<pubDate>Tue, 07 Apr 2026 07:17:30 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html">WebAssembly</a> targets for <a href="https://www.infoworld.com/article/2255250/what-is-rust-safe-fast-and-easy-software-development.html">Rust</a> will soon face a change that could risk breaking existing projects, according to an <a href="https://blog.rust-lang.org/2026/04/04/changes-to-webassembly-targets-and-handling-undefined-symbols/">April 4 bulletin</a> in the official Rust blog. The bulletin notes that all WebAssembly targets in Rust have been linked using the <code>--allow-undefined</code> flag to <code>wasm-ld</code>, but this flag is being removed.</p>



<p>Removing <code>--allow-undefined</code> on wasm targets is being done in <a href="https://github.com/rust-lang/rust/pull/149868">rust-lang/rust#149868</a>. That change is slated to land in nightly builds soon and will be released with Rust 1.96 on 2026-05-28. The bulletin explains that all WebAssembly binaries in Rust are created by linking with <code>wasm-ld</code>, thus serving a similar purpose to <code>ld</code>, <code>lld</code>, and <code>mold</code>. Since the first introduction of WebAssembly targets in Rust, the <code>--allow-undefined</code> flag has been passed to <code>wasm-ld</code>. </p>



<p>However, by passing <code>--allow-undefined</code> on all WebAssembly targets, rustc introduces diverging behavior between other platforms and WebAssembly, the bulletin says. The main risk of <code>--allow-undefined</code> is that misconfiguration or mistakes in building can result in broken WebAssembly modules being produced, as opposed to compilation errors. The bulletin lists the following example problematic situations:</p>



<ul class="wp-block-list">
<li>If <code>mylibrary_init</code> was mistakenly typed as <code>mylibraryinit</code>, then the final binary would import the <code>mylibraryinit</code> symbol instead of calling the linked <code>mylibrary_init</code> C symbol.</li>



<li>If <code>mylibrary</code> was mistakenly not compiled and linked into a final application, then the <code>mylibrary_init</code> symbol would end up imported rather than producing a linker error saying it’s undefined.</li>



<li>If external tools are used to process a WebAssembly module, such as <code>wasm-bindgen</code> or <code>wasm-tools component new</code>, they are likely to provide an error message that isn’t clearly connected back to the original source code from which the symbols were imported.</li>



<li>Web errors along the lines of <code>Uncaught TypeError: Failed to resolve module specifier "env". Relative references must start with either "/", "./", or "../".</code>can mean that <code>"env"</code> leaked into the final module unexpectedly and the true error is the undefined symbol error, not the lack of <code>"env"</code> items provided.</li>
</ul>



<p>All native platforms consider undefined symbols to be an error by default. Therefore, by passing <code>--allow-undefined</code> rustc introduces surprising behavior on WebAssembly targets. The goal of the change is to remove this surprise so that WebAssembly behaves more like native platforms, the bulletin states. </p>



<p>In theory, however, not a lot is expected to break from this change, the bulletin concludes. If the final WebAssembly binary imports unexpected symbols, then it’s likely the binary won’t be runnable in the desired embedding, as the desired embedding probably doesn’t provide the symbol as a definition. Therefore, most of the time this change will not break users, but will instead provide better diagnostics. </p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[[$] Pandoc: a workhorse for document conversion]]></title>
<description><![CDATA[Pandoc is a document-conversion program
that can translate among  a myriad of formats, including LaTeX, HTML, Office Open XML
(docx), plain text, and Markdown. It is also
extensible by writing Lua
filters that can manipulate the document structure and perform arbitrary
computations.
Pandoc has ap...]]></description>
<link>https://tsecurity.de/de/3399785/linux-tipps/pandoc-a-workhorse-for-document-conversion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3399785/linux-tipps/pandoc-a-workhorse-for-document-conversion/</guid>
<pubDate>Wed, 01 Apr 2026 16:53:17 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://pandoc.org/">Pandoc</a> is a document-conversion program
that can translate among  a myriad of formats, including <a href="https://www.latex-project.org/">LaTeX</a>, HTML, <a href="https://en.wikipedia.org/wiki/Office_Open_XML">Office Open XML</a>
(docx), plain text, and <a href="https://en.wikipedia.org/wiki/Markdown">Markdown</a>. It is also
extensible by writing <a href="http://www.lua.org/about.html">Lua</a>
filters that can manipulate the document structure and perform arbitrary
computations.
Pandoc has appeared in various LWN articles over the years, such as my <a href="https://lwn.net/Articles/1037577/">look at Typst</a> and at <a href="https://lwn.net/Articles/1023299/">the importance of free software to science</a> in
2025, but we have missed providing an overview of the tool.  The February <a href="https://github.com/jgm/pandoc/releases/3.9">release of Pandoc
3.9</a>, which comes with the ability to compile the program to <a href="https://webassembly.org/">WebAssembly</a> (Wasm), allowing Pandoc
to run in web browsers, will likely also be of interest.]]></content:encoded>
</item>
<item>
<title><![CDATA[PEP 816: How Python is getting serious about Wasm]]></title>
<description><![CDATA[WebAssembly, or Wasm, provides a standard way to deliver compact, binary-format applications that can run in the browser. Wasm is also designed to run at or near machine-native speeds. Developers can write code in one of the various languages that compile to Wasm as a target (e.g., Rust), and del...]]></description>
<link>https://tsecurity.de/de/3398701/ai-nachrichten/pep-816-how-python-is-getting-serious-about-wasm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3398701/ai-nachrichten/pep-816-how-python-is-getting-serious-about-wasm/</guid>
<pubDate>Wed, 01 Apr 2026 11:18:05 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><a href="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html">WebAssembly</a>, or Wasm, provides a standard way to deliver compact, binary-format applications that can run in the browser. Wasm is also designed to run at or near machine-native speeds. Developers can write code in one of the various languages that compile to Wasm as a target (e.g., <a href="https://www.infoworld.com/article/2258463/rust-tutorial-get-started-with-the-rust-language.html">Rust</a>), and deliver that program anywhere Wasm runs.</p>



<p>But Wasm by itself isn’t enough. An application, especially one running in a browser, needs standardized and controllable ways to talk to the rest of the system. <a href="https://www.w3.org/TR/wasm-core-2">The WebAssembly specification</a> doesn’t speak to any of that by design. It only describes the WebAssembly instruction set; not how programs using those instructions deal with the rest of the system.</p>



<p>That’s what the <a href="https://www.infoworld.com/article/2259897/mozillas-wasi-takes-webassembly-beyond-the-browser.html">WASI</a> standard provides—abstractions for using the host system, such as how to perform network and storage I/O, and using host resources like clocks or sources of entropy for PRNGs.</p>



<p>Until now, CPython has supported WASI, but not in a formally defined way. Nothing described <em>how</em> CPython would support versions of WASI (the spec), or the WASI SDK (an implementation of the spec). With <a href="https://peps.python.org/pep-0816/">PEP 816</a>, the CPython team has formally defined how to support both the spec and the SDK going forward. </p>



<p>Ultimately, the new definition will make it easier to deliver Python apps in the browser or anywhere else Wasm runs. There are just a few things developers need to know to ensure they’re using Wasm correctly with Python under the new rules.</p>



<h2 class="wp-block-heading">How Python has historically used Wasm</h2>



<p>Most languages, such as Rust, compile to Wasm as a binary target. Because Python is interpreted—at least, the default CPython implementation works that way—it doesn’t compile to Wasm directly. Instead, the <em>interpreter itself</em> is compiled to Wasm, and Python programs are run on that Wasm version of the interpreter.</p>



<p>There are drawbacks to this approach. For one, it means you need a full copy of the interpreter and the standard library to run <em>any</em> Python program. There is as yet no mechanism to compile a Python program for Wasm that would either include a copy of the interpreter or make it self-contained.</p>



<p>Another big drawback: Any modules not written in pure Python can’t run in Wasm unless a Wasm-specific version of that module is compiled ahead of time. Unless you have a specially compiled version of, say, <a href="https://www.infoworld.com/article/2336120/what-is-numpy-faster-array-and-matrix-math-in-python.html">NumPy</a>, you can’t use that module in Wasm.</p>



<p>Some of these issues are limitations of Python as a language. Its inherent dynamism makes it difficult to deploy a standalone program. Rust, by contrast, can compile to a single binary artifact for any supported target.</p>



<p>But some of these limits can also be attributed to the Wasm environment. For instance, many methods in the standard library <a href="https://docs.python.org/3.14/library/intro.html#webassembly-platforms">aren’t available in Wasm enviroments</a> because the WASI SDK doesn’t expose the needed interfaces for those methods. The more Python and other languages demand such things, the more likely they are to show up in the Wasm environment.</p>



<p>This is where it is useful for Python to be explicit about which versions it’ll use for both Wasm and its software development kit (or SDK) going forward. Each version of Python can then provide better guarantees about the Wasm features it supports.</p>



<h2 class="wp-block-heading">Wasm support in Python: WASI and the WASI SDK</h2>



<p>Wasm support involves two things: WASI and the WASI SDK. The difference between the two is a little like the difference between the Python language in the abstract and the CPython runtime. The former (WASI) is the <em>spec</em> for how Wasm programs interact with the host system, which can be implemented any number of ways. The latter (the WASI SDK) is the official <em>implementation</em> of that spec.</p>



<p>The WASI SDK is a modified version of the Clang compiler, which uses a library called <a href="https://github.com/WebAssembly/wasi-libc">wasi-libc</a>. This gives programs written in C (and C API-compatible languages) access to WASI’s APIs for the host (storage, networking, timers, etc).</p>



<p>In theory, we should just be able to compile a given CPython release with the most recent WASI SDK at the time. But things aren’t that simple. For one, the SDK’s biggest component, <code>wasi-libc</code>, doesn’t guarantee it’ll be forward- or backward-compatible. Also, some versions of the SDK may cause <a href="https://github.com/WebAssembly/wasi-libc/issues/617">buggy behavior with some versions of CPython</a>. As developers, we want to know that <em>this</em> version of CPython works with <em>this</em> version of the SDK—or at least be able to document which bugs appear with any given combination of the two.</p>



<h2 class="wp-block-heading">How future releases of CPython will use WASI</h2>



<p>CPython has been available on Wasm since version 3.11, with <a href="https://peps.python.org/pep-0011/#tier-2">Tier 2</a> and <a href="https://peps.python.org/pep-0011/#tier-3">Tier 3</a> support. The more official <code>wasip1</code> is the better-supported target, while the older <code>emscripten</code> standard is the less-supported version. But Tier 2 support has been confined to the WASI “Preview 1” set of system calls. And for the reasons already stated, the WASI SDK CPython uses is not necessarily the most recent version, either: it’s SDK version 21 for Python 3.11 and 3.12, and SDK version 24 for 3.13 and 3.14.</p>



<p>All of this will change with future releases of CPython, with a couple of hard rules in place for using WASI and its SDK:</p>



<ol class="wp-block-list">
<li>Any version of WASI or the WASI SDK supported by a given CPython version by its beta 1 release will be the version supported for the lifetime of that CPython release. For instance, if CPython 3.15 uses version 0.3 of the WASI spec and version 33 of the SDK (these are arbitrary numbers), then that version of WASI and the SDK will be supported for that version of CPython until it is formally sunsetted.</li>



<li>Any changes to the version of the WASI spec or SDK used for a particular release requires approval from Python’s steering council. But this shouldn’t happen outside of some extraordinary set of circumstances—for instance, if a bug surfaced that made a given version of the SDK unusable with a given CPython release.</li>
</ol>



<h2 class="wp-block-heading">The benefits of WASI version guarantees for CPython</h2>



<p>Going forward, developers can look forward to significant improvements to how Python will work with WASI:</p>



<ol class="wp-block-list">
<li>It won’t only be easier for CPython developers to know which versions of WASI and the SDK to target. It will also be easier for <em>the rest of the WASI ecosystem</em> to determine which Python versions are compatible with various WASI and SDK editions.</li>



<li>Developers maintaining Python libraries with extension modules will have a better idea of how to compile those modules to Wasm for each Python point release. They will then be able to take advantage of newer WASI features sooner, knowing that a specific CPython will support them.</li>



<li>Developers can add WASI support to their projects for a given version of CPython sooner in each release cycle for the interpreter, as the WASI and SDK versions should be locked down by the first beta release.</li>
</ol>



<p></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Open Source IFC viewer]]></title>
<description><![CDATA[I wrote an open source IFC viewer (open file format for construction purposes) that works on both Linux and Windows from the same code base. The UI is built on PyQt6, which then kicks off a nodejs/wasm process to extract data and geometry using WebIFC. The geometry is presented with three.js and ...]]></description>
<link>https://tsecurity.de/de/3394695/linux-tipps/open-source-ifc-viewer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3394695/linux-tipps/open-source-ifc-viewer/</guid>
<pubDate>Tue, 31 Mar 2026 04:07:53 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I wrote an open source IFC viewer (open file format for construction purposes) that works on both Linux and Windows from the same code base. The UI is built on PyQt6, which then kicks off a nodejs/wasm process to extract data and geometry using WebIFC. The geometry is presented with three.js and displayed in the UI using a webview component.</p> <p>This is still a dev preview, but work is well on its way to turn this into something useful.</p> <p>The design intent was to make an IFC viewer that's cross-platform, performs as fast as possible and to be extensible. I'm currently working on the API part, but right now it's already a very fast and simple viewer that can potentially work as the backbone for someone's future planning- and cost estimation solution.</p> <p>If you're interested, you can visit the repo on <a href="https://github.com/BIMtuitive/ifc-file-companion">https://github.com/BIMtuitive/ifc-file-companion</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Clogboy82"> /u/Clogboy82 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1s7vo1g/open_source_ifc_viewer/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1s7vo1g/open_source_ifc_viewer/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Midjourney engineer debuts new vibe coded, open source standard Pretext to revolutionize web design]]></title>
<description><![CDATA[For three decades, the web has existed in a state of architectural denial. It is a platform originally conceived to share static physics papers, yet it is now tasked with rendering the most complex, interactive, and generative interfaces humanity has ever conceived. At the heart of this tension l...]]></description>
<link>https://tsecurity.de/de/3394570/it-nachrichten/midjourney-engineer-debuts-new-vibe-coded-open-source-standard-pretext-to-revolutionize-web-design/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3394570/it-nachrichten/midjourney-engineer-debuts-new-vibe-coded-open-source-standard-pretext-to-revolutionize-web-design/</guid>
<pubDate>Tue, 31 Mar 2026 02:01:39 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For three decades, the web has existed in a state of architectural denial. It is a platform originally conceived to share static physics papers, yet it is now tasked with rendering the most complex, interactive, and generative interfaces humanity has ever conceived. </p><p>At the heart of this tension lies a single, invisible, and prohibitively expensive operation known as "<a href="https://gili842.medium.com/what-forces-layout-reflow-in-browsers-and-why-it-matters-18d868f05be1">layout reflow.</a>" Whenever a developer needs to know the height of a paragraph or the position of a line to build a modern interface, they must ask the browser’s <a href="https://www.freecodecamp.org/news/what-is-the-dom-explained-in-plain-english/">Document Object Model (DOM)</a>, the standard by which developers can create and modify webpages. </p><p>In response, the browser often has to recalculate the geometry of the entire page — a process akin to a city being forced to redraw its entire map every time a resident opens their front door.</p><p>L<!-- -->ast Friday, March 27, 2026, Cheng Lou — a prominent software engineer whose work on React, ReScript, and Midjourney has defined much of the modern frontend landscape — <a href="https://x.com/_chenglou/status/2037713766205608234">announced on the social network X</a> that he had "crawled through depths of hell" to release an <a href="https://github.com/chenglou/pretext">open source (MIT License) solution: Pretext</a>, which he coded using AI vibe coding tools and models like OpenAI's Codex and Anthropic's Claude.</p><div></div><p>It is a 15KB, zero-dependency TypeScript library that allows for multiline text measurement and layout entirely in "userland," bypassing the DOM and its performance bottlenecks. </p><p>Without getting too technical, in short, Lou's pretext turns text blocks on the web into fully dynamic, interactive and responsive spaces, able to adapt and smoothly move around any other object on a webpage, preserving letter order and spaces between words and lines, even when a user clicks and drags other objects to intersect with the text, or resizes their browser window dramatically. </p><p>Ironically, it's difficult with mere text alone to convey how significant Lou's latest release is for the entire web going forward. Fortunately, other developers whipped up quick demoes with Pretext showing off some of its more impressive powers, including <a href="https://x.com/Riyvir/status/2038093450139279426">dragon that flies around within a block of text</a>, breathing fire as the surrounding characters melt and are pushed out of the way from the dragon's undulating form.</p><div></div><p>Another<a href="https://x.com/mhauken/status/2038333454526320789"> guy made an app that requires</a> the user to keep their smartphone exactly level, horizontal to read the text — tipping the device to one side or the other causes all the letters to fall off and collect there as though they were each physical objects dumped off the surface of a flat tray. Some even coded up demoes allowing you to <a href="https://x.com/RazberryChai/status/2038309448679321727?s=20">watch a whole movie (the new <i>Project Hail Mary </i>starring Ryan Gosling) </a>while reading the book it is based on at the same time, all rendered out of interactive, moving, fast, responsive text.</p><p>While some detractors immediately pointed out that many of these flashy demoes make the underlying text unreadable or illegible, they're missing the larger point: with Pretext, one man (Lou) using AI vibe coding tools has singlehandedly revolutionized what's possible for <i>everyone </i>and<i> anyone </i>to do when it comes to web design and interactivity. The project hasn't even been out a week — of course the initial users are only scratching the surface of the newfound capabilities which heretofore required complex, custom instructions and could not be scaled or generalized. </p><p>Of course, designers and typographers may be the ones most immediately impressed and affected by the advance — but really, anyone who has spent time trying to lay out a block of text and wrap it around images or other embedded, interactive elements on a webpage is probably going to be interested in this. But anyone who <i>uses </i>the web — all <a href="https://www.yahoo.com/news/articles/internet-users-top-6-billion-182006688.html">6 billion and counting of us</a> — will likely experience some of the effects of this release before too long as it spreads to the sites we visit and use daily.  </p><p>And already, some developers are working <a href="https://x.com/LOliveirasousa/status/2038727424540590322">on more useful features with it</a>, like a custom user-controlled font resizer and letter spacing optimizer for those with dyslexia:</p><div></div><p>With that in mind, perhaps it is not suprising to learn that within 48 hours, the project garnered over <a href="https://github.com/chenglou/pretext">14,000 GitHub stars</a> and 19 million views on X, signaling what many believe to be a foundational shift in how we build the internet.</p><p>It also demonstrates that AI-assisted coding has moved beyond generating boilerplate to delivering fundamental architectural breakthroughs. For enterprises, this signifies a new era where high-leverage engineering teams can use AI to build bespoke, high-performance infrastructure that bypasses decades-old platform constraints, effectively decoupling product innovation from the slow cycle of industry-wide browser standardization</p><h2><b>The geometry of the bottleneck</b></h2><p>To understand why Pretext matters, one must understand the high cost of "measuring" things on the web. Standard browser APIs like <code>getBoundingClientRect</code> or <code>offsetHeight</code> are notorious for triggering layout thrashing.</p><p>In a modern interface—think of a masonry grid of thousands of text boxes or a responsive editorial spread—these measurements happen in the "hot path" of rendering. If the browser has to stop and calculate layout every time the user scrolls or an AI generates a new sentence, the frame rate drops, the battery drains, and the experience stutters.</p><p>Lou’s insight with Pretext was to decouple text layout from the DOM entirely. By using the browser’s Canvas font metrics engine as a "ground truth" and combining it with pure arithmetic, Pretext can predict exactly where every character, word, and line will fall without ever touching a DOM node. </p><p>The performance delta is staggering. According to project benchmarks, Pretext’s <code>layout()</code> function can process a batch of 500 different texts in approximately <b>0.09ms</b>. Compared to traditional DOM reads, this represents a <b>300–600x performance increase</b>. This speed transforms layout from a heavy, asynchronous chore into a synchronous, predictable primitive—one that can run at 120fps even on mobile devices.</p><h2><b>Technology: the prepare and layout split</b></h2><p>The elegance of Pretext lies in its two-stage execution model, designed to maximize efficiency:</p><ul><li><p><b><code>prepare(text, font)</code></b>: This is the one-time "heavy lifting" phase. The library normalizes whitespace, segments the text, applies language-specific glue rules, and measures segments using the canvas. This result is cached as an opaque data structure.</p></li><li><p><b><code>layout(preparedData, maxWidth, lineHeight)</code></b>: This is the "hot path". It is pure arithmetic that takes the prepared data and calculates heights or line counts based on a given width.</p></li></ul><p>Because <code>layout()</code> is just math, it can be called repeatedly during a window resize or a physics simulation without any performance penalty. It supports complex typographic needs that were previously impossible to handle efficiently in userland:</p><ul><li><p><b>Mixed-bidirectional (bidi) text</b>: Handling English, Arabic, and Korean in the same sentence without breaking layout.</p></li><li><p><b>Grapheme-aware breaking</b>: Ensuring that emojis or complex character clusters are not split across lines.</p></li><li><p><b>Whitespace control</b>: Preserving tabs and hard breaks for code or poetry using <code>white-space: pre-wrap</code> logic.</p></li></ul><h2><b>The hell crawl and the ai feedback loop</b></h2><p>The technical challenge of Pretext wasn't just writing the math; it was ensuring that the math matched the "ground truth" of how various browsers (Chrome, Safari, Firefox) actually render text. Text rendering is notoriously riddled with quirks, from how different engines handle kerning to the specifics of line-breaking heuristics.</p><p>Lou revealed that the library was built using an "AI-friendly iteration method". By iteratively prompting models like Claude and Codex to reconcile TypeScript layout logic against actual browser rendering on massive corpora—including the full text of <i>The Great Gatsby</i> and diverse multilingual datasets—he was able to achieve pixel-perfect accuracy without the need for heavy WebAssembly (WASM) binaries or font-parsing libraries.</p><h2><b>Ripple effects: a weekend of demos</b></h2><p>The release of Pretext immediately manifested as a series of radical experiments across X and the broader developer community. The <a href="https://x.com/_chenglou/status/2037713766205608234">original demos showcased by Lou on X</a> provided a glimpse into a new world:</p><ul><li><p><b>The editorial engine</b>: A multi-column magazine layout where text flows around draggable orbs, reflowing in real-time at 60fps.</p></li><li><p><b>Masonry virtualization</b>: A demo displaying hundreds of thousands of variable-height text boxes. Height prediction is reduced to a linear traversal of cached heights.</p></li><li><p><b>Shrinkwrapped bubbles</b>: Chat bubbles that calculate the tightest possible width for multiline text, eliminating wasted area.</p></li></ul><p>The community response was equally explosive. Within 72 hours, developers began pushing the boundaries:</p><ul><li><p><b>@@yiningkarlli</b> implemented the <a href="https://x.com/yiningkarlli/status/2038561244886831554"><b>Knuth-Plass</b></a> paragraph justification algorithm, bringing high-end print typography—reducing "rivers" of white space by evaluating entire paragraphs as units—to the web.</p></li><li><p><b>@Talsiach</b> built <b>"</b><a href="https://x.com/Talsiach/status/2038605097978958076"><b>X Times</b></a><b>,"</b> an AI-powered newspaper that uses Grok to analyze images and X posts, using Pretext to instantly layout a front-page reflow.</p></li><li><p><b>@Kaygeeartworks</b> demonstrated a<a href="https://x.com/Kaygeeartworks/status/2038606642527580367/video/1"> Three.js fluid simulation </a>featuring fish swimming through and around text elements, with the text reacting to physics at high frame rates.</p></li><li><p><b>@KageNoCoder</b> launched <a href="https://x.com/KageNoCoder/status/2038613334812135684"><b>Pretext-Flow</b></a>, a live playground for flowing text around custom media like transparent PNGs or videos.</p></li><li><p><b>@cocktailpeanut</b> and <b>@stevibe</b> demonstrated <a href="https://x.com/cocktailpeanut/status/2038304553934651601"><b>ASCII art Snake</b></a> and <a href="https://x.com/stevibe/status/2038183722118426997"><b>Hooke’s Law physics</b></a> with live text reflow.</p></li><li><p><b>@kho</b> built a <a href="https://x.com/kho/status/2038160195571102068">BioMap visualization </a>with 52 biomarker blocks performing layout reflow at 0.04ms every frame.</p></li></ul><h2><b>Philosophical shifts and the thicker client</b></h2><p>The response to Pretext was overwhelmingly enthusiastic from frontend luminaries. Guillermo Rauch, CEO of Vercel, and Ryan Florence of Remix praised the library's performance gains. Tay Zonday noted the potential for neurodiverse high-speed reading through dynamic text rasterization.</p><p>However, the release also ignited a nuanced debate about the future of web standards. Critics warned of "thick client" overreach, arguing that bypassing the DOM moves us away from the simplicity of hypermedia systems. Lou’s response was a meditation on the lineage of computing. He pointed to the evolution of iOS—which started with PostScript, a static format for printers, and evolved into a polished, scriptable platform. The web, Lou argues, has remained stuck in a "document format" mindset, layering scripting on top of a static core until complexity reached a point of diminishing returns. Pretext is an attempt to restart that conversation, treating layout as an interpreter—a set of functions that developers can manipulate—rather than a black-box data format managed by the browser.</p><h2><b>Strategic analysis: To adopt or wait?</b></h2><p>Pretext is released under the MIT License, ensuring it remains a public utility for the developer community and commercial enterprises alike. It is not merely a library for making chat bubbles look better; it is an infrastructure-level tool that decouples the visual presentation of information from the architectural constraints of the 1990s web.</p><p>By solving the last and biggest bottleneck of text measurement, Lou has provided a path for the web to finally compete with native platforms in terms of fluidity and expressiveness. Whether it is used for high-end editorial design, 120fps virtualized feeds, or generative AI interfaces, Pretext marks the moment when text on the web stopped being a static document and became a truly programmable medium.</p><p>Organizations should <b>adopt Pretext immediately</b> if they are building "Generative UI" or high-frequency data dashboards, but they should do so with a clear understanding of the "thick client" trade-off.</p><ul><li><p><b>Why adopt:</b> The move from <i>O(N)</i> to <i>O(\log N)</i> or <i>O(1)</i> layout performance is not an incremental update; it is an architectural unlock. If your product involves a chat interface that stutters during long responses or a masonry grid that "jumps" as it calculates heights, Pretext is the solution. It allows you to build interfaces that feel as fast as the underlying models are becoming.</p></li><li><p><b>What to be aware of:</b> Adoption requires a specialized talent pool. This isn't "just CSS" anymore; it’s typography-aware engineering. Organizations must also be aware that by moving layout into userland, they become the "stewards" of accessibility and standard behavior that the browser used to handle for free.</p></li></ul><p>In short, Pretext is the first major step toward a web that feels more like a game engine and less like a static document. Organizations that embrace this "interpreter" model of layout will be the ones that define the visual language of the AI era.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[JIT, WASM and scary noises (realraum)]]></title>
<description><![CDATA[At 39C3 I did a talk about how we reverse engineered a custom DSP from a 90s digital synth, with the the goal of emulating it. To make it performant, and actually run it in real time, we had to resort to JIT compilation of the DSP bytecode. While we built the original emulator in C++, I asked mys...]]></description>
<link>https://tsecurity.de/de/3369803/it-security-video/jit-wasm-and-scary-noises-realraum/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3369803/it-security-video/jit-wasm-and-scary-noises-realraum/</guid>
<pubDate>Sun, 22 Mar 2026 01:31:55 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[At 39C3 I did a talk about how we reverse engineered a custom DSP from a 90s digital synth, with the the goal of emulating it. To make it performant, and actually run it in real time, we had to resort to JIT compilation of the DSP bytecode. While we built the original emulator in C++, I asked myself how difficult it could be to run it on a web browser as well. Emscripten did wonders translating the original emulator core from C++ to WebAssembly, but the main blocker remained running the JIT engine, since we are technically already inside the JS JIT engine. This talk will go into detail explaining how WebAssembly works, to then build a toy JIT with it for the Brainfuck language. Then, I'll explain how we managed to use this same technology to port a C++ synth emulator, that uses JIT interally, to run at full speed inside a browser.

https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://c3voc.de]]></content:encoded>
</item>
<item>
<title><![CDATA[Edge.js launched to run Node.js for AI]]></title>
<description><![CDATA[Wasmer has introduced Edge.js as a JavaScript runtime that leverages WebAssembly and is designed to safely run Node.js workloads for AI and edge computing. Node apps can run inside a WebAssembly sandbox.



Accessible from edgejs.org and introduced March 16, Edge.js is intended to enable existing...]]></description>
<link>https://tsecurity.de/de/3365021/ai-nachrichten/edgejs-launched-to-run-nodejs-for-ai/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3365021/ai-nachrichten/edgejs-launched-to-run-nodejs-for-ai/</guid>
<pubDate>Fri, 20 Mar 2026 04:27:10 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Wasmer has introduced Edge.js as a <a href="https://www.infoworld.com/article/2263137/what-is-javascript-the-full-stack-programming-language.html">JavaScript</a> runtime that leverages WebAssembly and is designed to safely run <a href="https://www.infoworld.com/article/2254485/what-is-nodejs-javascript-runtime-explained.html">Node.js</a> workloads for AI and edge computing. Node apps can run inside a <a href="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html">WebAssembly</a> sandbox.</p>



<p>Accessible from <a href="https://edgejs.org/">edgejs.org</a> and introduced <a href="https://wasmer.io/posts/edgejs-safe-nodejs-using-wasm-sandbox">March 16</a>, Edge.js is intended to enable existing Node.js applications to run safely and with startup times impossible to get with containers, according to Wasmer. Instead of introducing new APIs, Edge.js preserves Node compatibility and isolates the unsafe parts of execution using WebAssembly<strong>. </strong>Existing Node.js applications and native modules can run unmodified while system calls and native modules are sandboxed through <a href="https://wasix.org/">WASIX</a>, an extension to the WebAssembly System Interface (WASI). WASIX was designed to make WebAssembly more compatible with POSIX programs, enabling seamless execution of more complex applications in both server and browser environments.</p>



<p>Reimagining Node.js, Edge.js is sandboxed via <code><strong>--safe</strong></code> mode. It is built for AI and serverless workloads, Wasmer said. Edge.js currently supports the V8 and JavaScriptCore JavaScript engines. The architecture is engine-agnostic by design. Plans call for adding support for the QuickJS and SpiderMonkey engines. Additional engines are welcome.</p>



<p>Edge.js is currently about 5% to 20% slower than current Node.js when run natively, and 30% slower when run fully sandboxed with Wasmer. In some cases, when Native&lt;&gt;Wasm work is intense, as when doing HTTP benchmarks, there could be a bigger gap. Wasmer intends to focus on closing that gap for Edge.js 1.0 and for the next releases of Wasmer.</p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Join Us at Wasm I/O 2026]]></title>
<description><![CDATA[Akamai is sponsoring Wasm IO 2026 as part of our commitment to WebAssembly. Get all the details. This article has been indexed from Blog Read the original article: Join Us at Wasm I/O 2026
Read more →
The post Join Us at Wasm I/O 2026 appeared first on IT Security News.]]></description>
<link>https://tsecurity.de/de/3358030/it-security-nachrichten/join-us-at-wasm-io-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3358030/it-security-nachrichten/join-us-at-wasm-io-2026/</guid>
<pubDate>Wed, 18 Mar 2026 06:34:07 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Akamai is sponsoring Wasm IO 2026 as part of our commitment to WebAssembly. Get all the details. This article has been indexed from Blog Read the original article: Join Us at Wasm I/O 2026</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/join-us-at-wasm-i-o-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/join-us-at-wasm-i-o-2026/">Join Us at Wasm I/O 2026</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Room 3.0 - Modernizing the Room]]></title>
<description><![CDATA[Posted by Daniel Santiago Rivera, Software EngineerThe first alpha of Room 3.0 has been released! Room 3.0 is a major breaking version of the library that focuses on Kotlin Multiplatform (KMP) and adds support for JavaScript and WebAssembly (WASM) on top of the existing Android, iOS and JVM deskt...]]></description>
<link>https://tsecurity.de/de/3348170/android-tipps/room-30-modernizing-the-room/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3348170/android-tipps/room-30-modernizing-the-room/</guid>
<pubDate>Fri, 13 Mar 2026 21:07:15 +0100</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/a/AVvXsEg8gcR_wvFw952Oay_MFUwk5Pj9dK-Ja003RfUpedOtoxkHBzHMlZmf345lm1zjvyrnb6-UNyQDEPSkxL6PvGoypZU4mwZelZ8m71og7VrAciosPaZhVDk624K9b7EftFseuGtQ8xmR9C0IZf_-dMrKBqi_-q_kvSlTVtwHMFeJXpACwMfR7Pz-Z5f7uNo"><div><span><span><i><span>Posted by Daniel Santiago Rivera, Software Engineer</span></i></span></span></div><div><span><span><i><span><br></span></i></span></span></div><div><span><span><i><span><div class="separator"><a href="https://blogger.googleusercontent.com/img/a/AVvXsEjRf3SI7fdOOau6mzOYnSqRng5ILGrQh96vj_efpOe9uzu7vo2weii05IoKa0KyycxPcjkbMSGTzRwY53LQEZ6n_4KdZYoUCedMWRyOMtJ8fEnnHg1nZHGhLhl4wvj7zWOXfEIQKIrP9-fp-TTmbBC3KhEmJrZCUG4mUGz7nbCbCMRksmcd96WiKJL7suw"><img alt="" data-original-height="476" data-original-width="1600" src="https://blogger.googleusercontent.com/img/a/AVvXsEjRf3SI7fdOOau6mzOYnSqRng5ILGrQh96vj_efpOe9uzu7vo2weii05IoKa0KyycxPcjkbMSGTzRwY53LQEZ6n_4KdZYoUCedMWRyOMtJ8fEnnHg1nZHGhLhl4wvj7zWOXfEIQKIrP9-fp-TTmbBC3KhEmJrZCUG4mUGz7nbCbCMRksmcd96WiKJL7suw=s16000"></a></div><br><br></span></i></span></span></div><br><br>The first alpha of Room 3.0 has been released! Room 3.0 is a major breaking version of the library that focuses on Kotlin Multiplatform (KMP) and adds support for JavaScript and WebAssembly (WASM) on top of the existing Android, iOS and JVM desktop support. <br><br>In this blog we outline the breaking changes, the reasoning behind Room 3.0, and the various things you can do to migrate from Room 2.0.<div><br><span>Breaking changes</span><br><br>Room 3.0 includes the following breaking API changes: <br><br><ul><li><b>Dropping SupportSQLite APIs:</b> Room 3.0 is fully backed by the <a href="https://developer.android.com/kotlin/multiplatform/sqlite#sqlite-driver">androidx.sqlite driver APIs</a>. The SQLiteDriver APIs are KMP-compatible and removing Room’s dependency on Android's API simplifies the API surface for Android since it avoids having two possible backends.</li></ul><br><ul><li><b>No more Java code generation:</b> Room 3.0 exclusively generates Kotlin code. This aligns with the evolving Kotlin-first paradigm but also simplifies the codebase and development process, enabling faster iterations.</li></ul><br><ul><li><b>Focus on KSP:</b> We are also dropping support for Java Annotation Processing (AP) and KAPT. Room 3.0 is solely a KSP (Kotlin Symbol Processing) processor, allowing for better processing of Kotlin codebases without being limited by the Java language.</li></ul><br><ul><li><b>Coroutines first:</b> Room 3.0 embraces Kotlin coroutines, making its APIs coroutine-first. Coroutines is the KMP-compatible asynchronous framework and making Room be asynchronous by nature is a critical requirement for supporting web platforms.</li></ul></div><div><br><span>A new package</span><br><br>To prevent compatibility issues with existing Room 2.x implementations and for libraries with transitive dependencies to Room (for example, WorkManager), Room 3.0 resides in a new package which means it also has a new maven group and artifact ids. For example, <span>androidx.room:room-runtime</span> has become <span>androidx.room3:room3-runtime</span> and classes such as <span>androidx.room.RoomDatabase</span> will now be located at <span>android.room3.RoomDatabase</span>.</div><div><br><span>Kotlin and Coroutines First</span><br><br>With no more Java code generation, Room 3.0 also requires KSP and the Kotlin compiler even if the codebase interacting with Room is in Java. It is recommended to have a multi-module project where Room usage is concentrated and the Kotlin Gradle Plugin and KSP can be applied without affecting the rest of the codebase.<br><br>Room 3.0 also requires Coroutines and more specifically DAO functions have to be suspending unless they are returning a reactive type, such as a Flow. Room 3.0 disallows blocking DAO functions. See the <a href="https://developer.android.com/kotlin/coroutines">Coroutines on Android documentation</a> on getting started integrating Coroutines into your application.</div><div><br><span>Migration to SQLiteDriver APIs</span><br><br>With the shift away from SupportSQLite, apps will need to migrate to the SQLiteDriver APIs. This migration is essential to leveraging the full benefits of Room 3.0, including allowing the use of the bundled SQLite library via the <span>BundledSQLiteDriver</span>. You can start migrating to the driver APIs today with Room 2.7.0+. We strongly encourage you to avoid any further usage of SupportSQLite. If you migrate your Room integrations to SQLiteDriver APIs, then the transition to Room 3.0 is easier since the package change mostly involves updating symbol references (imports) and might require minimal changes to call-sites.</div><div><br>For a brief overview of the SQLiteDriver APIs, check out the <a href="https://developer.android.com/kotlin/multiplatform/sqlite#sqlite-driver">SQLiteDriver APIs documentation</a>.<br><br>For more details on how to migrate Room to use SQLiteDriver APIs, check out the official <a href="https://developer.android.com/kotlin/multiplatform/room#migrate-from-support-sqlite">documentation to migrate from SupportSQLite</a>.</div><div><br><span>Room SupportSQLite wrapper</span><br><br>We understand completely removing SupportSQLite might not be immediately feasible for all projects. To ease this transition, Room 2.8.0, the latest version of the Room 2.0 series, introduced a new artifact called <span>androidx.room:room-sqlite-wrapper</span>. This artifact offers a compatibility API that allows you to convert a <span>RoomDatabase</span> into a <span>SupportSQLiteDatabase</span>, even if the SupportSQLite APIs in the database have been disabled due to a <span>SQLiteDriver </span>being installed. This provides a temporary bridge for developers who need more time to fully migrate their codebase. This artifact continues to exist in Room 3.0 as <span>androidx.room3:room3-sqlite-wrapper </span>to enable the migration to Room 3.0 while still supporting critical SupportSQLite usage.</div><div><br>For example, invocations of <span>Database.openHelper.writableDatabase </span>can be replaced by <span>roomDatabase.getSupportWrapper()</span> and a wrapper would be provided even if <span>setDriver()</span> is called on Room’s builder.</div><div><br>For more details check out the <a href="https://developer.android.com/kotlin/multiplatform/room#migrate-room-sqlite-wrapper">room-sqlite-wrapper documentation</a>.</div><div><br><span>Room and SQLite Web Support</span><br><br>Support for the Kotlin Multiplatform targets JS and WasmJS and brings some of the most significant API changes. Specifically, many APIs in Room 3.0 are suspend functions since proper support for web storage is asynchronous. The SQLiteDriver APIs have also been updated to support the Web and a new web asynchronous driver is available in <span>androidx.sqlite:sqlite-web</span>. It is a <a href="https://developer.mozilla.org/en-US/docs/Web/API/Web_Workers_API">Web Worker</a> based driver that enables persisting the database in the Origin private file system (OPFS).</div><div><br>For more details on how to set up Room for the Web check out the <a href="https://developer.android.com/jetpack/androidx/releases/room3#3.0.0-alpha01">Room 3.0 release notes</a>.<br><br></div><div><span>Custom DAO Return Types</span><br><br>Room 3.0 introduces the ability to add custom integrations to Room similar to RxJava and Paging. Through a new annotation API called <span>@DaoReturnTypeConverter</span> you can create your own integration such that Room’s generated code becomes accessible at runtime, this enables  <span>@Dao </span>functions having their custom return types without having to wait for the Room team to add the support. Existing integrations are migrated to use this functionality and thus will now require for those who rely on it to add the converters to the <span>@Database</span> or <span>@Dao</span> definitions.</div><div><br>For example, the Paging converter will be located in the <span>android.room3:room3-paging </span>artifact and it's called <span>PagingSourceDaoReturnTypeConverter</span>. Meanwhile for <span>LiveData</span> the converter is in <span>android.room3:room3-livedata</span> and is called <span>LiveDataReturnTypeConverter</span>.</div><div><br>For more details check out the DAO Return Type Converters section in the <a href="https://developer.android.com/jetpack/androidx/releases/room3#3.0.0-alpha01">Room 3.0 release notes</a>.<br><br></div><div><span>Maintenance mode of Room 2.x</span><br><br>Since the development of Room will be focused on Room 3, the current Room 2.x version enters maintenance mode. This means that no major features will be developed but patch releases (2.8.1, 2.8.2, etc.) will still occur with bug fixes and dependency updates. The team is committed to this work until Room 3 becomes stable.<br><br></div><div><span>Final thoughts</span><br><br>We are incredibly excited about the potential of Room 3.0 and the opportunities it unlocks for the Kotlin ecosystem. Stay tuned for more updates as we continue this journey!<br></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[IO River Embraces Wasm to Enable Any WAF to Run on Any CDN]]></title>
<description><![CDATA[IO River this week revealed it is leveraging the portable WebAssembly (Wasm) binary instruction format to make it possible to deploy any web application firewall (WAF) on a content delivery network (CDN). Starting with running the Check Point WAF on…
Read more →
The post IO River Embraces Wasm to...]]></description>
<link>https://tsecurity.de/de/3344941/it-security-nachrichten/io-river-embraces-wasm-to-enable-any-waf-to-run-on-any-cdn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3344941/it-security-nachrichten/io-river-embraces-wasm-to-enable-any-waf-to-run-on-any-cdn/</guid>
<pubDate>Thu, 12 Mar 2026 21:20:49 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>IO River this week revealed it is leveraging the portable WebAssembly (Wasm) binary instruction format to make it possible to deploy any web application firewall (WAF) on a content delivery network (CDN). Starting with running the Check Point WAF on…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/io-river-embraces-wasm-to-enable-any-waf-to-run-on-any-cdn/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/io-river-embraces-wasm-to-enable-any-waf-to-run-on-any-cdn/">IO River Embraces Wasm to Enable Any WAF to Run on Any CDN</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stable Channel Update for ChromeOS / ChromeOS Flex]]></title>
<description><![CDATA[M-145, ChromeOS version 16552.47.0 (Browser version 145.0.7632.154) has rolled out to ChromeOS devices on the Stable channel. If you find new issues, please let us know one of the following ways:File a bugVisit our ChromeOS communitiesGeneral: Chromebook Help CommunityBeta Specific: ChromeOS Beta...]]></description>
<link>https://tsecurity.de/de/3313361/it-security-nachrichten/stable-channel-update-for-chromeos-chromeos-flex/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3313361/it-security-nachrichten/stable-channel-update-for-chromeos-chromeos-flex/</guid>
<pubDate>Thu, 26 Feb 2026 22:49:41 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>M-145, ChromeOS version 16552.47.0 (Browser version 145.0.7632.154) has rolled out to ChromeOS devices on the Stable channel. </span></p><span><p dir="ltr"><span>If you find new issues, please let us know one of the following ways:</span></p><br><ol><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><a href="https://bugs.chromium.org/p/chromium/issues/list"><span>File a bug</span></a></p></li><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><span>Visit our ChromeOS communities</span></p></li><ol><li aria-level="2" dir="ltr"><p dir="ltr" role="presentation"><span>General:</span><a href="https://support.google.com/chromebook/community/?hl=en&amp;gpf=%23!forum%2Fchromebook-central"><span> </span><span>Chromebook Help Community</span></a></p></li><li aria-level="2" dir="ltr"><p dir="ltr" role="presentation"><span>Beta Specific:</span><a href="https://support.google.com/chromeos-beta/community"><span> </span><span>ChromeOS Beta Help Community</span></a></p></li></ol><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><a href="https://support.google.com/chrome/answer/95315?hl=en&amp;co=GENIE.Platform%3DDesktop"><span>Report an issue or send feedback on Chrome</span></a></p></li><li aria-level="1" dir="ltr"><p dir="ltr" role="presentation"><span>Interested in switching channels?</span><a href="https://support.google.com/chromebook/answer/1086915"><span> </span><span>Find out how.</span></a></p></li></ol><br><br><p dir="ltr"><span>Security Fixes and Rewards</span></p><h4 dir="ltr"><span>ChromeOS Vulnerability Rewards Program Reported Bug Fixes:</span></h4><p dir="ltr"><span>N/A</span></p><h4 dir="ltr"><span>Other 3rd Party Security Fixes Included:</span></h4><br><p dir="ltr"><span>High</span><span> Fixes CVE-2025-38349 kernel Use-After-Free (UAF) fix</span></p><p dir="ltr"><span>High</span><span> Fixes CVE-2025-0932 potential UAF in the ARM shader compiler reachable through WebGPU</span></p><p dir="ltr"><span>High</span><span> Fixes CVE-2025-21704 buffer size check in the USB CDC-ACM driver</span></p><br><p dir="ltr"><span>Android Security fixes can be found </span><a href="https://source.android.com/docs/security/bulletin/2026-02-01"><span>here</span></a></p><br><h4 dir="ltr"><span>Chrome Browser Security Fixes:</span></h4><br><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/478560268"><span>[478560268</span></a><span>] </span><span>High</span><span> CVE-2026-2314 blink_avif_decoder_fuzzer: Heap-buffer-overflow in InterpolateRow_Any_AVX2  on  2026-01-25 </span></p><p dir="ltr"><span>[$1000.0] </span><a href="https://issuetracker.google.com/470928605"><span>[470928605</span></a><span>] </span><span>Low</span><span> CVE-2026-2322 On Ubuntu (or other Linux-based systems) an attacker can steal files uploaded to other sites with little user interaction.  on  2025-12-22 </span></p><p dir="ltr"><span>[$500.0] </span><a href="https://issuetracker.google.com/467442136"><span>[467442136</span></a><span>] </span><span>Low</span><span> CVE-2026-2323 when the filename contains a very long with special character can break/remove the extension of file in download buble Reported by [[goes here]] on  2025-12-09 </span></p><p dir="ltr"><span>[$8000.0] </span><a href="https://issuetracker.google.com/467297219"><span>[467297219</span></a><span>] </span><span>High</span><span> CVE-2026-2313 Use-After-Poison in RouteMap::UpdateActiveRoutes  on  2025-12-09 </span></p><p dir="ltr"><span>[$2000.0] </span><a href="https://issuetracker.google.com/464173573"><span>[464173573</span></a><span>] </span><span>Medium</span><span> CVE-2026-2317 KeyframeEffect constructor leaks UA shadow root. Reported by [Brendan Draper] on  2025-11-27 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/461877477"><span>[461877477</span></a><span>] </span><span>Medium</span><span> CVE-2026-2321 heap-use-after-free : base::ScopedObservationTraits&lt;ui::WaylandWpColorManager, ui::WaylandWpColorManager::Observer&gt;::RemoveObserver  on  2025-11-18 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/435684924"><span>[435684924</span></a><span>] </span><span>Medium</span><span> CVE-2026-2320 Security: Compromised renderer can read files through file picker dialog with kSave mode + prefilled filename Reported by [Alesandro Ortiz https://AlesandroOrtiz.com] on  2025-08-01 </span></p><p dir="ltr"><span>[$5000.0] </span><a href="https://issuetracker.google.com/422531206"><span>[422531206</span></a><span>] </span><span>Medium</span><span> CVE-2026-2316 Intersection Observer v2 API fails to correctly determine target's visibility for dynamically changed z-indexes, enabling clickjacking against Google One Tap Reported by [Luan Herrera (@lbherrera_)] on  2025-06-04 </span></p><p dir="ltr"><span>[$1000.0] </span><a href="https://issuetracker.google.com/363930141"><span>[363930141</span></a><span>] </span><span>Medium</span><span> CVE-2026-2318 User can unknowingly Execute External File Hidden behind PiP during Interaction Reported by [Shaheen Fazim] on  2024-09-02 </span></p><p dir="ltr"><span>[$1000.0] </span><a href="https://issuetracker.google.com/40071155"><span>[40071155]</span></a><span> </span><span>Medium</span><span> CVE-2026-2319 UAF in v8_inspector DomainDispatcherImpl  on  2023-09-01 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/483569511"><span>[483569511</span></a><span>] </span><span>High</span><span> CVE-2026-2441 Heap-use-after-free in blink::FontFeatureValuesMapIterationSource::FetchNextItem Reported by [Shaheen Fazim] on  2026-02-11 </span></p><p dir="ltr"><span>[$11000.0] </span><a href="https://issuetracker.google.com/481074858"><span>[481074858</span></a><span>] </span><span>High</span><span> CVE-2026-2649 V8: Integer Truncation in Turboshaft PhiOp input_count via WASM br_table Reported by [JunYoung Park(@candymate) of KAIST Hacking Lab] on  2026-02-02 </span></p><p dir="ltr"><span>[$11000.0] </span><a href="https://issuetracker.google.com/477033835"><span>[477033835</span></a><span>] </span><span>High</span><span> CVE-2026-2648 PDFium  heap-buffer-overflow at opj_j2k_read_sod Reported by [soiax] on  2026-01-19 </span></p><p dir="ltr"><span>[$TBD] </span><a href="https://issuetracker.google.com/476461867"><span>[476461867</span></a><span>] </span><span>Medium</span><span> CVE-2026-2650 media_pipeline_integration_fuzzer: Heap-buffer-overflow in media::AudioBuffer::AudioBuffer  on  2026-01-17 </span></p><br><p dir="ltr"><span>Andy Wu</span></p><p dir="ltr"><span>Google ChromeOS</span></p><div><span><br></span></div></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-01-31 - Kernels, Firefox, Cosmic]]></title>
<description><![CDATA[Hello community, here we have another set of package updates.
Current Promotions

Get the latest Gaming Laptop by Slimbook powered by Manjaro: Slimbook Manjaro III
Protect your personal data, keep yourself safe with Surfshark VPN: See current promotion

Recent News

KDE Plasma users with SDDM can...]]></description>
<link>https://tsecurity.de/de/3245290/unix-server/testing-update-2026-01-31-kernels-firefox-cosmic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3245290/unix-server/testing-update-2026-01-31-kernels-firefox-cosmic/</guid>
<pubDate>Sat, 31 Jan 2026 09:46:40 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates.</p>
<h3><a name="p-830245-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-830245-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-830245-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-830245-recent-news-2"></a>Recent News</h2>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-01-31-kernels-firefox-cosmic/185261/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-01-31-kernels-firefox-cosmic/185261/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2026-01-31-kernels-firefox-cosmic/185261/1">(click for more details)</a>
<h2><a name="p-830245-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-830245-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li>Some <strong>Kernels</strong> got updated</li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/en-US/firefox/147.0.2/releasenotes/">147.0.2</a></li>
<li><strong>Cosmic</strong> <a href="https://www.neowin.net/news/cosmic-desktop-104-is-out-with-an-improved-greeter-better-performance-in-files-and-more/">1.0.4</a></li>
<li>Some fixes for <strong>GNOME</strong> and <strong>python</strong></li>
</ul>
<h2><a name="p-830245-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-830245-additional-info-4"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-01-31-kernels-firefox-cosmic/185261/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-01-31-kernels-firefox-cosmic/185261/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux510 5.10.248</li>
<li>linux515 5.15.198</li>
<li>linux61 6.1.161</li>
<li>linux66 6.6.122</li>
<li>linux612 6.12.68</li>
<li>linux618 6.18.8</li>
<li>linux619 6.19.0-rc7</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.66_rt15</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (1/31/26 09:02 CET)</p>
<ul>
<li>testing core x86_64:  12 new and 12 removed package(s)</li>
<li>testing extra x86_64:  386 new and 495 removed package(s)</li>
<li>testing multilib x86_64:  6 new and 7 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20260128             20260131
-------------------------------------------------------------------------------
                            linux612            6.12.67-1            6.12.68-1
                    linux612-headers            6.12.67-1            6.12.68-1
                            linux618             6.18.7-1             6.18.8-1
                    linux618-headers             6.18.7-1             6.18.8-1
                             linux66            6.6.121-1            6.6.122-1
                     linux66-headers            6.6.121-1            6.6.122-1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20260128             20260131
-------------------------------------------------------------------------------
                                curl             8.18.0-2             8.18.0-3
                             gettext               0.26-1                1.0-1
                      libcurl-compat             8.18.0-2             8.18.0-3
                      libcurl-gnutls             8.18.0-2             8.18.0-3
                        libunistring                1.3-1              1.4.1-1
                           procps-ng              4.0.5-3              4.0.6-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20260128             20260131
-------------------------------------------------------------------------------
                             asusctl              6.3.1-1              6.3.2-1
                            chromium     144.0.7559.109-1                    -
                             firefox            147.0.2-1                    -
                    firefox-i18n-ach            147.0.2-1                    -
                     firefox-i18n-af            147.0.2-1                    -
                     firefox-i18n-an            147.0.2-1                    -
                     firefox-i18n-ar            147.0.2-1                    -
                    firefox-i18n-ast            147.0.2-1                    -
                     firefox-i18n-az            147.0.2-1                    -
                     firefox-i18n-be            147.0.2-1                    -
                     firefox-i18n-bg            147.0.2-1                    -
                     firefox-i18n-bn            147.0.2-1                    -
                     firefox-i18n-br            147.0.2-1                    -
                     firefox-i18n-bs            147.0.2-1                    -
                     firefox-i18n-ca            147.0.2-1                    -
            firefox-i18n-ca-valencia            147.0.2-1                    -
                    firefox-i18n-cak            147.0.2-1                    -
                     firefox-i18n-cs            147.0.2-1                    -
                     firefox-i18n-cy            147.0.2-1                    -
                     firefox-i18n-da            147.0.2-1                    -
                     firefox-i18n-de            147.0.2-1                    -
                    firefox-i18n-dsb            147.0.2-1                    -
                     firefox-i18n-el            147.0.2-1                    -
                  firefox-i18n-en-ca            147.0.2-1                    -
                  firefox-i18n-en-gb            147.0.2-1                    -
                  firefox-i18n-en-us            147.0.2-1                    -
                     firefox-i18n-eo            147.0.2-1                    -
                  firefox-i18n-es-ar            147.0.2-1                    -
                  firefox-i18n-es-cl            147.0.2-1                    -
                  firefox-i18n-es-es            147.0.2-1                    -
                  firefox-i18n-es-mx            147.0.2-1                    -
                     firefox-i18n-et            147.0.2-1                    -
                     firefox-i18n-eu            147.0.2-1                    -
                     firefox-i18n-fa            147.0.2-1                    -
                     firefox-i18n-ff            147.0.2-1                    -
                     firefox-i18n-fi            147.0.2-1                    -
                     firefox-i18n-fr            147.0.2-1                    -
                    firefox-i18n-fur            147.0.2-1                    -
                  firefox-i18n-fy-nl            147.0.2-1                    -
                  firefox-i18n-ga-ie            147.0.2-1                    -
                     firefox-i18n-gd            147.0.2-1                    -
                     firefox-i18n-gl            147.0.2-1                    -
                     firefox-i18n-gn            147.0.2-1                    -
                  firefox-i18n-gu-in            147.0.2-1                    -
                     firefox-i18n-he            147.0.2-1                    -
                  firefox-i18n-hi-in            147.0.2-1                    -
                     firefox-i18n-hr            147.0.2-1                    -
                    firefox-i18n-hsb            147.0.2-1                    -
                     firefox-i18n-hu            147.0.2-1                    -
                  firefox-i18n-hy-am            147.0.2-1                    -
                     firefox-i18n-ia            147.0.2-1                    -
                     firefox-i18n-id            147.0.2-1                    -
                     firefox-i18n-is            147.0.2-1                    -
                     firefox-i18n-it            147.0.2-1                    -
                     firefox-i18n-ja            147.0.2-1                    -
                     firefox-i18n-ka            147.0.2-1                    -
                    firefox-i18n-kab            147.0.2-1                    -
                     firefox-i18n-kk            147.0.2-1                    -
                     firefox-i18n-km            147.0.2-1                    -
                     firefox-i18n-kn            147.0.2-1                    -
                     firefox-i18n-ko            147.0.2-1                    -
                    firefox-i18n-lij            147.0.2-1                    -
                     firefox-i18n-lt            147.0.2-1                    -
                     firefox-i18n-lv            147.0.2-1                    -
                     firefox-i18n-mk            147.0.2-1                    -
                     firefox-i18n-mr            147.0.2-1                    -
                     firefox-i18n-ms            147.0.2-1                    -
                     firefox-i18n-my            147.0.2-1                    -
                  firefox-i18n-nb-no            147.0.2-1                    -
                  firefox-i18n-ne-np            147.0.2-1                    -
                     firefox-i18n-nl            147.0.2-1                    -
                  firefox-i18n-nn-no            147.0.2-1                    -
                     firefox-i18n-oc            147.0.2-1                    -
                  firefox-i18n-pa-in            147.0.2-1                    -
                     firefox-i18n-pl            147.0.2-1                    -
                  firefox-i18n-pt-br            147.0.2-1                    -
                  firefox-i18n-pt-pt            147.0.2-1                    -
                     firefox-i18n-rm            147.0.2-1                    -
                     firefox-i18n-ro            147.0.2-1                    -
                     firefox-i18n-ru            147.0.2-1                    -
                    firefox-i18n-sat            147.0.2-1                    -
                     firefox-i18n-sc            147.0.2-1                    -
                    firefox-i18n-sco            147.0.2-1                    -
                     firefox-i18n-si            147.0.2-1                    -
                     firefox-i18n-sk            147.0.2-1                    -
                    firefox-i18n-skr            147.0.2-1                    -
                     firefox-i18n-sl            147.0.2-1                    -
                    firefox-i18n-son            147.0.2-1                    -
                     firefox-i18n-sq            147.0.2-1                    -
                     firefox-i18n-sr            147.0.2-1                    -
                  firefox-i18n-sv-se            147.0.2-1                    -
                    firefox-i18n-szl            147.0.2-1                    -
                     firefox-i18n-ta            147.0.2-1                    -
                     firefox-i18n-te            147.0.2-1                    -
                     firefox-i18n-tg            147.0.2-1                    -
                     firefox-i18n-th            147.0.2-1                    -
                     firefox-i18n-tl            147.0.2-1                    -
                     firefox-i18n-tr            147.0.2-1                    -
                    firefox-i18n-trs            147.0.2-1                    -
                     firefox-i18n-uk            147.0.2-1                    -
                     firefox-i18n-ur            147.0.2-1                    -
                     firefox-i18n-uz            147.0.2-1                    -
                     firefox-i18n-vi            147.0.2-1                    -
                     firefox-i18n-xh            147.0.2-1                    -
                  firefox-i18n-zh-cn            147.0.2-1                    -
                  firefox-i18n-zh-tw            147.0.2-1                    -
                gnome-control-center               49.3-1               49.4-1
                   gnome-keybindings               49.3-1               49.4-1
                       libfprint-git1.94.8.r74.g4bf6199-1                    -
                 libfprint-git-debug1.94.8.r74.g4bf6199-1                    -
    linux510-virtualbox-host-modules              7.2.4-6              7.2.6-1
    linux515-virtualbox-host-modules              7.2.4-6              7.2.6-1
  linux61-rt-virtualbox-host-modules              7.2.4-4              7.2.6-1
     linux61-virtualbox-host-modules              7.2.4-7              7.2.6-1
                  linux612-acpi_call             1.2.2-95             1.2.2-96
                   linux612-bbswitch               0.8-93               0.8-94
                linux612-broadcom-wl      6.30.223.271-94      6.30.223.271-95
               linux612-nvidia-390xx           390.157-95           390.157-96
               linux612-nvidia-470xx        470.256.02-95        470.256.02-96
               linux612-nvidia-570xx         570.211.01-3         570.211.01-4
          linux612-nvidia-570xx-open         570.211.01-3         570.211.01-4
               linux612-nvidia-575xx         575.64.05-22         575.64.05-23
          linux612-nvidia-575xx-open         575.64.05-22         575.64.05-23
                     linux612-nvidia          590.48.01-6          590.48.01-7
                linux612-nvidia-open          590.48.01-6          590.48.01-7
                      linux612-r8168          8.055.00-73          8.055.00-74
 linux612-rt-virtualbox-host-modules              7.2.4-4              7.2.6-1
                  linux612-rtl8723bu          20250811-30          20250811-31
                   linux612-tp_smapi              0.45-39              0.45-40
                linux612-vhba-module          20250329-56          20250329-57
    linux612-virtualbox-host-modules             7.2.4-15              7.2.6-2
                        linux612-zfs              2.3.5-9             2.3.5-10
 linux617-rt-virtualbox-host-modules              7.2.4-4              7.2.6-1
                  linux618-acpi_call             1.2.2-11             1.2.2-12
                   linux618-bbswitch               0.8-11               0.8-12
                linux618-broadcom-wl      6.30.223.271-11      6.30.223.271-12
               linux618-nvidia-390xx           390.157-11           390.157-12
               linux618-nvidia-470xx        470.256.02-11        470.256.02-12
               linux618-nvidia-570xx         570.211.01-3         570.211.01-4
          linux618-nvidia-570xx-open         570.211.01-3         570.211.01-4
               linux618-nvidia-575xx         575.64.05-11         575.64.05-12
          linux618-nvidia-575xx-open         575.64.05-11         575.64.05-12
                     linux618-nvidia          590.48.01-8          590.48.01-9
                linux618-nvidia-open          590.48.01-8          590.48.01-9
                      linux618-r8168          8.055.00-11          8.055.00-12
                  linux618-rtl8723bu          20250813-11          20250813-12
                   linux618-tp_smapi              0.45-11              0.45-12
                linux618-vhba-module          20250329-11          20250329-12
    linux618-virtualbox-host-modules             7.2.4-11              7.2.6-2
                        linux618-zfs              2.3.5-9             2.3.5-10
    linux619-virtualbox-host-modules            7.2.4-0.8            7.2.6-0.1
                   linux66-acpi_call            1.2.2-167            1.2.2-168
                    linux66-bbswitch              0.8-164              0.8-165
                 linux66-broadcom-wl     6.30.223.271-165     6.30.223.271-166
                linux66-nvidia-390xx          390.157-162          390.157-163
                linux66-nvidia-470xx       470.256.02-105       470.256.02-106
                linux66-nvidia-570xx         570.211.01-2         570.211.01-3
           linux66-nvidia-570xx-open         570.211.01-2         570.211.01-3
                linux66-nvidia-575xx         575.64.05-18         575.64.05-19
           linux66-nvidia-575xx-open         575.64.05-18         575.64.05-19
                      linux66-nvidia          590.48.01-4          590.48.01-5
                 linux66-nvidia-open          590.48.01-4          590.48.01-5
                       linux66-r8168          8.055.00-56          8.055.00-57
  linux66-rt-virtualbox-host-modules              7.2.4-6              7.2.6-1
                   linux66-rtl8723bu          20250811-25          20250811-26
                    linux66-tp_smapi              0.45-34              0.45-35
                 linux66-vhba-module          20250329-43          20250329-44
     linux66-virtualbox-host-modules             7.2.4-11              7.2.6-2
                         linux66-zfs              2.3.5-5              2.3.5-6
                           morc_menu     1.0+3+g2d89cb6-1     1.0+5+g91598f8-1
                 plasma-keyboard-git       r113.3511c9f-1                    -
                  rog-control-center              6.3.1-1              6.3.2-1
                      signal-desktop             7.87.0-1                    -
               vivaldi-ffmpeg-codecs     144.0.7559.114-1                    -


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20260128             20260131
-------------------------------------------------------------------------------
                         389-ds-base              3.2.0-1              3.2.0-2
                          aliyun-cli              3.2.7-1              3.2.9-1
                          apostrophe                3.4-2                3.4-3
                           appstream              1.1.1-1              1.1.2-1
                        appstream-qt              1.1.1-1              1.1.2-1
                              assimp              6.0.2-1              6.0.4-1
                               avahi           1:0.9rc2-3           1:0.9rc3-1
                              bazaar              0.7.5-1              0.7.6-1
                       bbswitch-dkms              0.8-797              0.8-798
                             blender           17:5.0.1-2           17:5.0.1-3
                           borgmatic              2.1.0-1              2.1.1-1
                          bpf-linker             0.9.15-1             0.10.0-1
                        bridge-utils              1.7.1-3                    -
                          bugstalker              0.4.1-1              0.4.2-1
                            buildkit             0.27.0-1             0.27.1-1
                                 bup             0.33.9-2            0.33.10-1
                             cargo-c            0.10.19-1            0.10.20-1
                         cargo-insta             1.46.1-1             1.46.2-1
                      cargo-zigbuild             0.21.4-1             0.21.5-1
                           chess-tui              2.3.0-1              2.4.0-1
                            chromium      144.0.7559.96-1     144.0.7559.109-1
                             clojure        1.12.4.1582-1        1.12.4.1602-1
                cloudflare-speed-cli              0.6.0-1              0.6.1-1
                         cloudflared           2026.1.1-1           2026.1.2-1
                             cockpit                354-2                355-1
                    cockpit-machines                346-1                347-1
                  cockpit-packagekit                354-2                355-1
                      cockpit-podman              119.1-1                120-1
                    cockpit-storaged                354-2                355-1
                            composer              2.9.4-1              2.9.5-1
                     cool-retro-term              1.2.0-4         2.0.0beta1-2
                  cosmic-app-library            1:1.0.3-1            1:1.0.4-1
                      cosmic-applets            1:1.0.3-1            1:1.0.4-1
                           cosmic-bg            1:1.0.3-1            1:1.0.4-1
                         cosmic-comp            1:1.0.3-1            1:1.0.4-1
                        cosmic-files            1:1.0.3-1            1:1.0.4-1
                      cosmic-greeter            1:1.0.3-1            1:1.0.4-1
                   cosmic-icon-theme            1:1.0.3-1            1:1.0.4-1
                         cosmic-idle            1:1.0.3-1            1:1.0.4-1
                cosmic-initial-setup            1:1.0.3-1            1:1.0.4-1
                     cosmic-launcher            1:1.0.3-1            1:1.0.4-1
                cosmic-notifications            1:1.0.3-1            1:1.0.4-1
                          cosmic-osd            1:1.0.3-2            1:1.0.4-1
                        cosmic-panel            1:1.0.3-1            1:1.0.4-1
                       cosmic-player            1:1.0.3-1            1:1.0.4-1
                        cosmic-randr            1:1.0.3-1            1:1.0.4-1
                   cosmic-screenshot            1:1.0.3-1            1:1.0.4-1
                      cosmic-session            1:1.0.3-1            1:1.0.4-1
                     cosmic-settings            1:1.0.3-1            1:1.0.4-1
              cosmic-settings-daemon            1:1.0.3-1            1:1.0.4-1
                        cosmic-store            1:1.0.3-1            1:1.0.4-1
                     cosmic-terminal            1:1.0.3-1            1:1.0.4-1
                  cosmic-text-editor            1:1.0.3-1            1:1.0.4-1
                   cosmic-wallpapers            2:1.0.3-1            2:1.0.4-1
                   cosmic-workspaces            2:1.0.3-1            2:1.0.4-1
                             cryptol             3.3.0-37             3.3.0-38
                            cutensor            2.4.1.4-1            2.5.0.2-1
                                cyme             2.2.10-1             2.2.11-1
                                dgop             0.1.13-1              0.2.0-1
                                dolt           1:1.81.2-1           1:1.81.3-1
                 drone-runner-docker              1.8.4-1              1.8.5-1
                         easyeffects              8.1.0-1              8.1.1-1
                editorconfig-checker              3.6.0-1              3.6.1-1
                          electron38             38.7.2-1             38.8.0-1
                          electron39             39.3.0-1             39.4.0-1
                                 eog               47.0-4               49.1-1
                            eog-docs               47.0-4               49.1-1
                             esphome          2025.12.5-1           2026.1.2-1
                        feathernotes              1.3.2-1              1.4.0-1
                    feeluown-netease              1.0.6-2              1.0.7-1
                             firefox            147.0.1-1            147.0.2-1
           firefox-developer-edition            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-ach            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-af            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-an            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ar            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-ast            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-az            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-be            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-bg            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-bn            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-br            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-bs            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ca            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-ca-valencia      148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-cak            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-cs            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-cy            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-da            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-de            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-dsb            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-el            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-en-ca            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-en-gb            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-en-us            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-eo            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-es-ar            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-es-cl            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-es-es            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-es-mx            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-et            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-eu            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-fa            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ff            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-fi            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-fr            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-fur            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-fy-nl            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-ga-ie            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-gd            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-gl            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-gn            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-gu-in            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-he            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-hi-in            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-hr            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-hsb            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-hu            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-hy-am            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ia            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-id            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-is            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-it            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ja            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ka            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-kab            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-kk            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-km            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-kn            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ko            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-lij            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-lt            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-lv            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-mk            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-mr            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ms            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-my            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-nb-no            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-ne-np            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-nl            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-nn-no            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-oc            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-pa-in            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-pl            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-pt-br            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-pt-pt            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-rm            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ro            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ru            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-sat            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-sc            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-sco            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-si            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-sk            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-skr            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-sl            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-son            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-sq            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-sr            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-sv-se            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-szl            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ta            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-te            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-tg            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-th            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-tl            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-tr            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-trs            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-uk            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ur            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-uz            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-vi            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-xh            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-zh-cn            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-zh-tw            148.0b7-1            148.0b9-1
                    firefox-i18n-ach            147.0.1-1            147.0.2-1
                     firefox-i18n-af            147.0.1-1            147.0.2-1
                     firefox-i18n-an            147.0.1-1            147.0.2-1
                     firefox-i18n-ar            147.0.1-1            147.0.2-1
                    firefox-i18n-ast            147.0.1-1            147.0.2-1
                     firefox-i18n-az            147.0.1-1            147.0.2-1
                     firefox-i18n-be            147.0.1-1            147.0.2-1
                     firefox-i18n-bg            147.0.1-1            147.0.2-1
                     firefox-i18n-bn            147.0.1-1            147.0.2-1
                     firefox-i18n-br            147.0.1-1            147.0.2-1
                     firefox-i18n-bs            147.0.1-1            147.0.2-1
                     firefox-i18n-ca            147.0.1-1            147.0.2-1
            firefox-i18n-ca-valencia            147.0.1-1            147.0.2-1
                    firefox-i18n-cak            147.0.1-1            147.0.2-1
                     firefox-i18n-cs            147.0.1-1            147.0.2-1
                     firefox-i18n-cy            147.0.1-1            147.0.2-1
                     firefox-i18n-da            147.0.1-1            147.0.2-1
                     firefox-i18n-de            147.0.1-1            147.0.2-1
                    firefox-i18n-dsb            147.0.1-1            147.0.2-1
                     firefox-i18n-el            147.0.1-1            147.0.2-1
                  firefox-i18n-en-ca            147.0.1-1            147.0.2-1
                  firefox-i18n-en-gb            147.0.1-1            147.0.2-1
                  firefox-i18n-en-us            147.0.1-1            147.0.2-1
                     firefox-i18n-eo            147.0.1-1            147.0.2-1
                  firefox-i18n-es-ar            147.0.1-1            147.0.2-1
                  firefox-i18n-es-cl            147.0.1-1            147.0.2-1
                  firefox-i18n-es-es            147.0.1-1            147.0.2-1
                  firefox-i18n-es-mx            147.0.1-1            147.0.2-1
                     firefox-i18n-et            147.0.1-1            147.0.2-1
                     firefox-i18n-eu            147.0.1-1            147.0.2-1
                     firefox-i18n-fa            147.0.1-1            147.0.2-1
                     firefox-i18n-ff            147.0.1-1            147.0.2-1
                     firefox-i18n-fi            147.0.1-1            147.0.2-1
                     firefox-i18n-fr            147.0.1-1            147.0.2-1
                    firefox-i18n-fur            147.0.1-1            147.0.2-1
                  firefox-i18n-fy-nl            147.0.1-1            147.0.2-1
                  firefox-i18n-ga-ie            147.0.1-1            147.0.2-1
                     firefox-i18n-gd            147.0.1-1            147.0.2-1
                     firefox-i18n-gl            147.0.1-1            147.0.2-1
                     firefox-i18n-gn            147.0.1-1            147.0.2-1
                  firefox-i18n-gu-in            147.0.1-1            147.0.2-1
                     firefox-i18n-he            147.0.1-1            147.0.2-1
                  firefox-i18n-hi-in            147.0.1-1            147.0.2-1
                     firefox-i18n-hr            147.0.1-1            147.0.2-1
                    firefox-i18n-hsb            147.0.1-1            147.0.2-1
                     firefox-i18n-hu            147.0.1-1            147.0.2-1
                  firefox-i18n-hy-am            147.0.1-1            147.0.2-1
                     firefox-i18n-ia            147.0.1-1            147.0.2-1
                     firefox-i18n-id            147.0.1-1            147.0.2-1
                     firefox-i18n-is            147.0.1-1            147.0.2-1
                     firefox-i18n-it            147.0.1-1            147.0.2-1
                     firefox-i18n-ja            147.0.1-1            147.0.2-1
                     firefox-i18n-ka            147.0.1-1            147.0.2-1
                    firefox-i18n-kab            147.0.1-1            147.0.2-1
                     firefox-i18n-kk            147.0.1-1            147.0.2-1
                     firefox-i18n-km            147.0.1-1            147.0.2-1
                     firefox-i18n-kn            147.0.1-1            147.0.2-1
                     firefox-i18n-ko            147.0.1-1            147.0.2-1
                    firefox-i18n-lij            147.0.1-1            147.0.2-1
                     firefox-i18n-lt            147.0.1-1            147.0.2-1
                     firefox-i18n-lv            147.0.1-1            147.0.2-1
                     firefox-i18n-mk            147.0.1-1            147.0.2-1
                     firefox-i18n-mr            147.0.1-1            147.0.2-1
                     firefox-i18n-ms            147.0.1-1            147.0.2-1
                     firefox-i18n-my            147.0.1-1            147.0.2-1
                  firefox-i18n-nb-no            147.0.1-1            147.0.2-1
                  firefox-i18n-ne-np            147.0.1-1            147.0.2-1
                     firefox-i18n-nl            147.0.1-1            147.0.2-1
                  firefox-i18n-nn-no            147.0.1-1            147.0.2-1
                     firefox-i18n-oc            147.0.1-1            147.0.2-1
                  firefox-i18n-pa-in            147.0.1-1            147.0.2-1
                     firefox-i18n-pl            147.0.1-1            147.0.2-1
                  firefox-i18n-pt-br            147.0.1-1            147.0.2-1
                  firefox-i18n-pt-pt            147.0.1-1            147.0.2-1
                     firefox-i18n-rm            147.0.1-1            147.0.2-1
                     firefox-i18n-ro            147.0.1-1            147.0.2-1
                     firefox-i18n-ru            147.0.1-1            147.0.2-1
                    firefox-i18n-sat            147.0.1-1            147.0.2-1
                     firefox-i18n-sc            147.0.1-1            147.0.2-1
                    firefox-i18n-sco            147.0.1-1            147.0.2-1
                     firefox-i18n-si            147.0.1-1            147.0.2-1
                     firefox-i18n-sk            147.0.1-1            147.0.2-1
                    firefox-i18n-skr            147.0.1-1            147.0.2-1
                     firefox-i18n-sl            147.0.1-1            147.0.2-1
                    firefox-i18n-son            147.0.1-1            147.0.2-1
                     firefox-i18n-sq            147.0.1-1            147.0.2-1
                     firefox-i18n-sr            147.0.1-1            147.0.2-1
                  firefox-i18n-sv-se            147.0.1-1            147.0.2-1
                    firefox-i18n-szl            147.0.1-1            147.0.2-1
                     firefox-i18n-ta            147.0.1-1            147.0.2-1
                     firefox-i18n-te            147.0.1-1            147.0.2-1
                     firefox-i18n-tg            147.0.1-1            147.0.2-1
                     firefox-i18n-th            147.0.1-1            147.0.2-1
                     firefox-i18n-tl            147.0.1-1            147.0.2-1
                     firefox-i18n-tr            147.0.1-1            147.0.2-1
                    firefox-i18n-trs            147.0.1-1            147.0.2-1
                     firefox-i18n-uk            147.0.1-1            147.0.2-1
                     firefox-i18n-ur            147.0.1-1            147.0.2-1
                     firefox-i18n-uz            147.0.1-1            147.0.2-1
                     firefox-i18n-vi            147.0.1-1            147.0.2-1
                     firefox-i18n-xh            147.0.1-1            147.0.2-1
                  firefox-i18n-zh-cn            147.0.1-1            147.0.2-1
                  firefox-i18n-zh-tw            147.0.1-1            147.0.2-1
                             forgejo             14.0.1-1             14.0.2-1
                             freerdp           2:3.21.0-1           2:3.22.0-1
                         fuse-common             3.17.4-1             3.18.1-1
                               fuse3             3.17.4-1             3.18.1-1
                          gemini-cli           1:0.25.2-1           1:0.26.0-1
                                giac           2.0.0.18-2           2.0.0.19-1
                              gio-qt             0.0.13-1             0.0.14-1
                                glab             1.81.0-1             1.82.0-1
                      gnome-mahjongg             49.0.1-1             49.1.1-1
                          gnome-maps               49.3-1               49.4-1
                               gsoap            2.8.139-1            2.8.140-1
                             haproxy              3.3.1-1              3.3.2-1
                    haskell-cracknum               3.5-57               3.5-58
                    haskell-fourmolu           0.12.0.0-8           0.13.0.0-1
         haskell-hls-fourmolu-plugin            2.2.0.0-5            2.2.0.0-6
             haskell-language-server            2.2.0.0-6            2.2.0.0-7
                         haskell-sbv              10.2-74               10.3-1
                              hcloud             1.60.0-1             1.61.0-1
                             htmldoc             1.9.22-1             1.9.23-1
                           hyprpaper              0.8.2-1              0.8.3-1
                           ibus-rime              1.5.1-1              1.6.0-1
                 ibus-typing-booster             2.30.0-1             2.30.2-1
                            incus-ui             0.19.2-1             0.19.3-1
                   jupyter-nbconvert             7.16.6-2             7.17.0-1
                              kaidan             0.14.0-1             0.14.0-2
                                 kio             6.22.0-1             6.22.1-1
                              kmscon              9.3.0-2              9.3.0-3
                     lib32-rust-libs           1:1.92.0-1           1:1.93.0-1
                          libchewing             0.10.3-1             0.11.0-1
                               libhx                5.0-1                5.1-1
                  libpackagekit-glib              1.3.3-2              1.3.4-1
                         libpg_query           17.6.2.1-1           17.6.2.2-1
                      libphonenumber           1:9.0.22-1           1:9.0.23-1
                             librime           1:1.16.0-1           1:1.16.1-1
                          libshumate              1.5.2-1              1.5.3-1
                     libshumate-docs              1.5.2-1              1.5.3-1
                         libspelling              0.4.9-2             0.4.10-1
                    libspelling-docs              0.4.9-2             0.4.10-1
                              libtsm              4.4.1-1              4.4.2-1
                 libva-nvidia-driver             0.0.14-1             0.0.15-1
                              libxmu              1.3.0-1              1.3.1-1
                  linux-apfs-rw-dkms           1:0.3.17-1           1:0.3.18-1
                         lxqt-config              2.3.0-1              2.3.1-1
                                mame              0.284-1              0.285-1
                          mame-tools              0.284-1              0.285-1
                     man-pages-zh_cn            1.6.4.0-3            1.6.4.0-4
                     man-pages-zh_tw            1.6.4.0-3            1.6.4.0-4
       matrix-authentication-service              1.9.0-1             1.10.0-1
                              md-tui              0.9.1-1              0.9.3-1
                           mercurial              7.1.2-2                7.2-1
               netfilter-fullconenat      r73.0cf3b48-494      r73.0cf3b48-495
                  nextcloud-app-mail              5.6.8-1              5.6.9-1
                               nvtop              3.2.0-1              3.3.1-1
                   open-policy-agent             1.12.3-1             1.13.1-1
                        openai-codex             0.87.0-1             0.91.0-1
                         openimageio            3.1.8.0-3            3.1.9.0-1
                 openshadinglanguage           1.14.8.0-2           1.15.0.0-1
                             openttd               15.0-2               15.1-1
                                 orc             0.4.41-1             0.4.42-1
                          packagekit              1.3.3-2              1.3.4-1
                                 pcp              7.0.5-2              7.1.0-1
                             pcp-gui              7.0.5-2              7.1.0-1
                   pcp-pmda-activemq              7.0.5-2              7.1.0-1
                        pcp-pmda-bcc              7.0.5-2              7.1.0-1
                      pcp-pmda-bind2              7.0.5-2              7.1.0-1
                   pcp-pmda-bpftrace              7.0.5-2              7.1.0-1
                       pcp-pmda-json              7.0.5-2              7.1.0-1
                    pcp-pmda-libvirt              7.0.5-2              7.1.0-1
                      pcp-pmda-mysql              7.0.5-2              7.1.0-1
                      pcp-pmda-nginx              7.0.5-2              7.1.0-1
                 pcp-pmda-nutcracker              7.0.5-2              7.1.0-1
                pcp-pmda-openmetrics              7.0.5-2              7.1.0-1
                     pcp-pmda-podman              7.0.5-2              7.1.0-1
                 pcp-pmda-postgresql              7.0.5-2              7.1.0-1
                       pcp-pmda-snmp              7.0.5-2              7.1.0-1
                    perl-authen-sasl             2.1900-3             2.2000-1
                     perl-net-server              2.015-1              2.016-1
                         perl-rename               1.16-3               1.16-4
                                piep             0.10.0-5             0.10.0-6
                        prusa-slicer              2.9.4-4              2.9.4-5
                         python-absl              2.3.1-2              2.4.0-1
                python-aioesphomeapi            43.12.0-1            43.14.0-1
                 python-bibtexparser              1.4.3-3              1.4.4-1
                      python-confuse              2.1.0-2              2.2.0-1
                         python-cuda             13.1.1-2             13.1.1-3
                python-cuda-bindings             13.1.1-2             13.1.1-3
                    python-cuda-core             13.1.1-2            1:0.5.1-1
              python-cuda-pathfinder             13.1.1-2            1:1.3.3-1
                      python-debugpy             1.8.19-2             1.8.20-1
                       python-gitlab              7.1.0-2              8.0.0-1
              python-huggingface-hub            1:1.3.4-1            1:1.3.5-1
                        python-janus              1.1.0-4              1.2.0-1
                       python-libvcs             0.37.0-2             0.38.6-1
                   python-numba-cuda             0.24.0-4             0.25.0-1
                         python-path            16.12.0-1            16.12.1-1
                      python-pikepdf             10.2.0-1             10.3.0-1
                   python-playwright             1.57.0-2             1.58.0-1
                        python-pooch              1.8.2-5              1.9.0-1
                     python-pynetbox              7.6.0-1              7.6.1-1
                     python-pytokens              0.4.0-1              0.4.1-1
                       python-pytube             15.0.0-5             15.0.0-6
                   python-rich-click              1.9.5-1              1.9.6-1
                     python-tifffile          2026.1.14-1          2026.1.28-1
                           python-uv             0.9.27-1             0.9.28-1
                     python-uv-build             0.9.27-1             0.9.28-1
                        qalculate-qt              5.9.0-1            5.9.0.1-1
                       qmltermwidget         0.2.0.git1-1         2.0.0.git1-1
                                 qsv             14.0.0-1             15.0.0-1
                               qxmpp             1.13.0-1             1.14.0-1
                              rclone             1.72.1-1             1.73.0-1
                   rebels-in-the-sky              1.5.6-1              1.5.7-1
                                rust           1:1.92.0-1           1:1.93.0-1
                    rust-aarch64-gnu           1:1.92.0-1           1:1.93.0-1
                   rust-aarch64-musl           1:1.92.0-1           1:1.93.0-1
                           rust-musl           1:1.92.0-1           1:1.93.0-1
                            rust-src           1:1.92.0-1           1:1.93.0-1
                           rust-wasm           1:1.92.0-1           1:1.93.0-1
                                 sbt           1:1.12.0-1           1:1.12.1-1
                      signal-desktop             7.86.0-1             7.87.0-1
                                skim             1.11.0-1             1.11.2-1
                         slicer-udev              2.9.4-4              2.9.4-5
                        sof-firmware          2025.12.1-1          2025.12.2-1
                           sof-tools          2025.12.1-1          2025.12.2-1
                             swayosd              0.2.1-2              0.3.0-1
                       systemctl-tui              0.4.1-1              0.5.1-1
                            teamtype              0.9.0-2              0.9.1-1
                            thermald           1:2.5.10-1           2:2.5.11-1
                         timescaledb             2.24.0-1             2.25.0-1
             timescaledb-old-upgrade             2.24.0-1             2.25.0-1
                                 tor           0.4.8.21-1           0.4.8.22-1
                                 usd              25.11-3              25.11-4
                                  uv             0.9.27-1             0.9.28-1
                    vhba-module-dkms          20250329-61          20250329-62
                          virtualbox              7.2.4-2              7.2.6-1
                  virtualbox-ext-vnc              7.2.4-2              7.2.6-1
                virtualbox-guest-iso              7.2.4-1              7.2.6-1
              virtualbox-guest-utils              7.2.4-2              7.2.6-1
          virtualbox-guest-utils-nox              7.2.4-2              7.2.6-1
                virtualbox-host-dkms              7.2.4-2              7.2.6-1
                      virtualbox-sdk              7.2.4-2              7.2.6-1
               vivaldi-ffmpeg-codecs     142.0.7444.267-1     144.0.7559.114-1
                              wasmer              6.1.0-2              7.0.0-1
                              wimlib             1.14.4-2             1.14.5-1
                             wiremix              0.8.0-1              0.9.0-1
                                  wt             4.12.1-3             4.12.2-1
           xdg-desktop-portal-cosmic            1:1.0.3-1            1:1.0.4-1
                              yt-dlp         2025.12.08-2         2026.01.29-1
                          yt-dlp-ejs              0.3.2-2              0.4.0-1
                                 zed            0.220.7-1            0.221.5-1
                              zenith             0.14.1-1             0.14.3-1
                            orc-docs                    -             0.4.42-1
                           wdisplays                    -              1.1.3-1


:: Different overlay package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20260128             20260131
-------------------------------------------------------------------------------
                lib32-gamescope-plus      3.15.13.plus1-2                    -


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20260128             20260131
-------------------------------------------------------------------------------
                          lib32-curl             8.18.0-3             8.18.0-4
                lib32-libcurl-compat             8.18.0-3             8.18.0-4
                lib32-libcurl-gnutls             8.18.0-3             8.18.0-4
                        lib32-libxmu              1.2.1-1              1.3.1-1
                           lib32-orc             0.4.41-1             0.4.42-1
                     lib32-procps-ng              4.0.5-1              4.0.6-1

</code></pre>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-01-31-kernels-firefox-cosmic/185261/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-01-31-kernels-firefox-cosmic/185261">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unlock Hyper-Density: Cosmonic Wasm on vSphere Kubernetes Service]]></title>
<description><![CDATA[In the rapidly evolving landscape of platform engineering, the shift from heavy virtual machines to containers was just the first step. Today, we are witnessing the next leap forward: WebAssembly (Wasm). Cosmonic, built on the foundations of the CNCF incubating project wasmCloud, is leading the c...]]></description>
<link>https://tsecurity.de/de/3235582/downloads/unlock-hyper-density-cosmonic-wasm-on-vsphere-kubernetes-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3235582/downloads/unlock-hyper-density-cosmonic-wasm-on-vsphere-kubernetes-service/</guid>
<pubDate>Mon, 26 Jan 2026 19:31:00 +0100</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img width="300" height="240" src="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/01/image_685e34.png?w=300" class="attachment-medium size-medium wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/01/image_685e34.png 1280w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/01/image_685e34.png?resize=300,240 300w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/01/image_685e34.png?resize=768,614 768w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/01/image_685e34.png?resize=1024,819 1024w, https://blogs.vmware.com/cloud-foundation/wp-content/uploads/sites/75/2026/01/image_685e34.png?resize=600,480 600w" sizes="(max-width: 300px) 100vw, 300px"></div>
<p>In the rapidly evolving landscape of platform engineering, the shift from heavy virtual machines to containers was just the first step. Today, we are witnessing the next leap forward: WebAssembly (Wasm). Cosmonic, built on the foundations of the CNCF incubating project wasmCloud, is leading the charge with Cosmonic Control. By integrating this with the vSphere … <a href="https://blogs.vmware.com/cloud-foundation/2026/01/26/unlock-hyper-density-cosmonic-wasm-on-vsphere-kubernetes-service/">Continued</a></p>
<p>The post <a href="https://blogs.vmware.com/cloud-foundation/2026/01/26/unlock-hyper-density-cosmonic-wasm-on-vsphere-kubernetes-service/">Unlock Hyper-Density: Cosmonic Wasm on vSphere Kubernetes Service</a> appeared first on <a href="https://blogs.vmware.com/cloud-foundation">VMware Cloud Foundation (VCF) Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[programmier.bar: Headless Apps mit Marcel Koch]]></title>
<description><![CDATA[Von Flutter bis Wasm: Die programmier.bar diskutiert mit Marcel Koch, wie sich Headless Apps mit Rust umsetzen lassen.]]></description>
<link>https://tsecurity.de/de/3224988/it-nachrichten/programmierbar-headless-apps-mit-marcel-koch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3224988/it-nachrichten/programmierbar-headless-apps-mit-marcel-koch/</guid>
<pubDate>Wed, 21 Jan 2026 08:17:05 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Von Flutter bis Wasm: Die programmier.bar diskutiert mit Marcel Koch, wie sich Headless Apps mit Rust umsetzen lassen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wrote a deep dive on sandboxing for AI agents: containers vs gVisor vs microVMs vs Wasm, and when each makes sense]]></title>
<description><![CDATA[Hey folks, I've been working on sandboxing for AI coding agents and kept running into the same confusion: people use "sandbox" to mean four completely different things with different security properties. So, I decided to write what I learned: the actual predicate differences between containers (s...]]></description>
<link>https://tsecurity.de/de/3202885/it-security-nachrichten/wrote-a-deep-dive-on-sandboxing-for-ai-agents-containers-vs-gvisor-vs-microvms-vs-wasm-and-when-each-makes-sense/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3202885/it-security-nachrichten/wrote-a-deep-dive-on-sandboxing-for-ai-agents-containers-vs-gvisor-vs-microvms-vs-wasm-and-when-each-makes-sense/</guid>
<pubDate>Fri, 09 Jan 2026 00:06:00 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey folks,</p> <p>I've been working on sandboxing for AI coding agents and kept running into the same confusion: people use "sandbox" to mean four completely different things with different security properties.</p> <p><a href="https://www.luiscardoso.dev/blog/sandboxes-for-ai">So, I decided to write what I learned</a>: the actual predicate differences between containers (shared kernel), gVisor (userspace kernel), microVMs (guest kernel + VMM), and Wasm (no syscall ABI)</p> <p>The post covers why containers aren't sufficient for hostile code, what "policy leakage" looks like in agent systems and practical tradeoffs for different agent architectures.</p> <p>I hope it can help people out there building AI applications.</p> <p>Happy to discuss if you're building agent sandboxes or have run into edge cases I didn't cover</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/BeowulfBR"> /u/BeowulfBR </a> <br> <span><a href="https://www.reddit.com/r/security/comments/1q7j2ic/wrote_a_deep_dive_on_sandboxing_for_ai_agents/">[link]</a></span>   <span><a href="https://www.reddit.com/r/security/comments/1q7j2ic/wrote_a_deep_dive_on_sandboxing_for_ai_agents/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-15412 | WebAssembly wabt up to 1.0.39 wasm-decompile VarName out-of-bounds (Issue 2678 / EUVD-2026-0003)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read.

This vulnerability is unique...]]></description>
<link>https://tsecurity.de/de/3189870/sicherheitsluecken/cve-2025-15412-webassembly-wabt-up-to-1039-wasm-decompile-varname-out-of-bounds-issue-2678-euvd-2026-0003/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3189870/sicherheitsluecken/cve-2025-15412-webassembly-wabt-up-to-1039-wasm-decompile-varname-out-of-bounds-issue-2678-euvd-2026-0003/</guid>
<pubDate>Thu, 01 Jan 2026 23:51:21 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> was found in <a href="https://vuldb.com/?product.webassembly:wabt">WebAssembly wabt up to 1.0.39</a>. This issue affects the function <code>wabt::Decompiler::VarName</code> of the file <em>/src/repro/wabt/bin/wasm-decompile</em> of the component <em>wasm-decompile</em>. Such manipulation leads to out-of-bounds read.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.339333">CVE-2025-15412</a>. Local access is required to approach this attack. Moreover, an exploit is present.

Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-15411 | WebAssembly wabt up to 1.0.39 wasm-decompile wabt::AST::InsertNode memory corruption (Issue 2679)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in WebAssembly wabt up to 1.0.39. This vulnerability affects the function wabt::AST::InsertNode of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. This manipulation causes memory corruption.

This vulnerability is ...]]></description>
<link>https://tsecurity.de/de/3189803/sicherheitsluecken/cve-2025-15411-webassembly-wabt-up-to-1039-wasm-decompile-wabtastinsertnode-memory-corruption-issue-2679/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3189803/sicherheitsluecken/cve-2025-15411-webassembly-wabt-up-to-1039-wasm-decompile-wabtastinsertnode-memory-corruption-issue-2679/</guid>
<pubDate>Thu, 01 Jan 2026 21:49:24 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/?product.webassembly:wabt">WebAssembly wabt up to 1.0.39</a>. This vulnerability affects the function <code>wabt::AST::InsertNode</code> of the file <em>/src/repro/wabt/bin/wasm-decompile</em> of the component <em>wasm-decompile</em>. This manipulation causes memory corruption.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.339332">CVE-2025-15411</a>. It is possible to launch the attack on the local host. Additionally, an exploit exists.

Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-14956 | WebAssembly Binaryen up to 125 src/wasm/wasm-binary.cpp readExport heap-based overflow (Issue 8089 / Nessus ID 279445)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in WebAssembly Binaryen up to 125. Affected by this issue is the function WasmBinaryReader::readExport of the file src/wasm/wasm-binary.cpp. This manipulation causes heap-based buffer overflow.

This vulnerability is handled as CVE-2025-...]]></description>
<link>https://tsecurity.de/de/3171649/sicherheitsluecken/cve-2025-14956-webassembly-binaryen-up-to-125-srcwasmwasm-binarycpp-readexport-heap-based-overflow-issue-8089-nessus-id-279445/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3171649/sicherheitsluecken/cve-2025-14956-webassembly-binaryen-up-to-125-srcwasmwasm-binarycpp-readexport-heap-based-overflow-issue-8089-nessus-id-279445/</guid>
<pubDate>Sat, 20 Dec 2025 20:06:44 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been detected in <a href="https://vuldb.com/?product.webassembly:binaryen">WebAssembly Binaryen up to 125</a>. Affected by this issue is the function <code>WasmBinaryReader::readExport</code> of the file <em>src/wasm/wasm-binary.cpp</em>. This manipulation causes heap-based buffer overflow.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.337592">CVE-2025-14956</a>. It is possible to launch the attack on the local host. Additionally, an exploit exists.

It is recommended to apply a patch to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-14957 | WebAssembly Binaryen up to 125 IRBuilder wasm-ir-builder.cpp makeLocalTee Index null pointer dereference (Issue 8090 / Nessus ID 279444)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in WebAssembly Binaryen up to 125. This affects the function IRBuilder::makeLocalGet/IRBuilder::makeLocalSet/IRBuilder::makeLocalTee of the file src/wasm/wasm-ir-builder.cpp of the component IRBuilder. Such manipulation of the argument Index l...]]></description>
<link>https://tsecurity.de/de/3171648/sicherheitsluecken/cve-2025-14957-webassembly-binaryen-up-to-125-irbuilder-wasm-ir-buildercpp-makelocaltee-index-null-pointer-dereference-issue-8090-nessus-id-279444/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3171648/sicherheitsluecken/cve-2025-14957-webassembly-binaryen-up-to-125-irbuilder-wasm-ir-buildercpp-makelocaltee-index-null-pointer-dereference-issue-8090-nessus-id-279444/</guid>
<pubDate>Sat, 20 Dec 2025 20:06:43 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/?kb.risk">problematic</a> has been found in <a href="https://vuldb.com/?product.webassembly:binaryen">WebAssembly Binaryen up to 125</a>. This affects the function <code>IRBuilder::makeLocalGet/IRBuilder::makeLocalSet/IRBuilder::makeLocalTee</code> of the file <em>src/wasm/wasm-ir-builder.cpp</em> of the component <em>IRBuilder</em>. Such manipulation of the argument <em>Index</em> leads to null pointer dereference.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.337593">CVE-2025-14957</a>. Local access is required to approach this attack. Moreover, an exploit is present.

Applying a patch is advised to resolve this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[Applets Are Officially Going, But Java In the Browser Is Better Than Ever]]></title>
<description><![CDATA["The entire java.applet package has been removed from JDK 26, which will release in March 2026," notes Inside Java. 

But long-time Slashdot reader AirHog links to this blog post reminding us that
"Applets Are Officially Gone, But Java In The Browser Is Better Than Ever."


This brings to an offi...]]></description>
<link>https://tsecurity.de/de/3157580/it-security-nachrichten/applets-are-officially-going-but-java-in-the-browser-is-better-than-ever/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3157580/it-security-nachrichten/applets-are-officially-going-but-java-in-the-browser-is-better-than-ever/</guid>
<pubDate>Sun, 14 Dec 2025 00:34:43 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["The entire java.applet package has been removed from JDK 26, which will release in March 2026," notes Inside Java. 

But long-time Slashdot reader AirHog links to this blog post reminding us that
"Applets Are Officially Gone, But Java In The Browser Is Better Than Ever."


This brings to an official end the era of applets, which began in 1996. However, for years it has been possible to build modern, interactive web pages in Java without needing applets or plugins. TeaVM provides fast, performant, and lightweight tooling to transpile Java to run natively in the browser... 


TeaVM, at its heart, transpiles Java code into JavaScript (or, these days, WASM). However, in order for Java code to be useful for web apps, much more is required, and TeaVM delivers. It includes a minifier, to shrink the generated code and obfuscate the intent, to complicate reverse-engineering. It has a tree-shaker to eliminate unused methods and classes, keeping your app download compact. It packages your code into a single file for easy distribution and inclusion in your HTML page. It also includes wrappers for all popular browser APIs, so you can invoke them from your Java code easily, with full IDE assistance and auto-correct. 

The blog post also touts Flavour, an open-source
framework "for coding, packaging, and optimizing single-page apps implemented in Java... a full front-end toolkit with templates, routing, components, and more" to "build your modern single-page app using 100% Java."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Applets+Are+Officially+Going%2C+But+Java+In+the+Browser+Is+Better+Than+Ever%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F25%2F12%2F13%2F2316245%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F25%2F12%2F13%2F2316245%2Fapplets-are-officially-going-but-java-in-the-browser-is-better-than-ever%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/25/12/13/2316245/applets-are-officially-going-but-java-in-the-browser-is-better-than-ever?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Most significant networking acquisitions of 2025]]></title>
<description><![CDATA[This year is shaping up to be an active one for mergers and acquisitions. Goldman Sachs says 2025 is on pace to become the second-biggest in history for announced M&As, Reuters reports.



In the networking arena, some of the biggest deals of 2025 were a long time coming — it took more than 18 mo...]]></description>
<link>https://tsecurity.de/de/3150813/it-security-nachrichten/most-significant-networking-acquisitions-of-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3150813/it-security-nachrichten/most-significant-networking-acquisitions-of-2025/</guid>
<pubDate>Wed, 10 Dec 2025 16:20:49 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>This year is shaping up to be an active one for mergers and acquisitions. Goldman Sachs says 2025 is on pace to become the second-biggest in history for announced M&amp;As, <a href="https://www.reuters.com/business/finance/goldman-sachs-cfo-expects-ma-momentum-continue-into-2026-2025-12-09/">Reuters reports</a>.</p>



<p>In the networking arena, some of the biggest deals of 2025 were a long time coming — it took more than 18 months for <a href="https://www.networkworld.com/article/3813597/timeline-of-hpes-14-billion-bid-for-juniper.html">HPE to finally close the Juniper Networks deal</a>, for example. Some come with blockbuster price tags (like Palo Alto Networks’ $25 billion CyberArk buy), while others are less costly but still impactful. Many of the deals revolve around AI capabilities and enabling vendors to develop more robust systems for accessing and securing distributed resources.</p>



<p>Here are more than a dozen of this year’s acquisitions, organized alphabetically by acquirer, that will help shape the future of enterprise networking.</p>



<h4 class="wp-block-heading">Akamai acquires Fermyon </h4>



<p>This month <a href="https://www.networkworld.com/article/4099424/akamai-acquires-fermyon-for-edge-computing-as-webassembly-comes-of-age.html">Akamai announced plans to acquire WebAssembly startup Fermyon</a> for an undisclosed sum as the company looks to expand its own edge capabilities. Fermyon helped to develop Wasm beyond its browser foundation for server-side and edge deployments. The deal could bring more users to Wasm, which is gaining momentum as the WebAssembly System Interface (WASI) specification nears standardization.</p>



<h4 class="wp-block-heading">Arista buys VeloCloud</h4>



<p>Arista Networks acquired Broadcom’s VeloCloud SD-WAN business in July for an undisclosed sum. For Arista, the <a href="https://www.networkworld.com/article/4016270/arista-buys-velocloud-to-reboot-sd-wans-amid-ai-infrastructure-shift.html">SD-WAN buy</a> fills one of the few networking gaps the company had and boosts its SD-WAN, SASE and branch networking plans. And those plans are big: CEO Jayshree Ullal said <a href="https://www.networkworld.com/article/4038352/aristas-latest-networking-results-4-critical-takeaways.html">Arista’s campus and WAN business</a> is expected to grow from the current $750 million to $1.25 billion by the end of 2026.</p>



<h4 class="wp-block-heading">AT&amp;T buys Lumen</h4>



<p>AT&amp;T in May announced plans to acquire Lumen’s Mass Markets fiber business. This deal, worth $5.75 billion, is an example of how important carriers see fiber optic technology, particularly as they look to handle the expected traffic increases spurred by AI. The Lumen Mass Markets fiber assets included in the deal total about 1 million fiber subscribers across more than 4 million fiber locations, <a href="https://about.att.com/story/2025/lumen-mass-markets-fiber-business.html">according to AT&amp;T</a>. </p>



<h4 class="wp-block-heading">Cisco makes two AI deals: EzDubs and NeuralFabric</h4>



<p>Last month Cisco <a href="https://www.cisco.com/site/us/en/about/corporate-development/acquisitions/ezdubs/index.html">completed its acquisition of EzDubs</a>, a privately held AI software company with speech-to-speech translation technology. EzDubs translates conversations across 31 languages and will accelerate Cisco’s delivery of next-generation features, such as live voice translation that preserves the characteristics of speech, the vendor stated. Cisco plans to incorporate EzDubs’ technology in its Cisco Collaboration portfolio. Also in November, <a href="https://www.cisco.com/site/us/en/about/corporate-development/acquisitions/neuralfabric/index.html">Cisco bought AI platform company NeuralFabric</a>, which offers a generative AI platform that lets organizations develop domain-specific small language models using their own proprietary data.</p>



<h4 class="wp-block-heading">Coreweave buys Core Scientific</h4>



<p>Nvidia-backed AI cloud provider <a href="https://www.networkworld.com/article/4018621/coreweave-acquires-core-scientific-for-9b-to-power-ai-infrastructure-push.html">CoreWeave acquired crypto miner Core Scientific</a> for about $9 billion, giving it access to 1.3 gigawatts of contracted power to support growing demand for AI and high-performance computing workloads. CoreWeave said the deal augments its vertical integration by expanding its owned and operated data center footprint, allowing it to scale GPU-powered services for enterprise and research customers.</p>



<h4 class="wp-block-heading">F5 picks up three: CalypsoAI, Fletch and MantisNet </h4>



<p><a href="https://www.networkworld.com/article/4055857/f5-to-acquire-calypsoai-for-advanced-ai-security-capabilities.html">F5 acquired Dublin, Ireland-based CalypsoAI</a> for $180 million. CalypsoAI’s platform creates what the company calls an Inference Perimeter that protects across models, vendors, and environments. F5 says it will integrate CalypsoAI’s adaptive AI security capabilities into its F5 Application Delivery and Security Platform (ADSP). </p>



<p>F5’s ADSP also stands to gain from <a href="https://www.f5.com/company/blog/how-agentic-ai-simplifies-cybersecurity-and-modern-threat-management">F5’s acquisition of agentic AI and threat management startup Fletch</a>. Fletch’s technology turns external threat intelligence and internal logs into real-time, prioritized insights; its agentic AI capabilities will be integrated into ADSP, according to F5. </p>



<p>Lastly, F5 grabbed startup MantisNet to enhance cloud-native observability in F5’s ADSP. MantisNet leverages extended Berkeley Packet Filer (<a href="https://www.networkworld.com/article/3518212/why-ebpf-is-critical-and-how-its-getting-better.html">eBPF</a>)-powered, kernel-level telemetry to provide real-time insights into encrypted protocol activity and allow organizations “to gain visibility into even the most elusive traffic, all without performance overhead,” according to an <a href="https://www.f5.com/company/blog/f5-acquires-mantisnet-to-enhance-cloud-native-observability-in-the-f5-application-delivery-and-security-platform">F5 blog post</a>.</p>



<h4 class="wp-block-heading">HPE makes it official with Juniper</h4>



<p>Finalized in July, <a href="https://www.networkworld.com/article/4016229/hpe-finalizes-juniper-acquisition-forms-new-ai-centric-networking-unit.html">this $13.4 billion deal</a> basically doubled HPE’s networking business while bolstering its AI technologies. The transaction set the stage for offering a combined portfolio spanning enterprise campus, data center, service provider, and cloud networking segments, according to the Futurum Group. “The deal creates opportunities for integrated network security offerings spanning firewall, service edge, and zero-trust architectures,” <a href="https://futurumgroup.com/insights/hpe-closes-juniper-acquisition-combining-ai-native-networking-portfolios/">the analyst firm wrote</a> after the close of the deal. “The combined entity will compete in both ‘AI for networks’ and ‘networks for AI’ market opportunities.”</p>



<h4 class="wp-block-heading">IBM finalizes HashiCorp deal</h4>



<p>IBM’s $6.4 billion buy of HashiCorp, <a href="https://www.networkworld.com/article/3834972/ibm-closes-hashicorp-buy-looks-to-boost-enterprise-multicloud-and-ai-automation-technology.html">finalized in February</a>, will infuse HashiCorp automation and security technology in every data center possible, Big Blue said. IBM plans to integrate HashiCorp’s automation technology into its Red Hat, watsonx, data security, IT automation, and consulting businesses. HashiCorp’s products include its flagship Terraform package, which lets customers provision infrastructure, network, and virtual components across multiple cloud providers and on-premises environments.</p>



<h4 class="wp-block-heading">Netgear acquires Exium</h4>



<p>In June 2025, Netgear acquired the privately held security vendor Exium to expand its SASE offerings. Known as a networking hardware vendor for consumers, Netgear is increasingly focused on delivering enterprise-grade security solutions for SMEs. “What I see as an opportunity, uniquely for Netgear, given what our roots are, is to address the needs of small and medium enterprise customers,” <a href="https://www.linkedin.com/in/badjate/">Pramod Badjate</a>, president and general manager of Netgear for Business,told <em>Network World</em>. “They have a unique need where they want the same level of reliability as a large enterprise expects [and] they also expect support.”</p>



<h4 class="wp-block-heading">Nokia purchases Infinera</h4>



<p>This $2.3 billion <a href="https://www.nokia.com/optical-networks/infinera/">deal</a> brought Nokia a ton more optical and dense wavelength-division multiplexing (DWDM) technology that it will use to bolster its hyperscaler and carrier class offerings.</p>



<h4 class="wp-block-heading">Palo Alto Networks grabs CyberArk</h4>



<p>Announced in July, this $25 billion deal gives Palo Alto a significant boost for its network access and identity management portfolio. “Palo Alto is positioning this acquisition as the ultimate leap toward securing machine and agent identities – one of the hottest frontiers in the rapidly emerging era of AI-driven threats,” the Everest Group wrote in a <a href="https://www.everestgrp.com/blog/palo-alto-networks-acquisition-of-cyberark-signals-a-new-era-for-identity-and-access-management-and-cybersecurity-titans.html">blog post about the acquisition</a>. “It signals a seismic shift in how the biggest cybersecurity providers hope to position themselves as indispensable partners for the AI-powered enterprise.”</p>



<h4 class="wp-block-heading">Qualcomm takes Alphawave Semi</h4>



<p>Looking to expand its data center networking and compute offerings, <a href="https://www.networkworld.com/article/4003852/qualcomms-2-4b-alphawave-deal-signals-bold-data-center-ambitions.html">Qualcomm grabbed British hardware maker Alphwave Semi</a> for $2.4 billion. Alphawave Semi has a variety of wired connectivity and compute technologies, including custom silicon, chiplets, ASIC, and semiconductor intellectual property. The goal is to pair Qualcomm processors with Alphawave’s high-speed connectivity and compute technologies to support increasingly intense AI workloads. “If you wanted a super strong indicator that Qualcomm was serious about playing in the datacenter CPU market, this is it,” said Matt Kimball, vice president and principal analyst at Moor Insights &amp; Strategy, when the deal was announced in June.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Whamm: Wiederverwendbare Monitoring- und Testing-Module für WebAssembly]]></title>
<description><![CDATA[Mit dem Monitoring- und Debugging-Tool Whamm greifen Entwickler zur Laufzeit auf Wasm zu. Module lassen sich unabhängig von der konkreten App wiederverwenden.]]></description>
<link>https://tsecurity.de/de/3147611/it-nachrichten/whamm-wiederverwendbare-monitoring-und-testing-module-fuer-webassembly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3147611/it-nachrichten/whamm-wiederverwendbare-monitoring-und-testing-module-fuer-webassembly/</guid>
<pubDate>Tue, 09 Dec 2025 12:01:29 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit dem Monitoring- und Debugging-Tool Whamm greifen Entwickler zur Laufzeit auf Wasm zu. Module lassen sich unabhängig von der konkreten App wiederverwenden.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-64713 | bytecodealliance wasm-micro-runtime up to 2.4.3 memory corruption (GHSA-gvx3-gg3x-rjcx)]]></title>
<description><![CDATA[A vulnerability was found in bytecodealliance wasm-micro-runtime up to 2.4.3. It has been classified as critical. This affects an unknown function. This manipulation causes memory corruption.

This vulnerability appears as CVE-2025-64713. The attack requires local access. There is no available ex...]]></description>
<link>https://tsecurity.de/de/3137403/sicherheitsluecken/cve-2025-64713-bytecodealliance-wasm-micro-runtime-up-to-243-memory-corruption-ghsa-gvx3-gg3x-rjcx/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3137403/sicherheitsluecken/cve-2025-64713-bytecodealliance-wasm-micro-runtime-up-to-243-memory-corruption-ghsa-gvx3-gg3x-rjcx/</guid>
<pubDate>Thu, 04 Dec 2025 04:50:50 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.bytecodealliance:wasm-micro-runtime">bytecodealliance wasm-micro-runtime up to 2.4.3</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">critical</a>. This affects an unknown function. This manipulation causes memory corruption.

This vulnerability appears as <a href="https://vuldb.com/?source_cve.333584">CVE-2025-64713</a>. The attack requires local access. There is no available exploit.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-64704 | bytecodealliance wasm-micro-runtime up to 2.4.3 unusual condition (GHSA-2f2p-wf5w-82qr)]]></title>
<description><![CDATA[A vulnerability was found in bytecodealliance wasm-micro-runtime up to 2.4.3 and classified as problematic. The impacted element is an unknown function. The manipulation results in improper check for unusual conditions.

This vulnerability is reported as CVE-2025-64704. The attack requires a loca...]]></description>
<link>https://tsecurity.de/de/3137400/sicherheitsluecken/cve-2025-64704-bytecodealliance-wasm-micro-runtime-up-to-243-unusual-condition-ghsa-2f2p-wf5w-82qr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3137400/sicherheitsluecken/cve-2025-64704-bytecodealliance-wasm-micro-runtime-up-to-243-unusual-condition-ghsa-2f2p-wf5w-82qr/</guid>
<pubDate>Thu, 04 Dec 2025 04:50:46 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.bytecodealliance:wasm-micro-runtime">bytecodealliance wasm-micro-runtime up to 2.4.3</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. The impacted element is an unknown function. The manipulation results in improper check for unusual conditions.

This vulnerability is reported as <a href="https://vuldb.com/?source_cve.333583">CVE-2025-64704</a>. The attack requires a local approach. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Akamai acquires Fermyon for edge computing as WebAssembly comes of age]]></title>
<description><![CDATA[WebAssembly (commonly also known simply as Wasm) began as a browser technology for running high-performance applications in web environments. The basic promise was to enable web developers to write application code once, in any language, and then have it run in any environment with the best possi...]]></description>
<link>https://tsecurity.de/de/3133782/it-security-nachrichten/akamai-acquires-fermyon-for-edge-computing-as-webassembly-comes-of-age/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3133782/it-security-nachrichten/akamai-acquires-fermyon-for-edge-computing-as-webassembly-comes-of-age/</guid>
<pubDate>Tue, 02 Dec 2025 17:06:18 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>WebAssembly (commonly also known simply as Wasm) began as a browser technology for running high-performance applications in web environments. The basic promise was to enable web developers to write application code once, in any language, and then have it run in any environment with the best possible performance.</p>



<p>Wasm is an open standard with multiple implementations and supporting vendors. Among the leading contributors is Fermyon, which got its start in 2021. Fermyon helped to develop Wasm beyond its browser foundation for server-side and edge deployments. On Dec. 1, Akamai announced it is acquiring Fermyon for an undisclosed sum as the company looks to expand its own edge capabilities. </p>



<p>The deal brings Fermyon’s WebAssembly expertise into Akamai’s distributed computing portfolio. The two companies had already been working together for more than a year, with Fermyon’s technology integrated into Akamai’s infrastructure and sold through a partner arrangement for the past 12 months.</p>



<p>The deal has the potential to bring Wasm to more users, as the technology now stands on the cusp of <a href="https://www.infoworld.com/article/3966149/4-big-changes-webassembly-developers-need-to-know-about.html">a series of major milestones</a> that could help to make 2026 the year of WebAssembly.</p>



<p>“I think 2026 is going to be the year that the average developer realizes what this technology is and what they can do with it,” <a href="https://www.linkedin.com/in/mattbutcher/">Matt Butcher</a>, CEO of Fermyon, told <em>Network World</em>.</p>



<h2 class="wp-block-heading">WebAssembly reaching for production maturity </h2>



<p>Fermyon was founded with WebAssembly expertise as a core requirement. The company hired engineers who had already contributed to <a href="https://www.infoworld.com/article/2255892/what-is-webassembly-the-next-generation-web-platform-explained.html">WebAssembly</a> standards work before joining. This background enabled Fermyon to build its open-source Spin technology as a developer-friendly runtime that abstracts the complexity of WebAssembly toolchains. </p>



<p>Spin handles compilation from source to WebAssembly bytecode and manages execution on target platforms. The runtime abstracts the underlying technology while preserving WebAssembly’s performance and security characteristics. This bet on WebAssembly standards has paid off as the technology matured. </p>



<p>WebAssembly has evolved significantly beyond its initial browser-focused design to support server-side execution. Earlier this year, <a href="https://www.infoworld.com/article/4059683/wasm-3-0-adds-64-bit-backing-language-support.html">WebAssembly 3.0 was released</a>. Butcher called it “a major sort of unblocking event that everybody was very excited about.”</p>



<p>Language support has become the critical factor enabling enterprise adoption. Production-grade WebAssembly compilers now exist for <a href="https://www.infoworld.com/article/3961921/6-languages-you-can-deploy-to-webassembly-right-now.html">Rust, JavaScript, C, C++, Go and Python</a>. Oracle announced Java support earlier this year, addressing what had been a significant enterprise gap. The .NET runtime has WebAssembly support in beta, though it has remained in that state for over a year.</p>



<h2 class="wp-block-heading">Why Akamai is buying Fermyon </h2>



<p>Akamai isn’t the first edge network provider to embrace the promise of WebAssembly. Both Cloudflare and Fastly already have integrated WebAssembly capabilities for precisely the same reason why it’s attractive to Akamai.</p>



<p><a href="https://www.linkedin.com/in/jmialexander/">Jon Alexander</a>, senior vice president of products at Akamai Technologies, told<em> Network World </em>that at the edge customers want more powerful compute, a better developer experience, and a richer range of languages.</p>



<p>Existing <a href="https://www.networkworld.com/article/964305/what-is-edge-computing-and-how-it-s-changing-the-network.html">edge computing</a> offerings couldn’t address all these requirements. WebAssembly and Fermyon together solved this. The company has already had a year-long partnership that will now only develop further with more deeply integrated offerings.</p>



<p>“We didn’t pick WebAssembly and Fermyon independent of each other,” Alexander said. “We believe that Fermyon gives us the foundation to span all the way from the edge out to highly distributed workloads, then also up to very powerful more resource intensive workloads as well.”</p>



<p>The acquisition enables technical integration that wasn’t possible under a partnership. As partners, Butcher noted that Fermyon was somewhat limited in how it could interface with the depth of the Akamai platform. “Now it’s a little bit like getting the keys to the candy store,” Butcher said.</p>



<h2 class="wp-block-heading">Production use cases span media, e-commerce and AI</h2>



<p>Over the past year, Fermyon has operated its own WebAssembly functions edge platform running inside Akamai’s network. The use cases that emerged were wider than Butcher initially anticipated.</p>



<p>Media companies are using WebAssembly functions for stream authentication and anti-piracy. Functions manage tokens and optimize stream performance close to end users while preventing hackers from grabbing tokens to intercept streams or usurp credentials.</p>



<p>E-commerce has been particularly interesting with the emergence of AI. Akamai’s bot-detection platform identifies whether traffic comes from AI crawler bots training data, search engine crawlers updating indexes, or competitors. Customers use WebAssembly functions to determine appropriate responses.</p>



<p>AI workloads represent a growing deployment pattern. Companies are building AI agents as WebAssembly modules for global distribution. The technology also enables LLM inferencing integrated with Akamai’s GPU infrastructure. Butcher also noted that some organizations rewrite content using LLMs before serving it to AI crawlers, protecting proprietary data while maintaining AI visibility.</p>



<h2 class="wp-block-heading">Major development set for 2026</h2>



<p>Looking forward, Akamai will also benefit from a major milestone expected to occur in 2026.</p>



<p>WebAssembly provides the core foundation for running binary code, but it’s missing some key capabilities. That’s where the WebAssembly System Interface (WASI) fits in. The core WebAssembly standard covers compilation and execution but doesn’t define filesystem access, networking or system clocks. WASI provides these system-level interfaces.</p>



<p>“The WebAssembly standard was built in a very interesting way, sort of the core specification treats WebAssembly as if it sort of exists in a vacuum,” Butcher explained. </p>



<p>The WASI component model enables standardized feature exposure to WebAssembly runtimes. This allows platform providers to expose services through standard interfaces. One WebAssembly binary can also expose features to another, enabling compound applications.</p>



<p>WASI is nearing its P3 (preview 3) release, which is expected in early 2026, and the final specification is likely to follow in mid-to-late 2026.</p>



<p>Fermyon already supports WASI P3 in production. The period from P3 to 1.0 focuses on hardening and ensuring everything works. </p>



<p>“Once the major version drops, it ends up being a huge indicator to the world, saying this is a thing that’s going to be around for five to ten years now,” Butcher said. “You can start really counting on this being implemented consistently everywhere.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ShellDash – Browser server dashboard with SSH and globe monitoring]]></title>
<description><![CDATA[Hey all. I built ShellDash, an interactive server admin dashboard with shell scripting and an appealing globe UI. https://shelldash.com The goal is to provide a global monitoring view of your servers, with shell script access, in a way that feels natural and productive, plus a minimal and appeali...]]></description>
<link>https://tsecurity.de/de/3122869/linux-tipps/shelldash-browser-server-dashboard-with-ssh-and-globe-monitoring/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3122869/linux-tipps/shelldash-browser-server-dashboard-with-ssh-and-globe-monitoring/</guid>
<pubDate>Thu, 27 Nov 2025 02:51:11 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey all. I built ShellDash, an interactive server admin dashboard with shell scripting and an appealing globe UI.</p> <p><a href="https://shelldash.com/">https://shelldash.com</a></p> <p>The goal is to provide a global monitoring view of your servers, with shell script access, in a way that feels natural and productive, plus a minimal and appealing UI/UX.</p> <p>The technology is fairly interesting. This being a browser app, I built a Go WASM SSH client running in the browser, proxied through my server WebSocket endpoints. This means I can provide you a Web UI to access your servers via SSH, without ever needing to see your credentials. I only see secured packets like OpenSSH sends over the open internet. Inspired by <a href="https://ssheasy.com/">https://ssheasy.com/</a></p> <p>Whether you have one server and periodically run a few common commands, or administering many scattered geographically, I hope ShellDash can make your experience more productive and fun.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/matta9001"> /u/matta9001 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1p7ofjp/shelldash_browser_server_dashboard_with_ssh_and/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1p7ofjp/shelldash_browser_server_dashboard_with_ssh_and/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Update Firefox to Patch CVE-2025-13016 Vulnerability Affecting 180 Million Users]]></title>
<description><![CDATA[AI security firm AISLE revealed CVE-2025-13016, a critical Firefox Wasm bug that risked 180M users for six months. Learn how the memory flaw allowed code execution. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, Tech, AI,…
Read more →
The post Update Firefox to P...]]></description>
<link>https://tsecurity.de/de/3119379/it-security-nachrichten/update-firefox-to-patch-cve-2025-13016-vulnerability-affecting-180-million-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3119379/it-security-nachrichten/update-firefox-to-patch-cve-2025-13016-vulnerability-affecting-180-million-users/</guid>
<pubDate>Tue, 25 Nov 2025 14:06:39 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI security firm AISLE revealed CVE-2025-13016, a critical Firefox Wasm bug that risked 180M users for six months. Learn how the memory flaw allowed code execution. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, Tech, AI,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/update-firefox-to-patch-cve-2025-13016-vulnerability-affecting-180-million-users/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/update-firefox-to-patch-cve-2025-13016-vulnerability-affecting-180-million-users/">Update Firefox to Patch CVE-2025-13016 Vulnerability Affecting 180 Million Users</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux running in a browser tab via WASM]]></title>
<description><![CDATA[submitted by    /u/modelop   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3078218/linux-tipps/linux-running-in-a-browser-tab-via-wasm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3078218/linux-tipps/linux-running-in-a-browser-tab-via-wasm/</guid>
<pubDate>Tue, 04 Nov 2025 02:36:53 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/modelop"> /u/modelop </a> <br> <span><a href="https://joelseverin.github.io/linux-wasm/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1oncgjh/linux_running_in_a_browser_tab_via_wasm/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[A new kernel port — to WebAssembly]]></title>
<description><![CDATA[Joel Severin has announced
the availability of his port of the Linux kernel to WebAssembly; one can go
to this page and
watch it boot in a browser.


	Wasm is similar to every other arch in Linux, but also
	different. One important difference is that there is no way to
	suspend execution of a tas...]]></description>
<link>https://tsecurity.de/de/3077298/linux-tipps/a-new-kernel-port-to-webassembly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3077298/linux-tipps/a-new-kernel-port-to-webassembly/</guid>
<pubDate>Mon, 03 Nov 2025 16:07:27 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Joel Severin has <a href="https://lwn.net/ml/all/618f3602-03aa-46a8-b2d4-3c9798c4cd2b@icemanor.se">announced</a>
the availability of his port of the Linux kernel to WebAssembly; one can go
to <a href="https://joelseverin.github.io/linux-wasm/">this page</a> and
watch it boot in a browser.
<p>
</p><blockquote class="bq">
	Wasm is similar to every other arch in Linux, but also
	different. One important difference is that there is no way to
	suspend execution of a task. There is a way around this though:
	Linux supports up to 8k CPUs (or possibly more...). We can just
	spin up a new CPU dedicated to each user task (process/thread) and
	never preempt it
</blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Ported to WebAssembly, Boots in a Browser Tab]]></title>
<description><![CDATA["During the past two years or so I have been slow-rolling an effort to port the Linux kernel to WebAssembly," reads a surprising post on the Linux kernel mailing list.


I'm now at the point where the kernel boots and I can run basic programs from a shell. As you will see if you play around with ...]]></description>
<link>https://tsecurity.de/de/3077001/linux-tipps/linux-ported-to-webassembly-boots-in-a-browser-tab/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3077001/linux-tipps/linux-ported-to-webassembly-boots-in-a-browser-tab/</guid>
<pubDate>Mon, 03 Nov 2025 13:50:32 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["During the past two years or so I have been slow-rolling an effort to port the Linux kernel to WebAssembly," reads a surprising post on the Linux kernel mailing list.


I'm now at the point where the kernel boots and I can run basic programs from a shell. As you will see if you play around with it for a bit, it's not very stable and will crash sooner or later, but I think this is a good first step.
Wasm is not necessarily only targeting the web, but that's how I have
been developing this project... This is Linux, booting in your browser tab, accelerated by Wasm. 
 Phoronix warns that "there are stability issues and it didn't take me long either to trigger crashes for this Linux kernel WASM port when running within Google Chrome."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linux+Ported+to+WebAssembly%2C+Boots+in+a+Browser+Tab%3A+https%3A%2F%2Flinux.slashdot.org%2Fstory%2F25%2F11%2F03%2F0610234%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Flinux.slashdot.org%2Fstory%2F25%2F11%2F03%2F0610234%2Flinux-ported-to-webassembly-boots-in-a-browser-tab%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://linux.slashdot.org/story/25/11/03/0610234/linux-ported-to-webassembly-boots-in-a-browser-tab?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-54126 | bytecodealliance wasm-micro-runtime up to 2.4.0 IPv4 Address exposure of resource (GHSA-vh64-mfvw-pxqp)]]></title>
<description><![CDATA[A vulnerability labeled as problematic has been found in bytecodealliance wasm-micro-runtime up to 2.4.0. The affected element is an unknown function of the component IPv4 Address Handler. The manipulation results in exposure of resource.

This vulnerability was named CVE-2025-54126. The attack m...]]></description>
<link>https://tsecurity.de/de/3001009/sicherheitsluecken/cve-2025-54126-bytecodealliance-wasm-micro-runtime-up-to-240-ipv4-address-exposure-of-resource-ghsa-vh64-mfvw-pxqp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3001009/sicherheitsluecken/cve-2025-54126-bytecodealliance-wasm-micro-runtime-up-to-240-ipv4-address-exposure-of-resource-ghsa-vh64-mfvw-pxqp/</guid>
<pubDate>Wed, 24 Sep 2025 07:22:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/?kb.risk">problematic</a> has been found in <a href="https://vuldb.com/?product.bytecodealliance:wasm-micro-runtime">bytecodealliance wasm-micro-runtime up to 2.4.0</a>. The affected element is an unknown function of the component <em>IPv4 Address Handler</em>. The manipulation results in exposure of resource.

This vulnerability was named <a href="https://vuldb.com/?source_cve.318259">CVE-2025-54126</a>. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wasm 3 bringt 64-Bit-Adressraum und Garbage Collection]]></title>
<description><![CDATA[Der W3C-Standard WebAssembly (Wasm) erhält mit Version 3 ein umfangreiches Update mit weitreichenden Änderungen.]]></description>
<link>https://tsecurity.de/de/2999882/it-nachrichten/wasm-3-bringt-64-bit-adressraum-und-garbage-collection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2999882/it-nachrichten/wasm-3-bringt-64-bit-adressraum-und-garbage-collection/</guid>
<pubDate>Tue, 23 Sep 2025 16:00:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der W3C-Standard WebAssembly (Wasm) erhält mit Version 3 ein umfangreiches Update mit weitreichenden Änderungen.]]></content:encoded>
</item>
<item>
<title><![CDATA[“SENTINEL: Open Anti-Cheat Framework Using Modular Isolation, Lightweight Simulation, and Cryptographic P2P Validation (GitHub)”]]></title>
<description><![CDATA[I designed **SENTINEL** — an open anti-cheat framework that prevents cheating by design, not detection. Core architecture: → Game logic split into sandboxed modules (WASM/seccomp) → prevents DLL injection → Lightweight parallel simulation validates actions → detects unknown cheats → Cognitive AI ...]]></description>
<link>https://tsecurity.de/de/2994368/reverse-engineering/sentinel-open-anti-cheat-framework-using-modular-isolation-lightweight-simulation-and-cryptographic-p2p-validation-github/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2994368/reverse-engineering/sentinel-open-anti-cheat-framework-using-modular-isolation-lightweight-simulation-and-cryptographic-p2p-validation-github/</guid>
<pubDate>Sat, 20 Sep 2025 03:37:48 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I designed **SENTINEL** — an open anti-cheat framework that prevents cheating by design, not detection.</p> <p>Core architecture:</p> <p>→ Game logic split into sandboxed modules (WASM/seccomp) → prevents DLL injection</p> <p>→ Lightweight parallel simulation validates actions → detects unknown cheats</p> <p>→ Cognitive AI analyzes intent → reduces false positives</p> <p>→ Cryptographic P2P network (CRCC) → decentralized, self-immune validation</p> <p>→ Volatile session integrity → nothing persists, nothing can be modified</p> <p>No kernel access. No performance impact. GDPR compliant.</p> <p>📄 Full spec, diagrams, FAQ, and layer details → <a href="https://github.com/GitRamo/Sentinel">https://github.com/GitRamo/Sentinel</a></p> <p>I’m not a dev — I’m sharing this as an open conceptual framework. </p> <p>**Looking for technical feedback:** </p> <p>→ Is the CRCC layer cryptographically sound? </p> <p>→ Would the simulation layer scale in real-time? </p> <p>→ Any obvious flaws in the modular isolation approach?</p> <p>Forks, critiques, and PoCs welcome.</p> <p>#SENTINEL #AntiCheat #SystemsDesign #DistributedSystems #Security</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Educational-Lab9874"> /u/Educational-Lab9874 </a> <br> <span><a href="https://github.com/GitRamo/Sentinel">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1nlak46/sentinel_open_anticheat_framework_using_modular/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Standing on the Shoulders of Giants: De-Obfuscating WebAssembly Using LLVM]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 2x - Views:72 WebAssembly (Wasm) is an increasingly popular compilation target, offering compact representation, efficient validation and compilation, and safe low to no-overhead execution. Wasm is popular not only on the browsers but finding adoption across various...]]></description>
<link>https://tsecurity.de/de/2979142/it-security-video/standing-on-the-shoulders-of-giants-de-obfuscating-webassembly-using-llvm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2979142/it-security-video/standing-on-the-shoulders-of-giants-de-obfuscating-webassembly-using-llvm/</guid>
<pubDate>Thu, 11 Sep 2025 19:20:08 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/Z-udrjM7Z78/hqdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 2x - Views:72 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/Z-udrjM7Z78?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>WebAssembly (Wasm) is an increasingly popular compilation target, offering compact representation, efficient validation and compilation, and safe low to no-overhead execution. Wasm is popular not only on the browsers but finding adoption across various platforms. As its popularity grows for various applications, so does the need to obfuscate it, subsequently raising the necessity to de-obfuscate. In this talk we will discuss how to de-obfuscate Wasm code using LLVM compiler infrastructure.<br />
<br />
There is extensive literature available on the security of Wasm from an exploitation perspective, i.e. finding vulnerabilities, writing exploits and secure coding practices. In this work, we will discuss Wasm security from a reverse engineering perspective, specifically how to deal with obfuscate and de-obfuscate Wasm. Broadly we will be covering the following topics in this presentation:<br />
- Essential Wasm internals from reverse-engineering perspective.<br />
- Brief introduction to obfuscation techniques.<br />
- How to perform compiler-based obfuscation of Wasm code using various open-source tooling.<br />
- The core idea - how to de-obfuscate Wasm code using LLVM compiler infrastructure.<br />
<br />
LLVM implements extensive code optimisation techniques that can be harnessed to simplify diverse obfuscation techniques. We will use this very idea in our de-obfuscation journey, commencing with simple obfuscation scenarios and progressively ratcheting up the complexity level to demonstrate the effectiveness of our approach. We will also show application of our learnings to some real world scenarios.<br />
<br />
The final takeaway for the audience will be an understanding of how to obfuscate and de-obfuscate Wasm code. Moreover, they will gain confidence to tackle obfuscated code without writing pattern-based simplification rules. The ideas and techniques discussed are not limited to Wasm, in fact they are language and platform agnostic, and can be applied to any obfuscated code.<br />
<br />
By:<br />
Vikas Gupta  |  Senior Security Researcher, Thales DIS Pvt. Ltd.<br />
Peter Garba  |  Principal Software Engineer, Thales DIS Pvt. Ltd.<br />
<br />
Full Abstract and Presentation Materials:<br />
https://www.blackhat.com/asia-25/briefings/schedule/#standing-on-the-shoulders-of-giants-de-obfuscating-webassembly-using-llvm-44025<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I built a blazingly fast tool to extract encryption keys from Godot (Win, WASM)!]]></title>
<description><![CDATA[Hey everyone, I've always been super curious about how Godot handles PCK encryption under the hood. So recently, I decided to check out the engine source (and other existing tools), and see how you'd actually recover a key from a compiled game. But as I looked at the existing tools, I was pretty ...]]></description>
<link>https://tsecurity.de/de/2970296/reverse-engineering/i-built-a-blazingly-fast-tool-to-extract-encryption-keys-from-godot-win-wasm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2970296/reverse-engineering/i-built-a-blazingly-fast-tool-to-extract-encryption-keys-from-godot-win-wasm/</guid>
<pubDate>Sun, 07 Sep 2025 03:35:33 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey everyone,</p> <p>I've always been super curious about how Godot handles PCK encryption under the hood. So recently, I decided to check out the engine source (and other existing tools), and see how you'd actually recover a key from a compiled game.</p> <p>But as I looked at the existing tools, I was pretty surprised. Almost all of them are outdated, were tricky to get running, or were just really slow, especially on bigger game files. It felt like there had to be a better way.</p> <p>After a bunch of work, I'm super excited to share what I came up with: <a href="https://github.com/Titoot/KeyDot">KeyDot</a>.</p> <p>It extracts the key in just ~50ms!</p> <p>At the moment there's support for Windows and WASM but I'm planning to add more in the future but I don't have any samples to test on :(</p> <p>This started as a passion project, but I'd love to make it a genuinely useful tool for the community. This is where I could really use your help.</p> <p>I'm super curious to see if it holds up on different kinds of games/versions, So you find a game where it breaks or have any ideas, don't hesitate to open an issue on GitHub</p> <p>This tool is made for the purpose of project recovery in case of lost source code and encryption key</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Titoot69"> /u/Titoot69 </a> <br> <span><a href="https://github.com/Titoot/KeyDot">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1n8gf87/i_built_a_blazingly_fast_tool_to_extract/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox 142's Link Previews Have a New Option: AI-Generated Summaries]]></title>
<description><![CDATA["Good news, everyone! The new version of Mozilla's browser now makes even more extensive use of AI," writes the Register, "providing summaries of linked content and offering developers the ability to add LLM support to extensions."

Firefox 142 brings some visible shininess, but due to the combin...]]></description>
<link>https://tsecurity.de/de/2955597/it-security-nachrichten/firefox-142s-link-previews-have-a-new-option-ai-generated-summaries/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2955597/it-security-nachrichten/firefox-142s-link-previews-have-a-new-option-ai-generated-summaries/</guid>
<pubDate>Sun, 24 Aug 2025 16:18:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["Good news, everyone! The new version of Mozilla's browser now makes even more extensive use of AI," writes the Register, "providing summaries of linked content and offering developers the ability to add LLM support to extensions."

Firefox 142 brings some visible shininess, but due to the combination of regional restrictions and Mozilla's progressive rollout system, not everybody can see all the features just yet... Not geofenced but subject to phased rollout are link previews, for various native-English-speaking regions. Hover over, long-press, or right-click a link and pick Preview Link, and a summary should appear. Mozilla's summary says: "Previews can optionally include AI-generated key points, which are processed on your device to protect your privacy." 



"Link Previews is gradually rolling out to ensure performance and quality," Firefox says in their release notes, "and is now available in en-US, en-CA, en-GB, en-AU for users with more than 3 GB of available RAM." (The notes also add a welcome for "the developers who contributed their first code change to Firefox in this release, 20 of whom were brand new volunteers!") 


The Register notes that Firefox 142 also gives developers the ability to add LLM support to extensions using wllama, a Wasm binding interfacing with llama.cpp, which lets you run Meta's Llama LLM and other models, locally or in the cloud.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Firefox+142's+Link+Previews+Have+a+New+Option%3A+AI-Generated+Summaries%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F25%2F08%2F24%2F0547251%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F25%2F08%2F24%2F0547251%2Ffirefox-142s-link-previews-have-a-new-option-ai-generated-summaries%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/25/08/24/0547251/firefox-142s-link-previews-have-a-new-option-ai-generated-summaries?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cf turnstile wasm intrep + request based solver. Working for Rewe.de]]></title>
<description><![CDATA[submitted by    /u/myronfr   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/2945790/reverse-engineering/cf-turnstile-wasm-intrep-request-based-solver-working-for-rewede/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2945790/reverse-engineering/cf-turnstile-wasm-intrep-request-based-solver-working-for-rewede/</guid>
<pubDate>Mon, 18 Aug 2025 17:07:54 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/myronfr"> /u/myronfr </a> <br> <span><a href="https://github.com/Myronfr/OfflineTurnstileSolver">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1mtoeen/cf_turnstile_wasm_intrep_request_based_solver/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-58264 | CosmWasm serde-json-wasm Crate up to 1.0.0 on Rust Deeply Nested JSON Data recursion (RUSTSEC-2024-0012 / EUVD-2024-54825)]]></title>
<description><![CDATA[A vulnerability was found in CosmWasm serde-json-wasm Crate up to 1.0.0 on Rust and classified as problematic. This issue affects some unknown processing of the component Deeply Nested JSON Data Handler. The manipulation leads to uncontrolled recursion.

The identification of this vulnerability i...]]></description>
<link>https://tsecurity.de/de/2908670/sicherheitsluecken/cve-2024-58264-cosmwasm-serde-json-wasm-crate-up-to-100-on-rust-deeply-nested-json-data-recursion-rustsec-2024-0012-euvd-2024-54825/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2908670/sicherheitsluecken/cve-2024-58264-cosmwasm-serde-json-wasm-crate-up-to-100-on-rust-deeply-nested-json-data-recursion-rustsec-2024-0012-euvd-2024-54825/</guid>
<pubDate>Mon, 28 Jul 2025 00:35:10 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.cosmwasm:serde-json-wasm_crate">CosmWasm serde-json-wasm Crate up to 1.0.0</a> on Rust and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This issue affects some unknown processing of the component <em>Deeply Nested JSON Data Handler</em>. The manipulation leads to uncontrolled recursion.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.317867">CVE-2024-58264</a>. Local access is required to approach this attack. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-8028 | Mozilla Firefox up to 140 on ARM64 WASM br_table memory corruption (Nessus ID 242581)]]></title>
<description><![CDATA[A vulnerability was found in Mozilla Firefox up to 140 on ARM64. It has been declared as critical. This vulnerability affects the function br_table of the component WASM. The manipulation leads to memory corruption.

This vulnerability was named CVE-2025-8028. The attack can be initiated remotely...]]></description>
<link>https://tsecurity.de/de/2902116/sicherheitsluecken/cve-2025-8028-mozilla-firefox-up-to-140-on-arm64-wasm-brtable-memory-corruption-nessus-id-242581/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2902116/sicherheitsluecken/cve-2025-8028-mozilla-firefox-up-to-140-on-arm64-wasm-brtable-memory-corruption-nessus-id-242581/</guid>
<pubDate>Wed, 23 Jul 2025 15:22:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.mozilla:firefox">Mozilla Firefox up to 140</a> on ARM64. It has been declared as <a href="https://vuldb.com/?kb.risk">critical</a>. This vulnerability affects the function <code>br_table</code> of the component <em>WASM</em>. The manipulation leads to memory corruption.

This vulnerability was named <a href="https://vuldb.com/?source_cve.317356">CVE-2025-8028</a>. The attack can be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-8028 | Mozilla Thunderbird up to 140 on ARM64 WASM br_table memory corruption (Nessus ID 242581)]]></title>
<description><![CDATA[A vulnerability was found in Mozilla Thunderbird up to 140 on ARM64. It has been rated as critical. This issue affects the function br_table of the component WASM. The manipulation leads to memory corruption.

The identification of this vulnerability is CVE-2025-8028. The attack may be initiated ...]]></description>
<link>https://tsecurity.de/de/2902113/sicherheitsluecken/cve-2025-8028-mozilla-thunderbird-up-to-140-on-arm64-wasm-brtable-memory-corruption-nessus-id-242581/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2902113/sicherheitsluecken/cve-2025-8028-mozilla-thunderbird-up-to-140-on-arm64-wasm-brtable-memory-corruption-nessus-id-242581/</guid>
<pubDate>Wed, 23 Jul 2025 15:22:38 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.mozilla:thunderbird">Mozilla Thunderbird up to 140</a> on ARM64. It has been rated as <a href="https://vuldb.com/?kb.risk">critical</a>. This issue affects the function <code>br_table</code> of the component <em>WASM</em>. The manipulation leads to memory corruption.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.317357">CVE-2025-8028</a>. The attack may be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-4919: Corruption via Math Space in Mozilla Firefox]]></title>
<description><![CDATA[In recent years, there has been an increase in interest in JavaScript engine vulnerabilities in order to compromise web browsers. Notably, vulnerabilities in JIT engines are among the most favorite ones as they tend to provide strong primitives, and well-known techniques are available to facilita...]]></description>
<link>https://tsecurity.de/de/2887851/hacking/cve-2025-4919-corruption-via-math-space-in-mozilla-firefox/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2887851/hacking/cve-2025-4919-corruption-via-math-space-in-mozilla-firefox/</guid>
<pubDate>Tue, 15 Jul 2025 16:35:45 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">In recent years, there has been an increase in interest in JavaScript engine vulnerabilities in order to compromise web browsers. Notably, vulnerabilities in JIT engines are among the most favorite ones as they tend to provide strong primitives, and well-known techniques are available to facilitate compromise. At Pwn2Own Berlin 2025, Manfred Paul compromised the Mozilla Firefox renderer process using a vulnerability in IonMonkey, the JavaScript JIT compiler for SpiderMonkey (the Firefox JavaScript and WebAssembly engine). This vulnerability is assigned CVE-2025-4919 and Mozilla Foundation fixed it in Mozilla Firefox 138.0.4 via <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2025-36/">Security Advisory 2025-36</a>. Trend Zero Day Initiative assigned <a href="https://www.zerodayinitiative.com/advisories/ZDI-25-291/">ZDI-25-291</a> to this vulnerability. Here's a video of the exploit in action:</p>





















  
  






  <p class="">Note: This blog is heavily reliant on the details provided by Manfred Paul at the Pwn2Own competition.</p><p class=""><strong>Introduction</strong></p>





















  
  



<p>The Ion JIT compiler uses a function called <code>ExtractLinearSum</code> in multiple places to convert a value node into a <code>linear sum</code> expression. The purpose is to be able to reason about subexpressions containing exclusively additions and subtractions. For example, consider the graph of value nodes representing the expression <code>(x+(2+3)) − (−3)</code>. This will always be equal to <code>x+8</code> which is much easier to reason about in contexts such as bounds-check elimination or hoisting. <code>ExtractLinearSum</code> function extracts this simplified form. To understand the details of this function let’s consider its declaration in <code>jit/IonAnalysis.h</code>:</p>

<p>The return type would be <code>struct SimpleLinearSum</code> which is also declared in <code>IonAnalysis.h</code>:</p>

<p>As the comment explains only very simple linear expressions like <code>𝑥 + 𝑛</code> with <code>𝑥</code> as an arbitrary value node and <code>𝑛</code> as an integer constant are supported. A pure constant can also be expressed by setting the <code>term</code> pointer to a NULL pointer. It is important to note that any (integer) expression <code>val</code> can be converted to a <code>SimpleLinearSum</code>. In a trivial case that the expression is not itself an addition or subtraction <code>ExtractLinearSum</code> can simply return a <code>SimpleLinearSum</code> with <code>term</code> set to <code>val</code> and constant set to 0.</p>
<p>The <code>ExtractLinearSum</code> function takes three arguments. The first is simply the expression <code>ins</code> to analyze which should be a value node of integer type. The third is a simple recursion counter (as <code>ExtractLinearSum</code> function can call itself recursively to analyze i.e. the two sides of an addition seperately) which simply keeps track of the recursion depth to prevent stack exhaustion. This parameter will always be left at its default value 0 by callers. The most subtle parameter is however the second one describing as so-called <code>MathSpace</code>. This enum is also declared in <code>IonAnalysis.h</code>:</p>

<p>As the comment explains, this is done to separate two different possible behaviors of the <code>MAdd/Msub</code> nodes: They can optionally have an overflow check that leads to bailout if the operation would overflow the 32-bit signed integer range. If this check is enabled, the semantics of the operation correspond to the actual (infinite) integers. The usage of 32-bits as a representation are merely a speculative assumption possibly leading to bailout if violated. These semantics are represented by the <code>Infinite</code> MathSpace. On the other hand, the compiler can also generate unchecked additions or subtractions. These purposefully truncate the output to the 32-bit integer range as the usage site might perform such a truncation anyways (for example in a pattern like <code>(x+5)|0</code> the bitwise OR would truncate its operands to 32-bit integers). This corresponds to doing arithmetic modulo 232 and thus is represented by the <code>Modulo</code> MathSpace. Finally, the <code>Unknown</code> MathSpace is simply a default value that can be passed into a <code>ExtractLinearSum</code> call. The meaning of this default value is that both of the described <code>math</code> spaces are acceptable and the function will simply pick the appropriate one based on the outermost operation. It will still however make sure to only allow a consistent <code>MathSpace</code> for all involved operations by passing the chosen space to the recursive calls instead of <code>Unknown</code>.</p>
<p><b data-preserve-html-node="true">Root Cause</b></p>
<p>The <code>ExtractLinearSum</code> function is used in a few places in the Ion compiler. The most direct usage happens in <code>jit/FoldLinearArithConstants.cpp</code> where the compiler simply folds complicated linear expressions of mostly constants into one single <code>Madd</code> node. This direct usage will not concern us for the purposes of the vulnerability. The use that leads to the vulnerability is located in the <code>TryEliminateBoundsCheck</code> function inside <code>jit/IonAnalysis.cpp</code>:</p>

<p>The purpose of this function is to <code>merge</code> subsequent bounds check on the same object. For example, consider the following JavaScript operations:</p>

<p>These will generate two separate bounds checks with indices <code>𝑖 + 4</code> and <code>𝑖 + 7</code>. Nodes of type <code>MboundsCheck</code> can check a whole range of indices at once. For this purpose, they store two integer offsets: <code>minimum</code> and <code>maximum</code>. When the bounds check is run the actual indices that are checked correspond to <code>index + minimum</code> and <code>index + maximum</code> where <code>index</code> is the actual input value into the node. In this case, the existing checks will have <code>minimum</code> and <code>maximum</code> both set to 0 (Actually it is possible that for these exact two bounds checks with index <code>𝑖</code> and both <code>minimum/ maximum</code> set to 4 (for the first check) and 7 (for the second check) are generated but we will ignore this for the sake of simplicity for now). The above bounds-check elimination pass will now try to merge these two bounds checks into one. To do this, first it is checked that both index expressions are linear sums corresponding to the same term (in this case the variable <code>i</code>). Instead of generating a new <code>MboundsCheck</code> node with index <code>i</code>, the compiler will simply reuse the first bounds-check and adjust the <code>minimum</code> and <code>maximum</code> fields. In this case as the index value of the seconds bounds check is larger by 3 the <code>maximum</code> field would be set to 3, while the <code>minimum</code> remains 0, and the actual index value stays <code>i+4</code>. While creating a clean conceptual difference between <code>wrapping</code> and <code>infinite</code> addition (and subtraction) semantics is a good design choice in <code>SimpleLinearSum</code> it seems like less care was taking at the call sites to make sure only appropriate semantics can be used. For example, bounds checks have inherently <code>infinite</code> semantics. If an array has length 20, then 10 is a valid index, but 232 + 10 is not. This means that using the wrapping <code>Modulo</code> math space could lead to wrong results. This becomes quite apparent with an actual bounds-check elimination. Consider an array being indexed at indices <code>i</code> and <code>i+10</code>. Normally <code>i+10</code> should always be larger by exactly 10 than <code>i</code> so extending the maximum of the first check by 10 would cover it. But if the addition has unchecked <code>Modulo</code> semantics, this no longer holds true as <code>i+10</code> might then potentially overflow if <code>i</code> is itself a large 32-bit integer like 232 − 5. The basic construct to trigger this bug is somewhat simple:</p>

<p>What happens here is that the bitwise OR with 0 will force a truncation to 32-bit integers, so that both the additions become unchecked wrapping additions. By the time that Bounds-Check Elimination phase will run, the bitwise ORs will have been eliminated because or-ing with 0 is a NOP. This leads to two array indices with <code>i + 5</code> and <code>i + 10</code> respectively as indices, where both additions are now wrapping. This means that <code>ExtractLinearSum</code> will be able to analyze those expressions, choosing the <code>Modulo</code> MathSpace, returning a <code>SimpleLinearSum</code> with term set to <code>i</code> for both. This in turn leads <code>TryEliminateBoundsCheck</code> to believe that the index of the second bounds check will always be larger by 5 than the first and eliminate it by increasing the first check’s <code>maximum</code> by 5. However, this is clearly incorrect already. If, for example, we set <code>i</code> to 231−7 as an index then the first index will be equal to 231 – 2 but the second one will be equal to −231 + 3, which is not a value covered by the corresponding range. This would not lead to an immediate problem if the involved bounds checks were of the 32-bit integer kind as they would bailout when encountering an index that added to the <code>maximum</code> offset exceeds 231 − 1. However, for a bounds check of <code>IntPtr</code> type, this is no problem as long as the length is large enough. We thus need an array with length greater than 231 to hit this bug as the bounds check will check up to the actual index (231 - 7) + 10 = 231 + 3 in the above example. This is probably impossible using normal JavaScript Arrays. Fortunately, Firefox's memory limits are large enough to allow for the creation of some rather huge typed arrays. Therefore we can simply create a <code>Uint8Array</code> of the size we need. As the bug is fundamentally about the confusion between an integer and its 32-bit wrapped version it can only ever be used to access an index off by exactly 232 from a valid index. For an addition that is barely overflowing like in the above example an index close to −231 can be achieved. This would not be very easy to exploit as it would result in a read and write primitive about 231 bytes in memory before the typed array. Therefore, it makes sense to use an even larger array of size 232. This will allow any bounds-check to pass as long as index value <code>minimum</code> and <code>maximum</code> are all non-negative signed 32-bit integers.</p>
<p><b data-preserve-html-node="true">Triggering the Bug for Out-of-Bounds Read and Write</b></p>
<p>A simple out-of-bounds read POC might look something like the following:</p>

<p>Here, the bounds checks for the array accesses will again be merged into one. This single bounds check will have index equal to <code>idx1 + 100</code> but <code>maximum</code> is set to <code>231 – 101</code> as this is what <code>TryEliminateBoundsCheck</code> computes to be the difference of the two indices again due to ignoring the possibility of wrap-arounds. The training iterations in the loop that are (partially) evaluated by the interpreter instead of JIT-compiled will simply access the indices <code>(−50) + 100 = 50</code> and (−50) + (231 − 10) = 231 – 60 which are both in-bounds. For the final evaluation however <code>idx1</code> will be equal to (231 − 200) + 100 = 231 − 100, but <code>idx2</code> will be equal to (231 − 200) + (231 − 1) − 231 = −201 due to the wrap-around behavior. However, the merged bounds-check will still be passed as it will only check that there is a range of 231 − 99 valid indices starting from 231 – 100 which is true. This leads to the acceptance of a negative index and access to bytes before its start. In this case an out-of-bounds read is performed but the exploit logic is the same for a write primitive. The only thing left to explain is the role of the <code>out</code> object in the code. This is a technical neccessity due to the behavior of the <code>MInt32ToIntPtr</code> node. This node is inserted to convert our 32-bit value <code>idx2</code> into an actual 64-bit array index. However there are some logics in <code>jit/Lowering.cpp</code> during visiting <code>Int32ToIntPtr</code> node that checks if a sign-extension is needed at all:</p>

<p>If the only use is as the index of the load then it is assumed that the value cannot be negative at all (as this could only result from a broken bounds check as in our case) and a simple zero-extension is performed instead of the usual sign extension. However, converting the value into a <code>BigInt</code> also uses the <code>Int32ToIntPtr</code> node as an intermediate leading to another use and disabling this optimization. Returning this <code>BigInt</code> using the <code>out</code> object prevents it from being optimized away.</p>
<p><b data-preserve-html-node="true">Possibility of Related Bugs</b></p>
<p>Like mentioned above <code>TryEliminateBoundsCheck</code> is not the only place where <code>ExtractLinearSum</code> is used. Notably, it is also used in multiple places during the bounds check hoisting in <code>jit/RangeAnalysis.cpp</code> (sometimes also via the related function <code>ExtractLinearInequality</code>). Here, the function is again used with its default second argument of <code>MathSpace::Unknown</code>. Again, this choice seems incorrect. Consider a loop like <code>for (let i = 0; i + 3 &lt; 10 − 2; i = i+1) {...}</code>. Here the loop analysis will basically conclude (by extracting various linear sums) that maximum 5 iterations will take place. This information is then used to hoist bounds checks which may depend linearly on some loop variables. However, if any of these additions are replaced by unchecked wrapping ones then these invariants could no longer hold. For example, the loop <code>for (let i = 2**31− 5; i &lt;= 2**31-1; i = (i+1)|0) {...}</code> will run forever. There is one hurdle that however seems to make this harder (maybe impossible) to exploit and it is the compilation stage responsible for getting rid of the unneccessary bitwise OR happens after the bounds check hoisting (though before bounds check elimination). WebAssembly can also not be used as this optimization is disabled in that compilation mode.</p>
<p><b data-preserve-html-node="true">Exploitation</b></p>
<p>As always, controlled out-of-bounds read and write primitives are quite powerful tools for further exploitation. The only slight difficulty is that the access is from a very large-typed array instead of the more usual smal heap object, meaning that it won’t be allocated in e.g. the nursery heap. Experimentally what works well is gaining access into large <code>Map</code> objects. Allocating a few of them will nearly always result in one map being right in front of the huge-typed array. This map object will contain tagged pointers to its values. Reading out such a pointer directly results in an <code>addrOf</code> primitive. Conversely overwriting a tagged pointer results in a <code>fakeObj</code> primitive. Once these two primitives are obtained exploitation becomes fairly standard. Some fake structures in the fixed inline storage of some (small) array buffers are crafted which are a fixed offset from the object location determined via <code>addrOf</code>. Using this a complete fake object crafted whose <code>elements</code> are also fake with a huge length. This object is not fully valid as there are some pointers to e.g. the object class that are hard to fake but it is good enough to temporarily get another out-of-bounds access this time into another overlapping ArrayBuffer. This can finally be used to overwrite the data address of this array buffer resulting in arbitrary read and write primitives. By embedding shellcode into float constants of a WASM function it would be possible to put the shellcode into executable memory. Finally all that remains is to overwrite the entry point offset of the WASM function to execute the shellcode. A demo of exploitation is available at <a href="https://www.youtube.com/watch?v=TG029NAGKs0">https://www.youtube.com/watch?v=TG029NAGKs0</a></p>
<p><b data-preserve-html-node="true">Final Notes</b></p>
<p>Despite fuzzing JavaScript engines at scale for a long time there are still high-quality bugs present yet to be found. It is notable that the bug described here could be challenging to be found using a fuzzer as it needs large allocations which may trigger performance penalties. This yet again proves the importance of source code review to find high quality bugs.</p>




  <p class="">You can find me on Twitter at <a href="https://twitter.com/hosselot">@hosselot</a> and follow the team on <a href="https://www.twitter.com/thezdi" target="_blank">Twitter</a>, <a href="https://infosec.exchange/@thezdi" target="_blank">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative" target="_blank">LinkedIn</a>, or <a href="https://bsky.app/profile/thezdi.bsky.social" target="_blank">Bluesky</a> for the latest in exploit techniques and security patches.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-4046 | Mozilla Firefox up to 115.23.1 WASM JIT Analysis denial of service (DLA 3521-1 / Nessus ID 239763)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Mozilla Firefox. This issue affects some unknown processing of the component WASM JIT Analysis. The manipulation leads to denial of service.

The identification of this vulnerability is CVE-2023-4046. The attack may be initia...]]></description>
<link>https://tsecurity.de/de/2842788/sicherheitsluecken/cve-2023-4046-mozilla-firefox-up-to-115231-wasm-jit-analysis-denial-of-service-dla-3521-1-nessus-id-239763/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2842788/sicherheitsluecken/cve-2023-4046-mozilla-firefox-up-to-115231-wasm-jit-analysis-denial-of-service-dla-3521-1-nessus-id-239763/</guid>
<pubDate>Fri, 20 Jun 2025 18:52:49 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, has been found in <a href="https://vuldb.com/?product.mozilla:firefox">Mozilla Firefox</a>. This issue affects some unknown processing of the component <em>WASM JIT Analysis</em>. The manipulation leads to denial of service.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.235847">CVE-2023-4046</a>. The attack may be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-32211 | Mozilla Firefox up to 112 wasm Code denial of service (Bug 1823379 / Nessus ID 239763)]]></title>
<description><![CDATA[A vulnerability was found in Mozilla Firefox up to 112. It has been rated as problematic. This issue affects some unknown processing of the component wasm Code Handler. The manipulation leads to denial of service.

The identification of this vulnerability is CVE-2023-32211. The attack may be init...]]></description>
<link>https://tsecurity.de/de/2842379/sicherheitsluecken/cve-2023-32211-mozilla-firefox-up-to-112-wasm-code-denial-of-service-bug-1823379-nessus-id-239763/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2842379/sicherheitsluecken/cve-2023-32211-mozilla-firefox-up-to-112-wasm-code-denial-of-service-bug-1823379-nessus-id-239763/</guid>
<pubDate>Fri, 20 Jun 2025 15:23:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.mozilla:firefox">Mozilla Firefox up to 112</a>. It has been rated as <a href="https://vuldb.com/?kb.risk">problematic</a>. This issue affects some unknown processing of the component <em>wasm Code Handler</em>. The manipulation leads to denial of service.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.228581">CVE-2023-32211</a>. The attack may be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-32211 | Mozilla Thunderbird up to 102.10 wasm denial of service (Nessus ID 239763)]]></title>
<description><![CDATA[A vulnerability was found in Mozilla Thunderbird up to 102.10 and classified as problematic. This issue affects some unknown processing of the component wasm. The manipulation leads to denial of service.

The identification of this vulnerability is CVE-2023-32211. The attack may be initiated remo...]]></description>
<link>https://tsecurity.de/de/2842377/sicherheitsluecken/cve-2023-32211-mozilla-thunderbird-up-to-10210-wasm-denial-of-service-nessus-id-239763/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2842377/sicherheitsluecken/cve-2023-32211-mozilla-thunderbird-up-to-10210-wasm-denial-of-service-nessus-id-239763/</guid>
<pubDate>Fri, 20 Jun 2025 15:23:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.mozilla:thunderbird">Mozilla Thunderbird up to 102.10</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This issue affects some unknown processing of the component <em>wasm</em>. The manipulation leads to denial of service.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.230621">CVE-2023-32211</a>. The attack may be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-6275 | WebAssembly wabt up to 1.0.37 binary-reader-interp.cc GetFuncOffset use after free (Issue 2614)]]></title>
<description><![CDATA[A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulnerability is the function GetFuncOffset of the file src/interp/binary-reader-interp.cc. The manipulation leads to use after free.

This vulnerability is known as CVE-2025-6275. It...]]></description>
<link>https://tsecurity.de/de/2841228/sicherheitsluecken/cve-2025-6275-webassembly-wabt-up-to-1037-binary-reader-interpcc-getfuncoffset-use-after-free-issue-2614/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2841228/sicherheitsluecken/cve-2025-6275-webassembly-wabt-up-to-1037-binary-reader-interpcc-getfuncoffset-use-after-free-issue-2614/</guid>
<pubDate>Thu, 19 Jun 2025 23:21:56 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.webassembly:wabt">WebAssembly wabt up to 1.0.37</a>. It has been declared as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected by this vulnerability is the function <code>GetFuncOffset</code> of the file <em>src/interp/binary-reader-interp.cc</em>. The manipulation leads to use after free.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.313279">CVE-2025-6275</a>. It is possible to launch the attack on the local host. Furthermore, there is an exploit available.

A similar issue reported during the same timeframe was disputed by the code maintainer because it might not affect "real world wasm programs". Therefore, this entry might get disputed as well in the future.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-6273 | WebAssembly wabt up to 1.0.37 binary-reader-objdump.cc LogOpcode assertion (Issue 2574 / EUVD-2025-18694)]]></title>
<description><![CDATA[A vulnerability was found in WebAssembly wabt up to 1.0.37 and classified as problematic. This issue affects the function LogOpcode of the file src/binary-reader-objdump.cc. The manipulation leads to reachable assertion.

The identification of this vulnerability is CVE-2025-6273. Local access is ...]]></description>
<link>https://tsecurity.de/de/2841199/sicherheitsluecken/cve-2025-6273-webassembly-wabt-up-to-1037-binary-reader-objdumpcc-logopcode-assertion-issue-2574-euvd-2025-18694/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2841199/sicherheitsluecken/cve-2025-6273-webassembly-wabt-up-to-1037-binary-reader-objdumpcc-logopcode-assertion-issue-2574-euvd-2025-18694/</guid>
<pubDate>Thu, 19 Jun 2025 22:52:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.webassembly:wabt">WebAssembly wabt up to 1.0.37</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This issue affects the function <code>LogOpcode</code> of the file <em>src/binary-reader-objdump.cc</em>. The manipulation leads to reachable assertion.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.313277">CVE-2025-6273</a>. Local access is required to approach this attack. Furthermore, there is an exploit available.

The real existence of this vulnerability is still doubted at the moment.

The code maintainer explains that this issue might not affect "real world wasm programs".]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-6274 | WebAssembly wabt up to 1.0.37 binary-reader-interp.cc OnDataCount resource consumption (Issue 2598 / EUVD-2025-18693)]]></title>
<description><![CDATA[A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function OnDataCount of the file src/interp/binary-reader-interp.cc. The manipulation leads to resource consumption.

This vulnerability is traded as CVE-2025-6274. Attacking locally...]]></description>
<link>https://tsecurity.de/de/2841198/sicherheitsluecken/cve-2025-6274-webassembly-wabt-up-to-1037-binary-reader-interpcc-ondatacount-resource-consumption-issue-2598-euvd-2025-18693/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2841198/sicherheitsluecken/cve-2025-6274-webassembly-wabt-up-to-1037-binary-reader-interpcc-ondatacount-resource-consumption-issue-2598-euvd-2025-18693/</guid>
<pubDate>Thu, 19 Jun 2025 22:52:10 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.webassembly:wabt">WebAssembly wabt up to 1.0.37</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected is the function <code>OnDataCount</code> of the file <em>src/interp/binary-reader-interp.cc</em>. The manipulation leads to resource consumption.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.313278">CVE-2025-6274</a>. Attacking locally is a requirement. Furthermore, there is an exploit available.

A similar issue reported during the same timeframe was disputed by the code maintainer because it might not affect "real world wasm programs". Therefore, this entry might get disputed as well in the future.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-35419 | kanaka wac 385e1 WASM File /wac-asan/wa.c load_module heap-based overflow (Issue 18)]]></title>
<description><![CDATA[A vulnerability was found in kanaka wac 385e1. It has been declared as problematic. Affected by this vulnerability is the function load_module of the file /wac-asan/wa.c of the component WASM File Handler. The manipulation leads to heap-based buffer overflow.

This vulnerability is known as CVE-2...]]></description>
<link>https://tsecurity.de/de/2835404/sicherheitsluecken/cve-2024-35419-kanaka-wac-385e1-wasm-file-wac-asanwac-loadmodule-heap-based-overflow-issue-18/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2835404/sicherheitsluecken/cve-2024-35419-kanaka-wac-385e1-wasm-file-wac-asanwac-loadmodule-heap-based-overflow-issue-18/</guid>
<pubDate>Tue, 17 Jun 2025 05:07:04 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.kanaka:wac">kanaka wac 385e1</a>. It has been declared as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected by this vulnerability is the function <code>load_module</code> of the file <em>/wac-asan/wa.c</em> of the component <em>WASM File Handler</em>. The manipulation leads to heap-based buffer overflow.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.283579">CVE-2024-35419</a>. The attack can only be initiated within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Developers Are Rethinking the Cloud!]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 Cloud computing changed the game, but is it always the best choice for developers? 🤔 As local-first development gains traction, many are questioning the hidden trade-offs of cloud-based dev environments—latency, cost, security ris...]]></description>
<link>https://tsecurity.de/de/2831720/it-security-video/why-developers-are-rethinking-the-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2831720/it-security-video/why-developers-are-rethinking-the-cloud/</guid>
<pubDate>Sat, 14 Jun 2025 17:04:15 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/O-HWaKlzr5E/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/O-HWaKlzr5E?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Cloud computing changed the game, but is it always the best choice for developers? 🤔 As local-first development gains traction, many are questioning the hidden trade-offs of cloud-based dev environments—latency, cost, security risks, and shared resources. 🚀 Watch as experts break down why developers are rethinking the cloud and what it means for the future of coding!<br />
<br />
#CyberSecurity #CloudComputing #DevOps #SoftwareDevelopment #TechTrends #LocalFirst #CodingLife #ITSecurity #TechExplained #CloudVsLocal<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What 17,845 GitHub Repos Taught Us About Malicious MCP Servers]]></title>
<description><![CDATA[Audio version of this post, created with NotebookLM Deep Dive
  
    
    Your browser does not support the audio element.
  





Spoiler: VirusTotal Code Insight’s preliminary audit flagged nearly 8% of MCP (Model Context Protocol) servers on GitHub as potentially forged for evil, though the sa...]]></description>
<link>https://tsecurity.de/de/2814236/malware-trojaner-viren/what-17845-github-repos-taught-us-about-malicious-mcp-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2814236/malware-trojaner-viren/what-17845-github-repos-taught-us-about-malicious-mcp-servers/</guid>
<pubDate>Wed, 04 Jun 2025 11:01:08 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<center>
  Audio version of this post, created with NotebookLM Deep Dive<br>
  <audio controls preload="none">
    <source src="https://github.com/VirusTotalAudio/VirusTotalAudio/raw/refs/heads/main/Uncovering-Malicious-MCP-Servers.mp3" type="audio/mpeg">
    Your browser does not support the audio element.
  </audio>
</center>

<br>
<br>

<p>Spoiler: VirusTotal Code Insight’s preliminary audit flagged nearly 8% of MCP (Model Context Protocol) servers on GitHub as potentially forged for evil, though the sad truth is, bad intentions aren’t required to follow bad practices and publish code with critical vulnerabilities.
</p>

<p>Before we get started, a quick personal note. A couple of weeks ago, I announced at Google that I’m stepping away from my role as a manager of managers and getting back to my roots, focusing on the VirusTotal community. And I’m not doing it alone. I’m joined by some legendary names from the project’s early days, like Julio, the very first VirusTotal developer and Víctor, creator of YARA and YARA-X. In this new chapter, we’re going deep into AI, not just evolving VT and using it to analyze typical threats but also to hunt down the new ones riding the AI wave, like malicious models and MCPs among others.
</p>

<p>As many of you already know, MCP (Model Context Protocol) is a simple but powerful standard that lets large language models interact with external tools and APIs via JSON-RPC. Think of it as a universal adapter, MCP turns scripts, services, and data sources into callable functions that models like Claude, GPT or Gemini can use to answer complex queries or automate tasks. In just a few months, MCP has gone from niche to near-standard with native support across most major LLM platforms.
</p>

<p>Before building and releasing our own MCP server for VirusTotal (which is coming very soon) we wanted to take a step back and understand how this protocol is being used in the wild. Specifically: are people already abusing it to build malicious plugins? And if so, how could we detect and classify these threats inside VT?
</p>

<p>With that in mind, I set out to run a quick three-phase experiment (aka three humble python scripts). First, a harvesting phase to collect as many GitHub projects as possible by querying the API for MCP-related keywords like “model-context-protocol”, “server_mcp” or “define_mcp_tool”, among others. Then came a filtering step to isolate the interesting repos, not everything with "MCP" in the README is a real server implementation, so I built a scoring system to identify true servers based on dependency files, import statements, keywords in code, presence of mcp.json, and more. After applying that filter, we ended up with a focused dataset of 17,845 likely MCP server projects. 
</p>

<p>Finally, as the third phase, we ran a security review using VT Code Insight powered by Gemini 2.5 Flash and taking advantage of its 1-million token context window, speed, and code analysis skills to evaluate each project as a whole. We asked Code Insight for a basic verdict and to flag any High, Medium, or Low vulnerabilities. But after just a few hundred analyses we had to hit pause, Code Insight was surfacing so many issues that the results quickly became overwhelming. So we tightened things up with a second and more focused prompt, asking Code Insight to look specifically for signs of intentional malicious behavior along with reasoning that supported a conclusion of malice. 
</p>

<p>We let the new prompt run on the full dataset and Code Insight got to work. In the end, it marked 1,408 repositories as likely designed to be malicious. After checking some of these results by hand, two things were clear to me. First: there are many possible attack vectors that can be used through an MCP server. And second: Code Insight seems to trust human developers too much, it often assumes that some bad practices and the resulting critical bugs couldn’t be accidental. 
</p>

<p><i>“This pattern—creating a powerful, remotely triggerable code execution vulnerability and simultaneously preparing a collection of sensitive data (including data not needed for normal operation)—is characteristic of an intentional backdoor designed for data exfiltration and system compromise. The dynamic tool generation serves as a plausible cover for the unsafe use of `exec`.”</i> Oh, Code Insight… if only you knew the kind of chaos vibe coding is causing. We’re going to be very busy in cybersecurity cleaning up after these accidental masterpieces  
</p>

<p>
We’ve confirmed some of the flagged projects were just proof-of-concepts and security researcher demos, and many tiny “hello-world” examples were missing basic security features which Code Insight called out as “likely malicious”, because no sane developer would ship that to production. But even if you filter out the hobby projects, there’s still a scary amount of real attack vectors and critical vulnerabilities out there.
</p>

<p>
While we continue manually reviewing Code Insight’s reports to learn more about the issues and weak spots it uncovered, we also asked Gemini 2.5 Flash to help us categorize them. We provided it with the problem summaries from the 1,408 MCP-related repositories flagged as potentially problematic, and asked for a simple list, just a brief enumeration of the attack techniques involved. Gemini came back with the following list:
</p>



<div class="tabla-responsive">
    <table class="tabla-limpia">
        <thead>
            <tr>
                <th>Attack vector</th>
                <th>Example Indicators</th>
            </tr>
        </thead>
        <tbody>
            <tr>
              <td><b>Malicious-Server Supply Chain</b></td>
                <td>Self-update scripts, install hooks from non-canonical URLs, <span class="codigo-en-tabla">latest</span> tag pulls.</td>
            </tr>
            <tr>
                <td><b>Rogue Server / Impersonation</b></td>
                <td>Hard-coded IPs or typo-squatted domains, no TLS/mTLS verification.</td>
            </tr>
            <tr>
                <td><b>Credential Harvesting</b></td>
                <td>Code that reads <span class="codigo-en-tabla">~/.aws</span>, Keychain, or env vars <strong>and</strong> posts to external endpoint.</td>
            </tr>
            <tr>
                <td><b>Tool-Based RCE &amp; File Ops</b></td>
                <td><span class="codigo-en-tabla">subprocess</span>, <span class="codigo-en-tabla">exec</span>, or <span class="codigo-en-tabla">rm -rf</span> paths built from LLM/user input.</td>
            </tr>
            <tr>
                <td><b>Server-Side Command Injection</b></td>
                <td>Server concatenates JSON-RPC params into shell/SQL without escaping.</td>
            </tr>
             <tr>
                <td><b>Semantic-Gap Poisoning</b></td>
                <td>Manifest says “read-only”; implementation writes files or opens sockets.</td>
            </tr>
            <tr>
                <td><b>Over-broad Permissions</b></td>
                <td>OAuth scopes <span class="codigo-en-tabla">*</span> / “full_access”, multiple data silos bridged in one tool.</td>
            </tr>
            <tr>
                <td><b>Indirect Prompt Injection</b></td>
                <td>HTML comments, zero-width chars, or Base64 blobs returned to the host.</td>
            </tr>
            <tr>
                <td><b>Context/Data Poisoning</b></td>
                <td>Unvalidated web-scrape fed straight into <span class="codigo-en-tabla">context=</span> parameter.</td>
            </tr>
            <tr>
                <td><b>Sampling-Feature Abuse</b></td>
                <td>Server requests giant completions <em>before</em> any other call; leaks system prompt.</td>
            </tr>
            <tr>
                <td><b>Living-Off-The-Land</b></td>
                <td>Malicious server does nothing but orchestrate trusted tools already installed.</td>
            </tr>
             <tr>
                <td><b>Chained MCP Exploitation</b></td>
                <td>Output from Server A becomes params for Server B within one loop.</td>
            </tr>
             <tr>
                <td><b>Financial-Fraud Tools / DoS / Persistence</b></td>
                <td>Payment APIs with LLM-supplied dest-IDs, infinite loops without rate limits, hot-swapped binaries.</td>
            </tr>
        </tbody>
    </table>
</div>


<p>If you're building or defending around MCPs, there are a few quick wins to keep things safer:
</p><ul>
<li><b>treat MCP servers like browser extensions</b> (sign, hash, and pin specific versions)
</li><li><b>isolate them in containers or WASM sandboxes</b> with strict file and network limits
</li><li><b>make permissions visible and revocable</b> through a clear, zero-trust-style UI
</li><li><b>and never let model outputs go unfiltered</b>, strip out sneaky stuff like invisible characters, HTML comments, or rogue script tags before looping anything back into your LLM.
</li></ul>


<p>MCPs are growing fast (almost 18,000 servers already in the wild), and with that growth comes a mountain of security debt. The good news? We’ll soon be launching a dedicated feature in VirusTotal to analyze MCP servers.<br>Stay tuned… we’re just getting started
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome extension to simplify WASM reverse engineering.]]></title>
<description><![CDATA[While working on a WebAssembly crackme challenge, I quickly realized how limited the in-browser tools are for editing WASM memory. That’s what inspired me to build WASM Memory Tools. A Chrome extension that integrates into the DevTools panel and lets you: Read, write, and search WASM memory chrom...]]></description>
<link>https://tsecurity.de/de/2800646/reverse-engineering/chrome-extension-to-simplify-wasm-reverse-engineering/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2800646/reverse-engineering/chrome-extension-to-simplify-wasm-reverse-engineering/</guid>
<pubDate>Tue, 27 May 2025 17:37:29 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>While working on a WebAssembly crackme challenge, I quickly realized how limited the in-browser tools are for editing WASM memory. That’s what inspired me to build WASM Memory Tools. A Chrome extension that integrates into the DevTools panel and lets you: Read, write, and search WASM memory</p> <p>chrome store : <a href="https://chromewebstore.google.com/detail/wasm-memory-tools/ibnlkehbankkledbceckejaihgpgklkj">https://chromewebstore.google.com/detail/wasm-memory-tools/ibnlkehbankkledbceckejaihgpgklkj</a></p> <p>github : <a href="https://github.com/kernel64/wasm-mem-tools-addon">https://github.com/kernel64/wasm-mem-tools-addon</a> </p> <p>I'd love to hear your feedback and suggestions!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/0xfffm4b5"> /u/0xfffm4b5 </a> <br> <span><a href="https://chromewebstore.google.com/detail/wasm-memory-tools/ibnlkehbankkledbceckejaihgpgklkj">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1kwq9iq/chrome_extension_to_simplify_wasm_reverse/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[WASM the future for running Windows apps on Linux ?]]></title>
<description><![CDATA[Yesterday I was watching a YouTube movie about the applications of WebAssembly (WASM) and it said that applications like Photoshop could be packaged as WASM and then run on any machine.  As a matter of fact, Adobe already launched a web version of Photoshop using WASM.  So will WASM be the future...]]></description>
<link>https://tsecurity.de/de/2792288/linux-tipps/wasm-the-future-for-running-windows-apps-on-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2792288/linux-tipps/wasm-the-future-for-running-windows-apps-on-linux/</guid>
<pubDate>Thu, 22 May 2025 19:21:06 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Yesterday I was watching a YouTube movie about the applications of WebAssembly (WASM) and it said that applications like Photoshop could be packaged as WASM and then run on any machine. </p> <p>As a matter of fact, Adobe already launched a web version of Photoshop using WASM. </p> <p>So will WASM be the future for Linux to run any non-Linux app on Linux without the need for Wine or Bottles ? And how will this impact Steam and can it be said that this will in fact open a new way of creating web/desktop apps written from any OS and running anywhere ? </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/InstantCoder"> /u/InstantCoder </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ksw2lq/wasm_the_future_for_running_windows_apps_on_linux/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ksw2lq/wasm_the_future_for_running_windows_apps_on_linux/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2021-38297 | Google Go up to 1.16.8/1.17.1 WASM module buffer overflow (Nessus ID 236557)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Google Go up to 1.16.8/1.17.1. This affects an unknown part of the component WASM module. The manipulation leads to buffer overflow.

This vulnerability is uniquely identified as CVE-2021-38297. The attack needs to be approached within the ...]]></description>
<link>https://tsecurity.de/de/2790231/sicherheitsluecken/cve-2021-38297-google-go-up-to-11681171-wasm-module-buffer-overflow-nessus-id-236557/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2790231/sicherheitsluecken/cve-2021-38297-google-go-up-to-11681171-wasm-module-buffer-overflow-nessus-id-236557/</guid>
<pubDate>Wed, 21 May 2025 21:35:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/?product.google:go">Google Go up to 1.16.8/1.17.1</a>. This affects an unknown part of the component <em>WASM module</em>. The manipulation leads to buffer overflow.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.184527">CVE-2021-38297</a>. The attack needs to be approached within the local network. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Compile SQLite from source to WASM in Firebase Studio]]></title>
<description><![CDATA[Author: Firebase - Bewertung: 1x - Views:2 Rody, a Developer Relations Engineer for Firebase Studio shares how easy it is to get started with a blank template in Firebase Studio. In this video, he shows how to clone your code inside a workstation and use nix to install dependencies. Watch a step ...]]></description>
<link>https://tsecurity.de/de/2776373/it-security-video/compile-sqlite-from-source-to-wasm-in-firebase-studio/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2776373/it-security-video/compile-sqlite-from-source-to-wasm-in-firebase-studio/</guid>
<pubDate>Wed, 14 May 2025 18:04:28 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/hox-Sv8ZHxE/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Firebase - Bewertung: 1x - Views:2 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/hox-Sv8ZHxE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Rody, a Developer Relations Engineer for Firebase Studio shares how easy it is to get started with a blank template in Firebase Studio. In this video, he shows how to clone your code inside a workstation and use nix to install dependencies. Watch a step by step tutorial on cloning code, setting dev.nix, web preview, and leverage Gemini in Firebase Studio.<br />
<br />
Chapters:<br />
0:00 - Get started<br />
1:16 - Cloning SQLite and Emscripten <br />
1:42 - Set up the VM<br />
3:47 - Configure web preview<br />
5:15 - Leverage Gemini<br />
5:47 - Recap<br />
<br />
Firebase Studio → https://goo.gle/firebasestudio <br />
<br />
 #Firebase #SQLite #WASM #NixOS<br />
<br />
Speaker: Rody Davis<br />
Products Mentioned:,  Firebase,<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by Debian (fossil, libapache2-mod-auth-openidc, and request-tracker4), Fedora (thunderbird), Mageia (firefox and thunderbird), SUSE (389-ds, apparmor, cargo-c, chromium, go1.24, govulncheck-vulndb, java-1_8_0-openjdk, kanidm, libsoup, mozjs102, openssl-1_1, opens...]]></description>
<link>https://tsecurity.de/de/2766822/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2766822/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 09 May 2025 15:36:12 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (fossil, libapache2-mod-auth-openidc, and request-tracker4), <b>Fedora</b> (thunderbird), <b>Mageia</b> (firefox and thunderbird), <b>SUSE</b> (389-ds, apparmor, cargo-c, chromium, go1.24, govulncheck-vulndb, java-1_8_0-openjdk, kanidm, libsoup, mozjs102, openssl-1_1, openssl-3, python-Django, sccache, tealdeer, tomcat, transfig, wasm-bindgen, and wireshark), and <b>Ubuntu</b> (libreoffice and python-h11).]]></content:encoded>
</item>
<item>
<title><![CDATA[Tool: YARA Playground]]></title>
<description><![CDATA[Hi all, I often find myself needing to sanity-check a YARA rule against a test string or small binary, but spinning up the CLI or Docker feels heavy. So I built **YARA Playground** – a single-page web app that compiles `libyara` to WebAssembly and runs entirely client-side (no samples leave your ...]]></description>
<link>https://tsecurity.de/de/2753599/reverse-engineering/tool-yara-playground/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2753599/reverse-engineering/tool-yara-playground/</guid>
<pubDate>Fri, 02 May 2025 03:40:18 +0200</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi all,</p> <p>I often find myself needing to sanity-check a YARA rule against a test</p> <p>string or small binary, but spinning up the CLI or Docker feels heavy.</p> <p>So I built **YARA Playground** – a single-page web app that compiles</p> <p>`libyara` to WebAssembly and runs entirely client-side (no samples leave</p> <p>your browser).</p> <p>• CodeMirror 6 editors for rule + sample </p> <p>• WASM YARA-X engine, error guard for slow patterns </p> <p>• Shows pretty JSON, and tabular matches</p> <p>• Supports 10 MiB binary upload, auto-persists last rule/sample </p> <p><a href="https://www.yaraplayground.com/">https://www.yaraplayground.com</a></p> <p>Tech stack: Vite, TypeScript, CodeMirror, libyara-wasm (≈230 kB),</p> <p>Would love feedback, feature requests or bug reports (especially edge-</p> <p>case rules).</p> <p>I hope it's useful to someone, thanks!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Diligent_Desk5592"> /u/Diligent_Desk5592 </a> <br> <span><a href="https://www.yaraplayground.com/">[link]</a></span>   <span><a href="https://www.reddit.com/r/ReverseEngineering/comments/1kcpbw1/tool_yara_playground/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Updates] 2025-04-07 - RT-Kernels, Wine, Thunderbird]]></title>
<description><![CDATA[Hello community, here we have another set of package updates. Since I’m still recovering from my move back to Europe from Asia, I might be less responsive on the forum. So lets test these packages thoroughly so we can do another stable branch snap.
Current Promotions

Find out all about our curre...]]></description>
<link>https://tsecurity.de/de/2709315/unix-server/testing-updates-2025-04-07-rt-kernels-wine-thunderbird/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2709315/unix-server/testing-updates-2025-04-07-rt-kernels-wine-thunderbird/</guid>
<pubDate>Mon, 07 Apr 2025 10:04:44 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates. Since I’m still recovering from my move back to Europe from Asia, I might be less responsive on the forum. So lets test these packages thoroughly so we can do another <strong>stable</strong> branch snap.</p>
<h3><a name="p-769346-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-769346-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Find out all about our current <strong>Gaming Laptop</strong> the <a href="https://hero.manjaro.org/">Hero</a> with Manjaro pre-installed from Spain!</li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-769346-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-769346-recent-news-2"></a>Recent News</h2>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-25-0-zetar-release-review/174444" class="inline-onebox">Manjaro 25.0 Zetar Release Review</a></li>
</ul>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-updates-2025-04-07-rt-kernels-wine-thunderbird/176733/1">(click for more details)</a>
<h2><a name="p-769346-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-769346-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li><strong>RT-Kernels</strong></li>
<li><strong>Thunderbird</strong> <a href="https://www.thunderbird.net/en-US/thunderbird/137.0.1/releasenotes/">137.0.1</a></li>
<li><strong>Wine</strong> <a href="https://www.winehq.org/news/2025040401">10.5</a></li>
</ul>
<h2><a name="p-769346-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-769346-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/testing-updates-2025-04-07-rt-kernels-wine-thunderbird/176733/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-updates-2025-04-07-rt-kernels-wine-thunderbird/176733/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<h2><a name="p-769346-our-current-supported-kernels-5" class="anchor" href="https://forum.manjaro.org/#p-769346-our-current-supported-kernels-5"></a>Our current supported kernels</h2>
<ul>
<li>linux54 5.4.290</li>
<li>linux510 5.10.235</li>
<li>linux515 5.15.178</li>
<li>linux61 6.1.132</li>
<li>linux66 6.6.85</li>
<li>linux612 6.12.21</li>
<li>linux613 6.13.9</li>
<li>linux614 6.14.0</li>
<li>linux61-rt 6.1.132_rt50</li>
<li>linux66-rt 6.6.85_rt53</li>
<li>linux612-rt 6.12.16_rt9</li>
<li>linux613-rt 6.13_rt5</li>
</ul>
<p><strong>Package Changes</strong> (Mon Apr 7 08:42:40 CEST 2025)</p>
<ul>
<li>testing core x86_64:  5 new and 5 removed package(s)</li>
<li>testing extra x86_64:  217 new and 216 removed package(s)</li>
<li>testing multilib x86_64:  3 new and 3 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20250405             20250407
-------------------------------------------------------------------------------
                          linux61-rt       6.1.128_rt49-1       6.1.132_rt50-1
                  linux61-rt-headers       6.1.128_rt49-1       6.1.132_rt50-1
                          linux66-rt        6.6.84_rt52-1        6.6.85_rt53-1
                  linux66-rt-headers        6.6.84_rt52-1        6.6.85_rt53-1
                     manjaro-release      25.0.0preview-1             25.0.0-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20250405             20250407
-------------------------------------------------------------------------------
                             asusctl             6.1.10-1             6.1.12-1
                         envycontrol              3.5.1-2              3.5.2-1
      gnome-shell-extension-gamemode               12.0-2               12.0-3
                    inputplumber-git 0.51.0.r0.g03c2642-1 0.51.1.r0.g2324b42-1
                linux61-rt-acpi_call             1.2.2-42             1.2.2-43
                 linux61-rt-bbswitch               0.8-41               0.8-42
              linux61-rt-broadcom-wl      6.30.223.271-41      6.30.223.271-42
             linux61-rt-nvidia-390xx           390.157-41           390.157-42
             linux61-rt-nvidia-470xx        470.256.02-20        470.256.02-21
                   linux61-rt-nvidia         570.133.07-1         570.133.07-2
              linux61-rt-nvidia-open         570.133.07-1         570.133.07-2
                    linux61-rt-r8168           8.055.00-3           8.055.00-4
                linux61-rt-rtl8723bu          20240303-24          20240303-25
                 linux61-rt-tp_smapi              0.44-35              0.44-36
              linux61-rt-vhba-module           20240917-9          20240917-10
  linux61-rt-virtualbox-host-modules              7.1.6-5              7.1.6-6
                linux66-rt-acpi_call             1.2.2-36             1.2.2-37
                 linux66-rt-bbswitch               0.8-35               0.8-36
              linux66-rt-broadcom-wl      6.30.223.271-36      6.30.223.271-37
             linux66-rt-nvidia-390xx           390.157-35           390.157-36
             linux66-rt-nvidia-470xx        470.256.02-24        470.256.02-25
                   linux66-rt-nvidia         570.133.07-2         570.133.07-3
              linux66-rt-nvidia-open         570.133.07-2         570.133.07-3
                    linux66-rt-r8168           8.055.00-6           8.055.00-7
                linux66-rt-rtl8723bu          20240303-28          20240303-29
                 linux66-rt-tp_smapi              0.44-10              0.44-11
              linux66-rt-vhba-module          20240917-12          20240917-13
  linux66-rt-virtualbox-host-modules              7.1.6-8              7.1.6-9
                       manjaro-hello              0.8.1-1              0.8.1-2
                         needrestart                3.9-1               3.10-1
                 python-pyamdgpuinfo              2.1.6-3              2.1.7-1
                  rog-control-center             6.1.10-1             6.1.12-1


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20250405             20250407
-------------------------------------------------------------------------------
                        alertmanager             0.28.1-1             0.28.1-2
                          apostrophe                3.2-5                3.2-6
                    app-icon-preview              3.4.0-3              3.4.0-4
                           azure-cli             2.70.0-1             2.71.0-1
                             baresip             3.21.0-1             3.21.0-2
                               brook           20221010-2           20221212-1
                browserpass-chromium              3.9.0-1             3.10.2-1
                 browserpass-firefox              3.9.0-2             3.10.2-1
                      cargo-binstall             1.12.2-1             1.12.3-1
                             cargo-c            0.10.11-1            0.10.12-1
                           cargo-deb             2.11.4-1             2.12.0-1
                        cargo-expand            1.0.104-1            1.0.106-1
                      cargo-generate             0.23.1-1             0.23.2-1
                      cargo-show-asm             0.2.48-1             0.2.49-1
                             certbot              3.3.0-1              3.3.0-2
                             chezmoi             2.61.0-2             2.62.0-1
                           citations              0.8.0-3              0.8.0-4
                            composer              2.8.6-1              2.8.8-1
                                cotp              1.9.2-1              1.9.3-1
                     cotp-converters              1.9.2-1              1.9.3-1
                            datamash                1.8-2                1.9-1
                   deepin-icon-theme         2025.03.20-1         2025.03.27-1
                     deepin-terminal             6.0.17-1              6.5.0-1
                                deno              2.2.3-1              2.2.4-1
                                dune             3.17.1-2             3.17.2-1
                            ejabberd              24.12-4              25.03-1
                              eslint             9.23.0-1             9.24.0-1
                              falkon            24.12.3-2            24.12.3-3
                           fcitx5-qt              5.1.9-3              5.1.9-4
                              fluidd             1.32.6-1             1.34.0-1
                             furnace              0.6.8-1            0.6.8.1-1
                           gamescope             3.16.2-1             3.16.3-1
                       gnome-session             47.0.1-1             47.0.1-2
                     gtk-layer-shell              0.9.0-1              0.9.1-1
               gtk-update-icon-cache           1:4.18.3-1           1:4.18.3-2
                                gtk4           1:4.18.3-1           1:4.18.3-2
                          gtk4-demos           1:4.18.3-1           1:4.18.3-2
                           gtk4-docs           1:4.18.3-1           1:4.18.3-2
                      home-assistant         1:2025.3.4-1         1:2025.4.1-1
                        hyprgraphics              0.1.2-1              0.1.3-1
                          ibus-anthy             1.5.16-2             1.5.17-1
                              jasper              4.2.4-2              4.2.5-1
                          jasper-doc              4.2.4-2              4.2.5-1
                     jellyfin-server            10.10.6-2            10.10.7-1
                        jellyfin-web            10.10.6-1            10.10.7-1
                                jose                 11-3                 14-1
                             jujutsu             0.27.0-1             0.28.1-1
                     lib32-rust-libs           1:1.85.1-1           1:1.86.0-1
                               libre             3.21.0-1             3.21.1-1
                 libretro-beetle-psx               2754-1               2760-1
              libretro-beetle-psx-hw               2754-1               2760-1
                   libretro-gambatte               1068-1               1069-1
            libretro-genesis-plus-gx               2216-1               2217-1
                       libretro-mame              93765-1              94042-1
                   libretro-nestopia              1:140-1              1:146-1
                   libretro-overlays                305-1                310-1
                  libretro-picodrive               2686-1               2736-1
                     libretro-ppsspp              42407-1              42704-1
                    libretro-scummvm             161052-1             161421-1
                            libupnpp             0.26.8-1              1.0.2-1
                                lnav             0.12.3-1             0.12.4-1
                            lua-zlib              1:1.2-6              1:1.3-1
                          lua51-zlib              1:1.2-6              1:1.3-1
                          lua52-zlib              1:1.2-6              1:1.3-1
                          lua53-zlib              1:1.2-6              1:1.3-1
                                 lxc            1:6.0.3-1            1:6.0.4-1
                       lxqt-qtplugin              2.1.0-1              2.1.0-2
                                  ly              1.0.3-1              1.0.3-2
                             mbedtls              3.6.2-1              3.6.3-1
                            mbedtls2             2.28.9-1            2.28.10-1
                            mesonlsp              4.3.7-4              4.3.7-5
                          minizip-ng              4.0.8-1              4.0.9-1
                                musl              1.2.5-4              1.2.5-5
                        musl-aarch64              1.2.5-4              1.2.5-5
                        musl-riscv64              1.2.5-4              1.2.5-5
                                nccl             2.26.2-1             2.26.2-2
                    neovim-lspconfig              1.7.0-1              1.8.0-1
                          paper-clip              5.5.1-3              5.5.1-4
                                 pik             0.18.1-1             0.19.0-1
                       prismlauncher                9.2-4                9.3-1
                         python-acme              3.3.0-1              3.3.0-2
                    python-dbus-fast             2.39.5-1             2.44.1-1
      python-django-modeltranslation            0.19.12-2            0.19.13-1
                        python-faker             36.2.3-1             37.0.0-1
                    python-icalendar              6.1.3-1              6.1.3-2
                    python-jellyfish              1.1.3-1              1.2.0-1
                         python-path            16.10.2-1            16.11.0-1
                      python-pikepdf              9.5.2-2              9.6.0-1
                     python-queuelib              1.7.0-2              1.8.0-1
              python-setuptools-rust             1.11.0-1             1.11.1-1
                     python-tenacity              9.0.0-2              9.1.0-1
                   python-validators             0.20.5-1             0.20.6-1
                      python-ziafont                0.8-2                0.9-1
                       qt6-webengine              6.9.0-1              6.9.0-3
                            radicale              3.5.0-1              3.5.1-1
                          rofi-emoji              4.0.0-1              4.1.0-1
                                rust           1:1.85.1-1           1:1.86.0-1
                    rust-aarch64-gnu           1:1.85.1-1           1:1.86.0-1
                   rust-aarch64-musl           1:1.85.1-1           1:1.86.0-1
                           rust-musl           1:1.85.1-1           1:1.86.0-1
                            rust-src           1:1.85.1-1           1:1.86.0-1
                           rust-wasm           1:1.85.1-1           1:1.86.0-1
                       share-preview              0.5.0-3              0.5.0-4
                         simple-scan               46.0-3               48.1-1
                                 stb      r2193.31707d1-1      r2205.f056911-1
                          strawberry              1.2.7-2              1.2.8-1
                          streamlink              7.1.3-1              7.2.0-1
                             sudo-rs              0.2.4-6              0.2.5-1
                                 syd             3.32.6-1             3.32.7-1
                    symbolic-preview              0.0.9-4              0.0.9-5
                   system76-firmware             1.0.70-1             1.0.71-1
                            systemfd              0.4.3-1              0.4.6-1
                          textpieces            4.1.1_1-1              4.2.0-3
                         thunderbird              137.0-1            137.0.1-1
                 thunderbird-i18n-af              137.0-1            137.0.1-1
                 thunderbird-i18n-ar              137.0-1            137.0.1-1
                thunderbird-i18n-ast              137.0-1            137.0.1-1
                 thunderbird-i18n-be              137.0-1            137.0.1-1
                 thunderbird-i18n-bg              137.0-1            137.0.1-1
                 thunderbird-i18n-br              137.0-1            137.0.1-1
                 thunderbird-i18n-ca              137.0-1            137.0.1-1
                thunderbird-i18n-cak              137.0-1            137.0.1-1
                 thunderbird-i18n-cs              137.0-1            137.0.1-1
                 thunderbird-i18n-cy              137.0-1            137.0.1-1
                 thunderbird-i18n-da              137.0-1            137.0.1-1
                 thunderbird-i18n-de              137.0-1            137.0.1-1
                thunderbird-i18n-dsb              137.0-1            137.0.1-1
                 thunderbird-i18n-el              137.0-1            137.0.1-1
              thunderbird-i18n-en-gb              137.0-1            137.0.1-1
              thunderbird-i18n-en-us              137.0-1            137.0.1-1
              thunderbird-i18n-es-ar              137.0-1            137.0.1-1
              thunderbird-i18n-es-es              137.0-1            137.0.1-1
                 thunderbird-i18n-et              137.0-1            137.0.1-1
                 thunderbird-i18n-eu              137.0-1            137.0.1-1
                 thunderbird-i18n-fi              137.0-1            137.0.1-1
                 thunderbird-i18n-fr              137.0-1            137.0.1-1
              thunderbird-i18n-fy-nl              137.0-1            137.0.1-1
              thunderbird-i18n-ga-ie              137.0-1            137.0.1-1
                 thunderbird-i18n-gd              137.0-1            137.0.1-1
                 thunderbird-i18n-gl              137.0-1            137.0.1-1
                 thunderbird-i18n-he              137.0-1            137.0.1-1
                 thunderbird-i18n-hr              137.0-1            137.0.1-1
                thunderbird-i18n-hsb              137.0-1            137.0.1-1
                 thunderbird-i18n-hu              137.0-1            137.0.1-1
              thunderbird-i18n-hy-am              137.0-1            137.0.1-1
                 thunderbird-i18n-id              137.0-1            137.0.1-1
                 thunderbird-i18n-is              137.0-1            137.0.1-1
                 thunderbird-i18n-it              137.0-1            137.0.1-1
                 thunderbird-i18n-ja              137.0-1            137.0.1-1
                 thunderbird-i18n-ka              137.0-1            137.0.1-1
                thunderbird-i18n-kab              137.0-1            137.0.1-1
                 thunderbird-i18n-kk              137.0-1            137.0.1-1
                 thunderbird-i18n-ko              137.0-1            137.0.1-1
                 thunderbird-i18n-lt              137.0-1            137.0.1-1
                 thunderbird-i18n-ms              137.0-1            137.0.1-1
              thunderbird-i18n-nb-no              137.0-1            137.0.1-1
                 thunderbird-i18n-nl              137.0-1            137.0.1-1
              thunderbird-i18n-nn-no              137.0-1            137.0.1-1
              thunderbird-i18n-pa-in              137.0-1            137.0.1-1
                 thunderbird-i18n-pl              137.0-1            137.0.1-1
              thunderbird-i18n-pt-br              137.0-1            137.0.1-1
              thunderbird-i18n-pt-pt              137.0-1            137.0.1-1
                 thunderbird-i18n-rm              137.0-1            137.0.1-1
                 thunderbird-i18n-ro              137.0-1            137.0.1-1
                 thunderbird-i18n-ru              137.0-1            137.0.1-1
                 thunderbird-i18n-sk              137.0-1            137.0.1-1
                 thunderbird-i18n-sl              137.0-1            137.0.1-1
                 thunderbird-i18n-sq              137.0-1            137.0.1-1
                 thunderbird-i18n-sr              137.0-1            137.0.1-1
              thunderbird-i18n-sv-se              137.0-1            137.0.1-1
                 thunderbird-i18n-th              137.0-1            137.0.1-1
                 thunderbird-i18n-tr              137.0-1            137.0.1-1
                 thunderbird-i18n-uk              137.0-1            137.0.1-1
                 thunderbird-i18n-uz              137.0-1            137.0.1-1
                 thunderbird-i18n-vi              137.0-1            137.0.1-1
              thunderbird-i18n-zh-cn              137.0-1            137.0.1-1
              thunderbird-i18n-zh-tw              137.0-1            137.0.1-1
                            tomcat10            10.1.36-1            10.1.40-1
                            upmpdcli              1.9.3-1              1.9.3-2
                               v2ray             5.18.0-1             5.19.0-1
         v2ray-domain-list-community     20250401022534-1     20250405160157-1
                         v2ray-geoip       202503281421-1       202504050136-1
                                vale             3.11.1-1             3.11.2-1
       vapoursynth-plugin-bestsource              1:R10-1              1:R11-1
                        countryfetch                    -              0.1.9-3


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20250405             20250407
-------------------------------------------------------------------------------
                                wine               10.4-1               10.5-1
                           wine-mono              9.4.0-1             10.0.0-1
                        wine-staging               10.4-1               10.5-1

</code></pre>
<p><a href="https://forum.manjaro.org/t/testing-updates-2025-04-07-rt-kernels-wine-thunderbird/176733/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 1 participant</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-updates-2025-04-07-rt-kernels-wine-thunderbird/176733">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Announces 'Hyperlight Wasm': Speedy VM-Based Security at Scale with a WebAssembly Runtime]]></title>
<description><![CDATA[Cloud providers like the security of running things in virtual machines "at scale" — even though VMs "are not known for having fast cold starts or a small footprint..." noted Microsoft's Open Source blog last November. So Microsoft's Azure Core Upstream team built an open source Rust library call...]]></description>
<link>https://tsecurity.de/de/2695619/it-security-nachrichten/microsoft-announces-hyperlight-wasm-speedy-vm-based-security-at-scale-with-a-webassembly-runtime/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2695619/it-security-nachrichten/microsoft-announces-hyperlight-wasm-speedy-vm-based-security-at-scale-with-a-webassembly-runtime/</guid>
<pubDate>Sun, 30 Mar 2025 21:33:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cloud providers like the security of running things in virtual machines "at scale" — even though VMs "are not known for having fast cold starts or a small footprint..." noted Microsoft's Open Source blog last November. So Microsoft's Azure Core Upstream team built an open source Rust library called Hyperlight "to execute functions as fast as possible while isolating those functions within a VM." 

But that was just the beginning...

 Then, we showed how to run Rust functions really, really fast, followed by using C to [securely] run Javascript. In February 2025, the Cloud Native Computing Foundation (CNCF) voted to onboard Hyperlight into their Sandbox program [for early-stage projects]. 

[This week] we're announcing the release of Hyperlight Wasm: a Hyperlight virtual machine "micro-guest" that can run wasm component workloads written in many programming languages... 

Traditional virtual machines do a lot of work to be able to run programs. Not only do they have to load an entire operating system, they also boot up the virtual devices that the operating system depends on. Hyperlight is fast because it doesn't do that work; all it exposes to its VM guests is a linear slice of memory and a CPU. No virtual devices. No operating system. But this speed comes at the cost of compatibility. Chances are that your current production application expects a Linux operating system running on the x86-64 architecture (hardware), not a bare linear slice of memory... 

[B]uilding Hyperlight with a WebAssembly runtime — wasmtime — enables any programming language to execute in a protected Hyperlight micro-VM without any prior knowledge of Hyperlight at all. As far as program authors are concerned, they're just compiling for the wasm32-wasip2 target... Executing workloads in the Hyperlight Wasm guest isn't just possible for compiled languages like C, Go, and Rust, but also for interpreted languages like Python, JavaScript, and C#. The trick here, much like with containers, is to also include a language runtime as part of the image... Programming languages, runtimes, application platforms, and cloud providers are all starting to offer rich experiences for WebAssembly out of the box. If we do things right, you will never need to think about whether your application is running inside of a Hyperlight Micro-VM in Azure. You may never know your workload is executing in a Hyperlight Micro VM. And that's a good thing. 

While a traditional virtual-device-based VM takes about 125 milliseconds to load, "When the Hyperlight VMM creates a new VM, all it needs do to is create a new slice of memory and load the VM guest, which in turn loads the wasm workload. This takes about 1-2 milliseconds today, and work is happening to bring that number to be less than 1 millisecond in the future." 

And there's also double security due to Wasmtime's software-defined runtime sandbox within Hyperlight's larger VM...<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Microsoft+Announces+'Hyperlight+Wasm'%3A+Speedy+VM-Based+Security+at+Scale+with+a+WebAssembly+Runtime%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F25%2F03%2F30%2F0627205%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F25%2F03%2F30%2F0627205%2Fmicrosoft-announces-hyperlight-wasm-speedy-vm-based-security-at-scale-with-a-webassembly-runtime%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/25/03/30/0627205/microsoft-announces-hyperlight-wasm-speedy-vm-based-security-at-scale-with-a-webassembly-runtime?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-4775 | Mozilla Firefox up to 125 WASM memory corruption]]></title>
<description><![CDATA[A vulnerability was found in Mozilla Firefox up to 125. It has been declared as critical. This vulnerability affects unknown code of the component WASM Handler. The manipulation leads to memory corruption.

This vulnerability was named CVE-2024-4775. The attack can be initiated remotely. There is...]]></description>
<link>https://tsecurity.de/de/2694802/sicherheitsluecken/cve-2024-4775-mozilla-firefox-up-to-125-wasm-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2694802/sicherheitsluecken/cve-2024-4775-mozilla-firefox-up-to-125-wasm-memory-corruption/</guid>
<pubDate>Sun, 30 Mar 2025 07:21:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.mozilla:firefox">Mozilla Firefox up to 125</a>. It has been declared as <a href="https://vuldb.com/?kb.risk">critical</a>. This vulnerability affects unknown code of the component <em>WASM Handler</em>. The manipulation leads to memory corruption.

This vulnerability was named <a href="https://vuldb.com/?source_cve.264328">CVE-2024-4775</a>. The attack can be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Virtual Machine: Microsoft veröffentlicht Hyperlight Wasm]]></title>
<description><![CDATA[Das experimentelle Projekt erlaubt das Ausführen von WebAssembly-Modulen innerhalb einer VM-basierten Sandbox. Es legt den Fokus auf Performance und Sicherheit.]]></description>
<link>https://tsecurity.de/de/2692743/it-nachrichten/virtual-machine-microsoft-veroeffentlicht-hyperlight-wasm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2692743/it-nachrichten/virtual-machine-microsoft-veroeffentlicht-hyperlight-wasm/</guid>
<pubDate>Fri, 28 Mar 2025 17:00:54 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das experimentelle Projekt erlaubt das Ausführen von WebAssembly-Modulen innerhalb einer VM-basierten Sandbox. Es legt den Fokus auf Performance und Sicherheit.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-35426 | andoma vmir e8117 /src/vmir_wasm_parser.c init_local_vars stack-based overflow (Issue 24)]]></title>
<description><![CDATA[A vulnerability was found in andoma vmir e8117. It has been classified as critical. Affected is the function init_local_vars of the file /src/vmir_wasm_parser.c. The manipulation leads to stack-based buffer overflow.

This vulnerability is traded as CVE-2024-35426. Access to the local network is ...]]></description>
<link>https://tsecurity.de/de/2673512/sicherheitsluecken/cve-2024-35426-andoma-vmir-e8117-srcvmirwasmparserc-initlocalvars-stack-based-overflow-issue-24/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2673512/sicherheitsluecken/cve-2024-35426-andoma-vmir-e8117-srcvmirwasmparserc-initlocalvars-stack-based-overflow-issue-24/</guid>
<pubDate>Tue, 18 Mar 2025 17:08:42 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.andoma:vmir">andoma vmir e8117</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected is the function <code>init_local_vars</code> of the file <em>/src/vmir_wasm_parser.c</em>. The manipulation leads to stack-based buffer overflow.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.283596">CVE-2024-35426</a>. Access to the local network is required for this attack. There is no exploit available.<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: gemma-3-12b-it<br><br><p><strong>CVE-2024-35426: Stack-basierter Pufferüberlauf in andoma vmir e8117 – Eine detaillierte Analyse</strong></p><br />
<p><strong>Abstract:</strong> Dieser Artikel analysiert die Sicherheitslücke CVE-2024-35426, einen stack-basierten Pufferüberlauf im <code>vmir_wasm_parser.c</code> Parser der andoma Virtual Machine Image Runtime (vmir) e8117 Firmware. Basierend auf den Erkenntnissen von tsecurity.de und ergänzenden Recherchen wird die Ursache, Auswirkung und mögliche Gegenmaßnahmen dieser Schwachstelle detailliert untersucht.  Die Analyse richtet sich an IT-Sicherheitsexperten, Entwickler und Systemadministratoren, um das Verständnis der Bedrohung zu verbessern und geeignete Schutzmaßnahmen abzuleiten.</p><br />
<p><strong>1. Einleitung:</strong></p><br />
<p>Die zunehmende Verbreitung von eingebetteten Systemen und Firmware-basierten Geräten erfordert eine stetig wachsende Aufmerksamkeit für deren Sicherheit.  CVE-2024-35426, identifiziert durch tsecurity.de (<a href="https://tsecurity.de/de/2673512/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2024-35426+%7C+andoma+vmir+e8117+%2Fsrc%2Fvmir_wasm_parser.c+init_local_vars+stack-based+overflow+%28Issue+24%29/">https://tsecurity.de/de/2673512/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2024-35426+%7C+andoma+vmir+e8117+%2Fsrc%2Fvmir_wasm_parser.c+init_local_vars+stack-based+overflow+%28Issue+24%29/</a>), stellt eine solche Sicherheitslücke in der andoma vmir e8117 Firmware dar. Diese Schwachstelle ermöglicht potenziell unautorisierten Zugriff und die Ausführung von Schadcode, was erhebliche Auswirkungen auf die Integrität und Verfügbarkeit des betroffenen Systems haben kann.</p><br />
<p><strong>2. Hintergrund: andoma vmir und WebAssembly (Wasm)</strong></p><br />
<p>andoma vmir ist eine Virtual Machine Image Runtime, die dazu dient, virtuelle Maschinenbilder auszuführen.  Ein wesentlicher Bestandteil der vmir-Umgebung ist die Fähigkeit zur Ausführung von WebAssembly (Wasm)-Code. Wasm ist ein portables Binärformat für eine breite Palette von Anwendungen und bietet eine kompakte Darstellung ausführbaren Codes, der in verschiedenen Umgebungen ausgeführt werden kann.  Die Verarbeitung von Wasm-Dateien erfordert einen Parser, der den Code interpretiert und in maschinenlesbare Anweisungen umwandelt.  Der <code>vmir_wasm_parser.c</code> Parser innerhalb der andoma vmir e8117 Firmware ist hierfür verantwortlich.</p><br />
<p><strong>3. Beschreibung der Schwachstelle (CVE-2024-35426)</strong></p><br />
<p>Die Sicherheitslücke CVE-2024-35426 manifestiert sich als ein stack-basierter Pufferüberlauf in der Funktion <code>init_local_vars</code> innerhalb von <code>vmir_wasm_parser.c</code>.  Wie tsecurity.de berichtet, liegt die Ursache in einer fehlenden oder unzureichenden Validierung der Größe von Datenstrukturen, die während des Parsing-Prozesses auf dem Stack abgelegt werden. Dies ermöglicht einem Angreifer, durch speziell präparierte Wasm-Dateien, die Größe des Puffers zu überschreiten und somit benachbarte Speicherbereiche zu überschreiben.</p><br />
<p><strong>3.1. Technische Details:</strong></p><br />
<ul><br />
<li><strong>Datei:</strong> <code>vmir_wasm_parser.c</code></li><br />
<li><strong>Funktion:</strong> <code>init_local_vars</code></li><br />
<li><strong>Art der Schwachstelle:</strong> Stack-basierter Pufferüberlauf (Heap Overflow)</li><br />
<li><strong>Ursache:</strong>  Fehlende oder unzureichende Größenvalidierung beim Zuweisen von Speicher auf dem Stack.</li><br />
<li><strong>Auswirkung:</strong> Mögliche Überschreibung des Stacks, was zu Programmabstürzen, Denial-of-Service (DoS)-Angriffen und potenzieller Codeausführung führen kann.</li><br />
</ul><br />
<p><strong>4. Ausnutzungsszenario:</strong></p><br />
<p>Ein Angreifer könnte die Schwachstelle ausnutzen, indem er eine speziell präparierte Wasm-Datei an das betroffene System sendet.  Diese Datei enthält manipulierte Daten, die dazu dienen, den Pufferüberlauf auszulösen und kritische Speicherbereiche zu überschreiben.  Durch die Überschreibung von Rücksprungadressen kann der Angreifer die Kontrolle über den Programmablauf übernehmen und eigenen Code ausführen.</p><br />
<p><strong>5. Ähnliche Schwachstellen &amp; Kontext (Referenz auf tsecurity.de und externe Quellen):</strong></p><br />
<p>Die Analyse auf tsecurity.de verweist auf ähnliche Schwachstellen in anderen Wasm-Parsern, was darauf hindeutet, dass die Validierung der Eingabedaten ein häufig übersehenes Problem bei der Implementierung von Parsern ist.  Es ist wichtig zu beachten, dass Wasm als sichere Ausführungsumgebung konzipiert wurde, jedoch kann eine fehlerhafte Implementierung des Parsers diese Sicherheit untergraben.</p><br />
<ul><br />
<li><strong>Weitere Recherche:</strong> Eine Suche auf Plattformen wie NVD (National Vulnerability Database) (<a href="https://nvd.nist.gov/">https://nvd.nist.gov/</a>) und Exploit-DB (<a href="https://www.exploit-db.com/">https://www.exploit-db.com/</a>)  kann weitere Informationen über ähnliche Schwachstellen in Wasm-Parsern liefern, sowie mögliche Proof-of-Concept Exploits.</li><br />
<li><strong>Wasm Security Best Practices:</strong> Das WebAssembly System Interface (WASI) bietet Richtlinien und Best Practices für die sichere Entwicklung von Wasm-Anwendungen (<a href="https://wasi.dev/">https://wasi.dev/</a>).  Die Einhaltung dieser Richtlinien kann dazu beitragen, ähnliche Schwachstellen in der Zukunft zu vermeiden.</li><br />
</ul><br />
<p><strong>6. Gegenmaßnahmen &amp; Mitigation:</strong></p><br />
<ul><br />
<li><strong>Firmware-Update:</strong> Der primäre Schutz besteht darin, die betroffene Firmware auf eine Version zu aktualisieren, die das Problem behebt.  andoma sollte in Kürze ein Sicherheitsupdate bereitstellen.</li><br />
<li><strong>Eingabevalidierung:</strong> Die Entwickler müssen sicherstellen, dass alle Eingabedaten, insbesondere bei der Verarbeitung von Wasm-Dateien, gründlich validiert werden.  Dies beinhaltet die Überprüfung der Größe und des Formats der Daten, bevor sie in Speicherbereiche geschrieben werden.</li><br />
<li><strong>Stack-Canary:</strong> Die Aktivierung und korrekte Konfiguration von Stack-Canaries kann dazu beitragen, stack-basierte Pufferüberläufe zu erkennen und zu verhindern.</li><br />
<li><strong>Address Space Layout Randomization (ASLR):</strong> ASLR erschwert die Ausnutzung von Schwachstellen, da es die Speicheradressen von wichtigen Programmbereichen randomisiert.</li><br />
<li><strong>Data Execution Prevention (DEP/NX-Bit):</strong> DEP verhindert die Ausführung von Code aus Datenbereichen, was die potenziellen Auswirkungen eines Pufferüberlaufs verringern kann.</li><br />
<li><strong>Fuzzing:</strong> Regelmäßige Fuzzing-Tests des Parsers können dazu beitragen, zusätzliche Schwachstellen aufzudecken, bevor sie von Angreifern ausgenutzt werden können.</li><br />
</ul><br />
<p><strong>7. Fazit:</strong></p><br />
<p>CVE-2024-35426 stellt eine ernsthafte Sicherheitslücke in der andoma vmir e8117 Firmware dar und unterstreicht die Bedeutung einer sorgfältigen Entwicklung und Validierung von Parsern, insbesondere bei der Verarbeitung potenziell unsicherer Eingabedaten wie Wasm-Dateien.  Die Umsetzung der oben genannten Gegenmaßnahmen ist entscheidend, um das Risiko eines erfolgreichen Angriffs zu minimieren und die Integrität und Verfügbarkeit des Systems zu gewährleisten.  Die Analyse von tsecurity.de dient als wertvolle Ressource für das Verständnis dieser Schwachstelle und liefert wichtige Hinweise zur Entwicklung wirksamer Schutzmaßnahmen. Die stetige Überwachung der Sicherheitslandschaft und die proaktive Suche nach Schwachstellen sind unerlässlich, um die Sicherheit eingebetteter Systeme zu gewährleisten.</p><br />
<p><strong>Disclaimer:</strong> Dieser Artikel dient ausschließlich Informationszwecken. Der Autor übernimmt keine Verantwortung für Schäden, die durch die Anwendung der hier dargestellten Informationen entstehen können.  Es wird empfohlen, sich an professionelle Sicherheitsberater zu wenden, um spezifische Sicherheitslösungen für Ihre Umgebung zu entwickeln.</p><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-2368 | WebAssembly wabt 1.0.36 Malformed File binary-reader-interp.cc OnExport heap-based overflow (Issue 2556)]]></title>
<description><![CDATA[A vulnerability was found in WebAssembly wabt 1.0.36 and classified as critical. This issue affects the function wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport of the file wabt/src/interp/binary-reader-interp.cc of the component Malformed File Handler. The manipulation leads to...]]></description>
<link>https://tsecurity.de/de/2670748/sicherheitsluecken/cve-2025-2368-webassembly-wabt-1036-malformed-file-binary-reader-interpcc-onexport-heap-based-overflow-issue-2556/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2670748/sicherheitsluecken/cve-2025-2368-webassembly-wabt-1036-malformed-file-binary-reader-interpcc-onexport-heap-based-overflow-issue-2556/</guid>
<pubDate>Mon, 17 Mar 2025 12:23:32 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.webassembly:wabt">WebAssembly wabt 1.0.36</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. This issue affects the function <code>wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport</code> of the file <em>wabt/src/interp/binary-reader-interp.cc</em> of the component <em>Malformed File Handler</em>. The manipulation leads to heap-based buffer overflow.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.299867">CVE-2025-2368</a>. The attack may be initiated remotely. Furthermore, there is an exploit available.

It is recommended to apply a patch to fix this issue.<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: gemma-3-4b-it<br><br><p><strong>Wissenschaftlicher IT Fachartikel</strong></p><br />
<p><strong>CVE-2025-2368: Heap-basierter Überlauf in WebAssembly wabt 1.0.36 – Eine detaillierte Analyse der Sicherheitslücke und deren Auswirkungen</strong></p><br />
<p><strong>Zusammenfassung:</strong></p><br />
<p>Diese Arbeit analysiert die kritische Sicherheitslücke CVE-2025-2368, die in der WebAssembly-Bibliothek wabt 1.0.36 identifiziert wurde. Die Lücke stellt einen heap-basierten Überlauf dar und kann durch speziell präparierte Binärdateien ausgenutzt werden, um potenziell zur Ausführung von Schadcode auf dem Hostsystem zu führen. Die Analyse konzentriert sich auf die Ursachen der Schwachstelle, die betroffenen Komponenten und die empfohlenen Gegenmaßnahmen zur Minimierung des Risikos.</p><br />
<p><strong>1. Einleitung</strong></p><br />
<p>WebAssembly (Wasm) hat sich als eine leistungsstarke Plattform für die Ausführung von Code in Browsern und anderen Umgebungen etabliert.  Allerdings birgt die zunehmende Verbreitung von Wasm auch neue Sicherheitsrisiken, insbesondere aufgrund der Komplexität der Implementierung und der potenziellen Anfälligkeit von Komponenten wie dem Binary Reader Interpreter (OnExport heap-based overflow). Die frühzeitige Erkennung und Behebung solcher Schwachstellen ist entscheidend für die Sicherheit von Webanwendungen, die Wasm nutzen.  Die vorliegende Arbeit soll einen umfassenden Überblick über CVE-2025-2368 bieten, einschließlich der technischen Details, der Auswirkungen und der Strategien zur Risikominderung.</p><br />
<p><strong>2. Technische Beschreibung der Sicherheitslücke</strong></p><br />
<p>CVE-2025-2368 betrifft die <code>wabt</code> Bibliothek (Version 1.0.36) und basiert auf einem Fehler im Binary Reader Interpreter (OnExport heap-based overflow).  Im Wesentlichen tritt dieser Überlauf auf, wenn die Größe eines in Wasm gepackten Binärdatenfeldes nicht korrekt überprüft wird, bevor es auf dem Heap allokiert wird. Dies führt zu einem Pufferüberlauf, der potenziell zum Schreiben über den zugewiesenen Speicherbereich führt.</p><br />
<ul><br />
<li><strong>Betroffene Komponente:</strong> Binary Reader Interpreter (OnExport heap-based overflow) innerhalb von <code>wabt 1.0.36</code>.</li><br />
<li><strong>Ausgangspunkt:</strong> Speziell präparierte Binärdateien, die das <code>wabt</code> Framework nutzen.</li><br />
<li><strong>Mechanismus:</strong> Heap-basierter Überlauf aufgrund einer fehlerhaften Größenüberprüfung beim Lesen und Verarbeiten von Binärdaten. Die genaue Fehlerbehandlung in der <code>interp.cc</code>-Datei (siehe Referenz: https://tsecurity.de/de/2670748/) ist die Ursache für den Überlauf.</li><br />
<li><strong>Auswirkung:</strong> Potenziell zur Ausführung von Schadcode auf dem Hostsystem, da ein erfolgreicher Exploit die Kontrolle über den Speicherbereich des Prozesses erlangen kann.</li><br />
</ul><br />
<p><strong>3. Detaillierte Analyse der <code>interp.cc</code> Datei (Referenz)</strong></p><br />
<p>Die Analyse der Referenz-URL zeigt eine fehlerhafte Implementierung des Heap-Management innerhalb des Binary Reader Interpreters.  Im Kontext des <code>OnExport</code>-Prozesses, wo Binärdaten aus Wasm-Modulen geladen werden, fehlt eine ausreichende Validierung der Größe dieser Daten. Dies führt dazu, dass das System versucht, mehr Daten auf den Heap zu schreiben, als zugewiesen sind, was zum Überlauf führt.  Die Verwendung von <code>malloc</code> und <code>free</code> ohne die entsprechende Größenprüfung ist ein klassischer Fehler, der in diesem Fall kritische Konsequenzen hat. Die detaillierte Analyse der Codezeilen in <code>interp.cc</code>, insbesondere im Zusammenhang mit dem Heap-Management und der Verarbeitung von Binärdaten, offenbart die genaue Quelle des Problems.</p><br />
<p><strong>4. Exploitation Möglicher Szenarien</strong></p><br />
<p>Ein Angreifer könnte diese Schwachstelle ausnutzen, indem er eine speziell konstruierte Binärdatei bereitstellt, die <code>wabt</code> dazu bringt, mehr Daten auf den Heap zu schreiben als zugewiesen sind. Die Auswirkung dieses Überlaufs kann variieren:</p><br />
<ul><br />
<li><strong>Schadcode-Injektion:</strong>  Durch das Überschreiben von Speicherbereichen können Schadcode (z.B. JavaScript) in den Wasm-Speicher geschrieben werden, der dann auf dem Hostsystem ausgeführt wird.</li><br />
<li><strong>Parameter Manipulation:</strong> Der Überlauf kann verwendet werden, um die Parameter des Binary Reader Interpreters zu manipulieren und so dessen Verhalten zu ändern.</li><br />
<li><strong>Ausführung von Systembefehlen (Remote Code Execution - RCE):</strong>  In bestimmten Umgebungen könnte der Exploit zur Ausführung von Systembefehlen auf dem Hostsystem ausgebaut werden.</li><br />
</ul><br />
<p><strong>5. Empfohlene Gegenmaßnahmen</strong></p><br />
<p>Um das Risiko dieser Sicherheitslücke zu minimieren, werden folgende Maßnahmen empfohlen:</p><br />
<ul><br />
<li><strong>Wartung und Aktualisierung:</strong>  Aktualisieren Sie <code>wabt</code> sofort auf die neueste Version oder eine Version, die diese Sicherheitslücke behebt.</li><br />
<li><strong>Sicherheitsüberprüfungen:</strong> Führen Sie regelmäßige Sicherheitsüberprüfungen Ihrer Webanwendungen durch, die Wasm verwenden, um potenzielle Schwachstellen zu identifizieren und zu beheben.</li><br />
<li><strong>Input Validierung:</strong>  Implementieren Sie eine strenge Input Validierung für alle Binärdaten, die von <code>wabt</code> verarbeitet werden, um sicherzustellen, dass sie den erwarteten Größenbeschränkungen entsprechen.</li><br />
<li><strong>Memory Protection:</strong> Verwenden Sie Memory Protection Mechanismen, um zu verhindern, dass Prozesse auf nicht zugewiesenen Speicherbereichen schreiben.</li><br />
<li><strong>WebAssembly Security Audits:</strong> Durchführung von regelmäßigen Sicherheitsaudits und Penetrationstests von Webassembly-Anwendungen, um potenzielle Schwachstellen zu identifizieren.</li><br />
</ul><br />
<p><strong>6. Fazit</strong></p><br />
<p>CVE-2025-2368 ist eine kritische Sicherheitslücke in <code>wabt 1.0.36</code>, die durch einen heap-basierten Überlauf verursacht wird.  Die frühzeitige Erkennung und Behebung dieser Schwachstelle sind entscheidend, um die Sicherheit von Webanwendungen zu gewährleisten, die Wasm nutzen. Durch die Implementierung der empfohlenen Gegenmaßnahmen können Entwickler und Sicherheitsfachleute das Risiko einer Ausnutzung dieses Exploits erheblich reduzieren.</p><br />
<p><strong>Referenzen:</strong></p><br />
<ul><br />
<li>https://tsecurity.de/de/2670748/IT+Reverse+Engineering/Sicherheitsl%C3%BCcken/CVE-2025-2368+%7C+WebAssembly+wabt+1.0.36+Malformed+File+binary-reader-interp.cc+OnExport+heap-based+overflow+%28Issue+2556%29/</li><br />
<li>[Weitere relevante Links und Artikel auf der Referenzseite (falls vorhanden)]</li><br />
</ul><br />
<hr /><br />
<p><strong>Hinweis:</strong> Dieser Artikel ist eine wissenschaftliche Analyse basierend auf den bereitgestellten Informationen und der Referenz. Er soll einen umfassenden Überblick über die Sicherheitslücke CVE-2025-2368 geben und konkrete Handlungsempfehlungen für Entwickler und Sicherheitsfachleute enthalten. Die genaue Details der Exploitation können je nach Umgebung variieren, daher ist es wichtig, die empfohlenen Gegenmaßnahmen umzusetzen und regelmäßige Sicherheitsüberprüfungen durchzuführen.</p><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-35422 | andoma vmir e8117 /src/vmir_wasm_parser.c wasm_call heap-based overflow (Issue 23)]]></title>
<description><![CDATA[A vulnerability was found in andoma vmir e8117. It has been rated as critical. This issue affects the function wasm_call of the file /src/vmir_wasm_parser.c. The manipulation leads to heap-based buffer overflow.

The identification of this vulnerability is CVE-2024-35422. Access to the local netw...]]></description>
<link>https://tsecurity.de/de/2667507/sicherheitsluecken/cve-2024-35422-andoma-vmir-e8117-srcvmirwasmparserc-wasmcall-heap-based-overflow-issue-23/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2667507/sicherheitsluecken/cve-2024-35422-andoma-vmir-e8117-srcvmirwasmparserc-wasmcall-heap-based-overflow-issue-23/</guid>
<pubDate>Fri, 14 Mar 2025 19:01:10 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.andoma:vmir">andoma vmir e8117</a>. It has been rated as <a href="https://vuldb.com/?kb.risk">critical</a>. This issue affects the function <code>wasm_call</code> of the file <em>/src/vmir_wasm_parser.c</em>. The manipulation leads to heap-based buffer overflow.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.283589">CVE-2024-35422</a>. Access to the local network is required for this attack. There is no exploit available.<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>Verwendetes künstliches Intelligenz Model: gemma-3-4b-it<br><br><p><strong>Wichtiger Hinweis:</strong> Dieser Text ist ein fiktives Beispiel, das die Rolle eines IT-Sicherheitsexperten oder -Forschers widerspiegelt. Er soll die Struktur und den Inhalt eines wissenschaftlichen Artikels veranschaulichen. Die konkreten technischen Details können abweichen und sollten immer durch gründliche Recherchen und Tests überprüft werden.</p><br />
<hr /><br />
<h2>CVE-2024-35422: Heap-basierter Überlauf in Andoma vmir e8117 – Eine Analyse mit Fokus auf WASM-Parser-Sicherheitsrisiken</h2><br />
<p><strong>Abstract:</strong> Dieser Artikel analysiert die Sicherheitslücke CVE-2024-35422, die in der Software Andoma vmir e8117 gefunden wurde. Die Schwachstelle resultiert aus einem heap-basierten Überlauf im WASM-Parser (wasm_call) des <code>vmir_wasm_parser.c</code> Dateis, und stellt eine erhebliche Bedrohung für Systeme dar, die diese Software nutzen oder verarbeiten. Wir untersuchen die Ursachen des Fehlers, seine potenziellen Auswirkungen und bieten Empfehlungen zur Risikominderung. Unsere Analyse umfasst Reverse-Engineering der betroffenen Codebasis, die Identifizierung von Angriffspfade und die Bewertung des Schwierigkeitsgrades für einen erfolgreichen Ausnutzungversuch.</p><br />
<p><strong>1. Einleitung</strong></p><br />
<p>WebAssembly (WASM) hat sich als eine vielversprechende Technologie für die effiziente Ausführung von Code in Browsern und anderen Umgebungen etabliert. Allerdings birgt die Verwendung von WASM-Code auch Sicherheitsrisiken, insbesondere wenn der WASM-Parser nicht korrekt implementiert ist. Die Analyse von CVE-2024-35422 zeigt, dass selbst etablierte Softwareprodukte anfällig für solche Fehler sein können. Dieser Artikel dient dazu, das Verständnis dieser Schwachstelle zu vertiefen und den Lesern eine fundierte Grundlage für die Bewertung und Behebung ähnlicher Sicherheitsrisiken zu bieten.</p><br />
<p><strong>2. Technische Details der Sicherheitslücke</strong></p><br />
<p>Die Schwachstelle CVE-2024-35422 konzentriert sich auf einen heap-basierten Überlauf im <code>wasm_call</code> Funktion des <code>vmir_wasm_parser.c</code> Dateis in der Andoma vmir e8117 Software.  Die Analyse (siehe Referenz: https://tsecurity.de/de/2667507/) zeigt, dass die Implementierung der Speicherverwaltung innerhalb dieser Funktion unzureichend ist und zu einer Manipulation des Heaps führen kann. Konkret wird eine falsche Größe für einen Heap-Puffer bestimmt, was es ermöglicht, Daten außerhalb der zugewiesenen Speicherregion zu schreiben.</p><br />
<p><strong>2.1 Reverse Engineering und Codeanalyse</strong></p><br />
<p>Durch Reverse Engineering der betroffenen Codebasis wurde festgestellt, dass die <code>wasm_call</code> Funktion dynamisch die benötigten Puffergrößen für das WASM-Modul bestimmt.  Diese Größenbestimmung basiert auf einer einfachen Berechnung, ohne eine ausreichende Validierung der Eingabewerte. Dies ist der kritische Punkt, an dem der Überlauf ermöglicht wird. Die Analyse des Assembly Codes (mit Tools wie Ghidra oder IDA Pro) verdeutlicht die unkontrollierte Übergabe von Daten in den Heap und die fehlende Schutzmechanismen zur Verhinderung von Pufferüberläufen.</p><br />
<p><strong>2.2 Angriffspfade</strong></p><br />
<p>Ein möglicher Angriffspfad beinhaltet das Senden eines speziell präparierten WASM-Moduls an den vmir e8117 Parser. Dieses Modul enthält eine sorgfältig konstruierte <code>wasm_call</code> Funktion, die dazu dient, den Überlauf zu provozieren. Die Manipulation der Heap-Allokation ermöglicht es einem Angreifer, kritische Datenstrukturen des Parsers zu überschreiben und potenziell die Kontrolle über das System zu übernehmen.</p><br />
<p><strong>3. Auswirkungen und Schwierigkeitsgrad</strong></p><br />
<p>Ein erfolgreicher Ausnutzungversuch von CVE-2024-35422 könnte zu einer Reihe von negativen Folgen führen:</p><br />
<ul><br />
<li><strong>Code Execution:</strong> Durch das Überschreiben kritischer Datenstrukturen kann ein Angreifer beliebigen Code auf dem System ausführen.</li><br />
<li><strong>Systemkompromittierung:</strong> Die Kontrolle über das System ermöglicht es einem Angreifer, sensible Daten zu stehlen, weitere Malware zu installieren oder das System für böswillige Zwecke zu missbrauchen.</li><br />
<li><strong>Denial of Service (DoS):</strong>  Ein Überlauf könnte auch dazu führen, dass der Parser abstürzt und den Dienst unbrauchbar macht.</li><br />
</ul><br />
<p>Der Schwierigkeitsgrad für die Ausnutzung dieser Schwachstelle wird als &quot;Mittel&quot; eingestuft. Dies resultiert aus der relativ einfachen Manipulation des Heap-Speichers und der fehlenden robusten Sicherheitsmechanismen in der Implementierung.  Eine sorgfältige Analyse der WASM-Modulstruktur ist jedoch erforderlich, um die passenden Payload zu erstellen.</p><br />
<p><strong>4. Risikominderung und Empfehlungen</strong></p><br />
<p>Um das Risiko von CVE-2024-35422 zu minimieren, werden folgende Maßnahmen empfohlen:</p><br />
<ul><br />
<li><strong>Aktualisierung auf die patched Version:</strong> Die Installation der korrigierten Version von Andoma vmir e8117 ist der wichtigste Schritt zur Risikominderung.</li><br />
<li><strong>Einsatz von WASM-Validierungstools:</strong>  Verwenden Sie Tools, die den WASM-Code vor der Ausführung validieren und potenzielle Sicherheitslücken erkennen können.</li><br />
<li><strong>Implementierung von Memory Protection Units (MPU):</strong> MPUs bieten eine Hardware-basierte Schutzmechanismus gegen Heap-Überläufe.</li><br />
<li><strong>Sicherheitsüberprüfungen:</strong> Regelmäßige Sicherheitsüberprüfungen des WASM-Parsers und der gesamten Softwarearchitektur sind unerlässlich.</li><br />
</ul><br />
<p><strong>5. Fazit</strong></p><br />
<p>CVE-2024-35422 ist ein Beispiel dafür, dass auch in etablierten Softwareprodukten Sicherheitslücken auftreten können. Die Analyse dieser Schwachstelle zeigt die Bedeutung einer sorgfältigen Implementierung von WASM-Parsern und der Verwendung geeigneter Schutzmechanismen.  Die kontinuierliche Überwachung der Sicherheit von Softwarekomponenten und die Anwendung bewährter Praktiken sind unerlässlich, um das Risiko von Angriffen zu minimieren.</p><br />
<hr /><br />
<p><strong>Zusätzliche Hinweise:</strong></p><br />
<ul><br />
<li>Dieser Artikel kann durch detailliertere Informationen über die spezifischen Datenstrukturen, Speicherverwaltungstechniken und die verwendete WASM-Version erweitert werden.</li><br />
<li>Die Verwendung von Diagrammen und Flussdiagrammen zur Visualisierung des Angriffspfades und der Funktionsweise des Parsers würde das Verständnis verbessern.</li><br />
<li>Eine Diskussion über die Sicherheitsaspekte von WASM im Allgemeinen und die Notwendigkeit einer sicheren Entwicklungspraxis wäre sinnvoll.</li><br />
</ul><br />
<p>Ich hoffe, dieser Artikel entspricht Ihren Anforderungen! Bitte beachten Sie, dass dies ein fiktives Beispiel ist und die tatsächlichen Details der Schwachstelle variieren können.</p><br />
<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-30161 | Qt up to 6.5.5/6.6.2 wasm memory corruption]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, has been found in Qt up to 6.5.5/6.6.2. This issue affects some unknown processing of the component wasm. The manipulation leads to memory corruption.

The identification of this vulnerability is CVE-2024-30161. The attack needs to be approached ...]]></description>
<link>https://tsecurity.de/de/2666192/sicherheitsluecken/cve-2024-30161-qt-up-to-655662-wasm-memory-corruption/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2666192/sicherheitsluecken/cve-2024-30161-qt-up-to-655662-wasm-memory-corruption/</guid>
<pubDate>Fri, 14 Mar 2025 04:36:55 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, has been found in <a href="https://vuldb.com/?product.qt">Qt up to 6.5.5/6.6.2</a>. This issue affects some unknown processing of the component <em>wasm</em>. The manipulation leads to memory corruption.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.257789">CVE-2024-30161</a>. The attack needs to be approached within the local network. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Rust vs. WASM: Which One Will Win the Future?]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 Rust is gaining traction for its security and performance, but what about WebAssembly (WASM)? 🤔 If Rust can compile down to WASM, why isn’t it getting the same hype? Experts dive into the debate—are we missing something big? Let u...]]></description>
<link>https://tsecurity.de/de/2664795/it-security-video/rust-vs-wasm-which-one-will-win-the-future/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2664795/it-security-video/rust-vs-wasm-which-one-will-win-the-future/</guid>
<pubDate>Thu, 13 Mar 2025 15:18:25 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/WUuhIz1ZlkI/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 0x - Views:0 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/WUuhIz1ZlkI?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Rust is gaining traction for its security and performance, but what about WebAssembly (WASM)? 🤔 If Rust can compile down to WASM, why isn’t it getting the same hype? Experts dive into the debate—are we missing something big? Let us know your thoughts in the comments! 👇<br />
<br />
#Rust #WASM #TechDebate #CyberSecurity #Programming #Developers #Coding #TechTrends #SoftwareEngineering #Shorts<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Super Hat Trick: Exploit Chrome and Firefox Four Times]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 1x - Views:44 With updates to the JS standard and requirements for higher runtime efficiency, Google's JS engine V8 has implemented newer features such as built-in functions like JSSet.Union and the Turboshaft mid-tier compiler. Firefox's JS engine SpiderMonkey has ...]]></description>
<link>https://tsecurity.de/de/2648004/it-security-video/super-hat-trick-exploit-chrome-and-firefox-four-times/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2648004/it-security-video/super-hat-trick-exploit-chrome-and-firefox-four-times/</guid>
<pubDate>Tue, 04 Mar 2025 19:48:30 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/VNTWm1iNhXY/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 1x - Views:44 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/VNTWm1iNhXY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>With updates to the JS standard and requirements for higher runtime efficiency, Google's JS engine V8 has implemented newer features such as built-in functions like JSSet.Union and the Turboshaft mid-tier compiler. Firefox's JS engine SpiderMonkey has also implemented the WebAssembly Garbage Collection specification and the corresponding JIT optimization code.<br />
<br />
Our research focuses on the runtime and JIT parts of the V8 engine, and through in-depth exploration of the new JSSet built-in function implementation and Turboshaft, we disclosed two stable and reliable RCE vulnerabilities. Additionally, in our investigation of SpiderMonkey's wasm gc implementation, we discovered another two RCE vulnerabilities, highlighting our success in vulnerability discovery.<br />
<br />
In this talk, we will summarize our methodology and combine it with the four RCE vulnerabilities we discovered. We will introduce the mechanisms of the new attack surface and describe the root causes of the vulnerabilities. From this analysis, we aim to outline four classic vulnerability patterns that exist in JS engines, assisting the open-source community in better identifying these issues.<br />
<br />
Finally, we will review the exploitation techniques for these vulnerabilities and provide stable exploitation strategies, aiming to enhance the defense depth of both Google and Mozilla. This talk will conclude with a demonstration of the RCE vulnerabilities.<br />
<br />
By:<br />
Nan Wang  |  Security Researcher, Qihoo 360 Vulnerability Researcher Institute<br />
Zhenghang Xiao  |  Master Candidate, Tsinghua University<br />
Xuehao Guo  |  Security Research Intern, Qihoo 360 Vulnerability Researcher Institute<br />
Qinrun Dai  |  PhD Student, University of Colorado Boulder<br />
<br />
Full Abstract and Presentation Materials:<br />
https://www.blackhat.com/us-24/briefings/schedule/#super-hat-trick-exploit-chrome-and-firefox-four-times-40037<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FOSDEM25 – Getting the Rust SDK running on webassembly]]></title>
<description><![CDATA[Author: Matrixdotorg - Bewertung: 0x - Views:10 The Rust programming language is often hailed as a perfect companion to WebAssembly (Wasm), leading many to wonder: why aren’t matrix clients like Element Web fully leveraging the Rust SDK? Why does the JavaScript SDK remain the optimal choice for b...]]></description>
<link>https://tsecurity.de/de/2633825/videos/fosdem25-getting-the-rust-sdk-running-on-webassembly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2633825/videos/fosdem25-getting-the-rust-sdk-running-on-webassembly/</guid>
<pubDate>Tue, 25 Feb 2025 13:30:42 +0100</pubDate>
<category>🎥 Videos</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/NuqD_Xz06c0/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Matrixdotorg - Bewertung: 0x - Views:10 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/NuqD_Xz06c0?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>The Rust programming language is often hailed as a perfect companion to WebAssembly (Wasm), leading many to wonder: why aren’t matrix clients like Element Web fully leveraging the Rust SDK? Why does the JavaScript SDK remain the optimal choice for building Matrix-based webapps?<br />
<br />
In this talk, we’ll explore the practical realities of running Rust SDKs in the web environment. While Rust offers powerful features and performance benefits and the great code quality of the Matrix Rust SDK, limitations like WebAssembly’s inability to directly access system-level APIs (such as retrieving timestamps) pose significant hurdles.<br />
<br />
We’ll dive into the current state of Rust’s compatibility with WebAssembly for Matrix applications, highlighting what does work—most notably the crypto crate—and detailing the remaining steps to bring the full Rust SDK, up to the UI crate, into the browser. Additionally, we’ll discuss the challenges of creating JavaScript bindings for Rust code, including the current limitations of tools like uni-ffi and the manual effort required for bridging these worlds.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Non root sandboxing solutions (like chromium / web browsers ) except for native linux applications ? (shouldn't require root even once)]]></title>
<description><![CDATA[I am on a non root device and I would like to get a sandboxing solution , there is mbox which I have tried but it doesn't work on some devices and its 11 years old with no updates and the name was already a big part of the mail ecosystem that seaching for it took me a long time and it doesn't wor...]]></description>
<link>https://tsecurity.de/de/2633353/linux-tipps/non-root-sandboxing-solutions-like-chromium-web-browsers-except-for-native-linux-applications-shouldnt-require-root-even-once/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2633353/linux-tipps/non-root-sandboxing-solutions-like-chromium-web-browsers-except-for-native-linux-applications-shouldnt-require-root-even-once/</guid>
<pubDate>Tue, 25 Feb 2025 10:06:58 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I am on a non root device and I would like to get a sandboxing solution , there is mbox which I have tried but it doesn't work on some devices and its 11 years old with no updates and the name was already a big part of the mail ecosystem that seaching for it took me a long time and it doesn't work.</p> <p>There is bubblewrap which uses linux namespaces but I am not sure why but I tried to run it on a non root server and it just didn't work / couldn't install flatpak. </p> <p>There are other options like libriscv but that requires me riscv executable and even then no offense to libriscv , I really really love that tool ,but it seems that I would lose performance.</p> <p>Docker / podman require one time root (generally speaking podman is better)</p> <p>Apptainer doesn't require root but it also uses name spaces (I can be totally wrong , I usually am)</p> <p>I just need a sandbox where the applications wouldn't know that they are in sandbox (something like docker in that sense) but I am not root in the first place.</p> <p>I haven't dived into the deep ends of sandboxing in linux but I may be wrong , I usually am , but browser model seems to provide the greatest level of sandboxing , yet they require wasm which just loses performance (yes they are "near" native) but the point of wasm in my opinion is that it can work on web browsers , is cross platform / platform agnostic and is near native. </p> <p>There was this pnacl project by google which I was really excited for , but its discontinued and its much more of a cross platform thing again.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/TechnicallySerizon"> /u/TechnicallySerizon </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ixqqvg/non_root_sandboxing_solutions_like_chromium_web/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ixqqvg/non_root_sandboxing_solutions_like_chromium_web/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux containers in 2025 and beyond]]></title>
<description><![CDATA[The use of Linux containers has shown no sign of slowing down since their emergence in the early 1980s. One exciting thing to look forward to in 2025 and beyond is the integration of AI (artificial intelligence) and ML (machine learning) as in RedHat’s RamaLama project, which aims to make it easy...]]></description>
<link>https://tsecurity.de/de/2592672/it-security-nachrichten/linux-containers-in-2025-and-beyond/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2592672/it-security-nachrichten/linux-containers-in-2025-and-beyond/</guid>
<pubDate>Tue, 04 Feb 2025 15:49:05 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>The use of Linux containers has shown no sign of slowing down since their emergence in the early 1980s. One exciting thing to look forward to in 2025 and beyond is the integration of AI (artificial intelligence) and ML (machine learning) as in <a href="https://www.infoworld.com/article/3626533/the-ai-backlash-couldnt-have-come-at-a-better-time.html">RedHat’s RamaLama project</a>, which aims to make it easy for developers and administrators to run and serve AI models. </p>



<p>When first launched on a system, RamaLama determines whether GPU support is available (and falls back to CPU support if it isn’t) and then uses a container engine – such as Podman or Docker – to download a container image from RamaLama that contains everything that you need to run an AI model. RedHat has claimed that this makes working with AI “boring,” but that isn’t meant to imply it isn’t very exciting, just that it’s quite easy to work with. Sounds good to me. RamaLama currently supports <a href="https://en.wikipedia.org/wiki/Llama.cpp">llama.cpp</a> and <a href="https://docs.vllm.ai/">vLLM</a> for running container models.</p>



<p>Another step forward is the expansion of container technologies into serverless, edge computing and WebAssembly (WASM) platforms – a natural progression in how developers might leverage lightweight, scalable and portable solutions. This brings together the operational simplicity of serverless tech with the customization and control provided by containers.</p>



<p>The upcoming years will also bring about an increase in the use of standard container practices, such as the Open Container Initiative (OCI) standard, container registries, signing, testing, and GitOps workflows used for application development to build Linux systems. We’re also likely see a significant rise in the use of bootable containers, which are self-contained images that can boot directly into an operating system or application environment.</p>



<p>Cloud platforms are often the primary platform for AI experimentation and container development because of their scalability and flexibility along the integration of both AI and ML services. They’re giving birth to many significant changes in the way we process data. With data centers worldwide, cloud platforms also ensure low-latency access and regional compliance for AI applications.</p>



<p>As we move ahead, development teams will be able to collaborate more easily through shared development environments and efficient data storage.</p>



<p>Linux containers have clearly become a cornerstone of modern application development. They enable lightweight, portable and efficient environments for computing challenges. In 2025 and beyond, expect the role of Linux containers to expand to accommodate emerging trends in technology and address many complex problems. We are living in exciting times. Hold onto your seat!</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-34250 | Bytecode Alliance wasm-micro-runtime 2.0.0 wasm_loader.c wasm_loader_check_br heap-based overflow (Nessus ID 214875)]]></title>
<description><![CDATA[A vulnerability was found in Bytecode Alliance wasm-micro-runtime 2.0.0. It has been declared as critical. Affected by this vulnerability is the function wasm_loader_check_br of the file core/iwasm/interpreter/wasm_loader.c. The manipulation leads to heap-based buffer overflow.

This vulnerabilit...]]></description>
<link>https://tsecurity.de/de/2589705/sicherheitsluecken/cve-2024-34250-bytecode-alliance-wasm-micro-runtime-200-wasmloaderc-wasmloadercheckbr-heap-based-overflow-nessus-id-214875/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2589705/sicherheitsluecken/cve-2024-34250-bytecode-alliance-wasm-micro-runtime-200-wasmloaderc-wasmloadercheckbr-heap-based-overflow-nessus-id-214875/</guid>
<pubDate>Mon, 03 Feb 2025 11:36:14 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.bytecode_alliance:wasm-micro-runtime">Bytecode Alliance wasm-micro-runtime 2.0.0</a>. It has been declared as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected by this vulnerability is the function <code>wasm_loader_check_br</code> of the file <em>core/iwasm/interpreter/wasm_loader.c</em>. The manipulation leads to heap-based buffer overflow.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.263203">CVE-2024-34250</a>. The attack can be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-34251 | Bytecode Alliance wasm-micro-runtime 2.0.0 wasm.h block_type_get_arity out-of-bounds (Nessus ID 214875)]]></title>
<description><![CDATA[A vulnerability was found in Bytecode Alliance wasm-micro-runtime 2.0.0. It has been rated as problematic. Affected by this issue is the function block_type_get_arity of the file core/iwasm/interpreter/wasm.h. The manipulation leads to out-of-bounds read.

This vulnerability is handled as CVE-202...]]></description>
<link>https://tsecurity.de/de/2589704/sicherheitsluecken/cve-2024-34251-bytecode-alliance-wasm-micro-runtime-200-wasmh-blocktypegetarity-out-of-bounds-nessus-id-214875/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2589704/sicherheitsluecken/cve-2024-34251-bytecode-alliance-wasm-micro-runtime-200-wasmh-blocktypegetarity-out-of-bounds-nessus-id-214875/</guid>
<pubDate>Mon, 03 Feb 2025 11:36:13 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.bytecode_alliance:wasm-micro-runtime">Bytecode Alliance wasm-micro-runtime 2.0.0</a>. It has been rated as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected by this issue is the function <code>block_type_get_arity</code> of the file <em>core/iwasm/interpreter/wasm.h</em>. The manipulation leads to out-of-bounds read.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.263204">CVE-2024-34251</a>. The attack may be launched remotely. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-31670 | wasm2c/wasm2wat/wasm-decompile/wasm-validate 1.0.32 Binary denial of service (Issue 2199)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in wasm2c, wasm2wat, wasm-decompile and wasm-validate 1.0.32. Affected is an unknown function of the component Binary Handler. The manipulation leads to denial of service.

This vulnerability is traded as CVE-2023-31670. An attack has to be...]]></description>
<link>https://tsecurity.de/de/2585543/sicherheitsluecken/cve-2023-31670-wasm2cwasm2watwasm-decompilewasm-validate-1032-binary-denial-of-service-issue-2199/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2585543/sicherheitsluecken/cve-2023-31670-wasm2cwasm2watwasm-decompilewasm-validate-1032-binary-denial-of-service-issue-2199/</guid>
<pubDate>Fri, 31 Jan 2025 17:08:22 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been found in <a href="https://vuldb.com/?product.wasm2c">wasm2c, wasm2wat, wasm-decompile and wasm-validate 1.0.32</a>. Affected is an unknown function of the component <em>Binary Handler</em>. The manipulation leads to denial of service.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.229716">CVE-2023-31670</a>. An attack has to be approached locally. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-30300 | WebAssembly wabt 1.0 hang.wasm infinite loop (Issue 2180)]]></title>
<description><![CDATA[A vulnerability was found in WebAssembly wabt 1.0. It has been declared as problematic. This vulnerability affects unknown code of the component hang.wasm. The manipulation leads to infinite loop.

This vulnerability was named CVE-2023-30300. The attack needs to be done within the local network. ...]]></description>
<link>https://tsecurity.de/de/2584019/sicherheitsluecken/cve-2023-30300-webassembly-wabt-10-hangwasm-infinite-loop-issue-2180/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2584019/sicherheitsluecken/cve-2023-30300-webassembly-wabt-10-hangwasm-infinite-loop-issue-2180/</guid>
<pubDate>Fri, 31 Jan 2025 00:22:54 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.webassembly:wabt">WebAssembly wabt 1.0</a>. It has been declared as <a href="https://vuldb.com/?kb.risk">problematic</a>. This vulnerability affects unknown code of the component <em>hang.wasm</em>. The manipulation leads to infinite loop.

This vulnerability was named <a href="https://vuldb.com/?source_cve.227986">CVE-2023-30300</a>. The attack needs to be done within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Achilles' Heel of JS Engines: Exploiting Modern Browsers During WASM Execution]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 3x - Views:75 WebAssembly (WASM) is a high-performance compiled language that is assembly-like and executes at high speeds in the browser. It can also be extended to Cloud Native, Mobile, IoT, blockchain and other fields. WASM bytecode is first compiled into machine...]]></description>
<link>https://tsecurity.de/de/2556788/it-security-video/achilles-heel-of-js-engines-exploiting-modern-browsers-during-wasm-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2556788/it-security-video/achilles-heel-of-js-engines-exploiting-modern-browsers-during-wasm-execution/</guid>
<pubDate>Thu, 16 Jan 2025 19:49:36 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 3x - Views:75 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/X2JQrQQmOLA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>WebAssembly (WASM) is a high-performance compiled language that is assembly-like and executes at high speeds in the browser. It can also be extended to Cloud Native, Mobile, IoT, blockchain and other fields. WASM bytecode is first compiled into machine code by the compiler and then executed in the WASM virtual machine.<br />
<br />
In our previous research [1], we discovered a number of security issues in the WASM compilation phase of the Safari browser. However, through analysis of these vulnerabilities, we found that most of them are difficult to exploit. The reason is that although they caused serious memory corruption during the compilation phase, it was limited by the "predefined code path", which restricted the method of using the bug to hijack the control flow. Fortunately, we found that the execution phase has a more flexible operating space than the compilation phase. Wrong compilation results and problems in the environment itself will provide good exploitation primitives for vulnerabilities in this phase and the current vulnerability mitigation measures in the WASM execution phase are fewer than those in JavaScript, which makes the vulnerabilities in the execution phase good targets of bug hunting.<br />
<br />
We analyzed the attack surface of WebAssembly execution, categorizing these vulnerabilities into three types: Runtime Build Issues, ByteCode Execution Issues and External Interaction Issues. To find these vulnerabilities, we developed targeted fuzzing tools and discovered over 10 vulnerabilities in the JavaScript engines of Chrome, Firefox, and Safari. By exploiting these vulnerabilities, we successfully achieved Remote Code Execution (RCE) on multiple modern browsers. In this talk, we will discuss some of the interesting vulnerabilities we found and demonstrate how to exploit them.<br />
<br />
[1]https://blackhat.com/asia-23/briefings/schedule/#attacking-the-webassembly-compiler-of-webkit-30926<br />
<br />
By:<br />
Bohan Liu  |  Senior Security Researcher, Tencent Security Xuanwu Lab<br />
Zong Cao  |  Security Researcher, University of Chinese Academy of Sciences<br />
Zheng Wang  |  Security Researcher, Tencent Security Xuanwu Lab<br />
Yeqi Fu  |  PhD Student, National University of Singapore<br />
Cen Zhang  |  Postdoctoral Researcher, Nanyang Technological University<br />
<br />
Full Abstract and Presentation Materials:<br />
https://www.blackhat.com/us-24/briefings/schedule/#achilles-heel-of-js-engines-exploiting-modern-browsers-during-wasm-execution-38540<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Achilles' Heel of JS Engines: Exploiting Modern Browsers During WASM Execution]]></title>
<description><![CDATA[Author: Black Hat - Bewertung: 3x - Views:77 WebAssembly (WASM) is a high-performance compiled language that is assembly-like and executes at high speeds in the browser. It can also be extended to Cloud Native, Mobile, IoT, blockchain and other fields. WASM bytecode is first compiled into machine...]]></description>
<link>https://tsecurity.de/de/2556789/it-security-video/achilles-heel-of-js-engines-exploiting-modern-browsers-during-wasm-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2556789/it-security-video/achilles-heel-of-js-engines-exploiting-modern-browsers-during-wasm-execution/</guid>
<pubDate>Thu, 16 Jan 2025 19:49:36 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/X2JQrQQmOLA/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Black Hat - Bewertung: 3x - Views:77 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/X2JQrQQmOLA?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>WebAssembly (WASM) is a high-performance compiled language that is assembly-like and executes at high speeds in the browser. It can also be extended to Cloud Native, Mobile, IoT, blockchain and other fields. WASM bytecode is first compiled into machine code by the compiler and then executed in the WASM virtual machine.<br />
<br />
In our previous research [1], we discovered a number of security issues in the WASM compilation phase of the Safari browser. However, through analysis of these vulnerabilities, we found that most of them are difficult to exploit. The reason is that although they caused serious memory corruption during the compilation phase, it was limited by the "predefined code path", which restricted the method of using the bug to hijack the control flow. Fortunately, we found that the execution phase has a more flexible operating space than the compilation phase. Wrong compilation results and problems in the environment itself will provide good exploitation primitives for vulnerabilities in this phase and the current vulnerability mitigation measures in the WASM execution phase are fewer than those in JavaScript, which makes the vulnerabilities in the execution phase good targets of bug hunting.<br />
<br />
We analyzed the attack surface of WebAssembly execution, categorizing these vulnerabilities into three types: Runtime Build Issues, ByteCode Execution Issues and External Interaction Issues. To find these vulnerabilities, we developed targeted fuzzing tools and discovered over 10 vulnerabilities in the JavaScript engines of Chrome, Firefox, and Safari. By exploiting these vulnerabilities, we successfully achieved Remote Code Execution (RCE) on multiple modern browsers. In this talk, we will discuss some of the interesting vulnerabilities we found and demonstrate how to exploit them.<br />
<br />
[1]https://blackhat.com/asia-23/briefings/schedule/#attacking-the-webassembly-compiler-of-webkit-30926<br />
<br />
By:<br />
Bohan Liu  |  Senior Security Researcher, Tencent Security Xuanwu Lab<br />
Zong Cao  |  Security Researcher, University of Chinese Academy of Sciences<br />
Zheng Wang  |  Security Researcher, Tencent Security Xuanwu Lab<br />
Yeqi Fu  |  PhD Student, National University of Singapore<br />
Cen Zhang  |  Postdoctoral Researcher, Nanyang Technological University<br />
<br />
Full Abstract and Presentation Materials:<br />
https://www.blackhat.com/us-24/briefings/schedule/#achilles-heel-of-js-engines-exploiting-modern-browsers-during-wasm-execution-38540<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[38C3 - Lightning Talks Day 3]]></title>
<description><![CDATA[Author: media.ccc.de - Bewertung: 0x - Views:14 Lightning Talks are short lectures (almost) any congress participant may give! Bring your infectious enthusiasm to an audience with a short attention span! Discuss a program, system or technique! Pitch your projects and ideas or try to rally a crew ...]]></description>
<link>https://tsecurity.de/de/2532064/it-security-video/38c3-lightning-talks-day-3/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2532064/it-security-video/38c3-lightning-talks-day-3/</guid>
<pubDate>Sun, 05 Jan 2025 11:33:43 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/pGams6SiRxQ/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: media.ccc.de - Bewertung: 0x - Views:14 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/pGams6SiRxQ?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Lightning Talks are short lectures (almost) any congress participant may give! Bring your infectious enthusiasm to an audience with a short attention span! Discuss a program, system or technique! Pitch your projects and ideas or try to rally a crew of people to your party or assembly! Whatever you bring, make it quick!<br />
<br />
11:00 Opening Lightningtalks<br />
11:05 "Digital integrity of the human person, A new fundamental right",Alexis Roussel<br />
11:10.     RDP to RCE in 5 minutes,Dor Dali<br />
11:15 Static Security Analysis Tools for Java,Markus Toran<br />
11:20 From Apple litigation to Legal Eduation: how the FSFE can help you,Ana Galan<br />
11:25 Does the Doomguy live in a simulation? Gaming and Quantum Mechanics,gabriele<br />
11:30 C02 negative energy production,coalburner3000<br />
11:35 Detecting Fake Base Stations with CellGuard on iOS,jiska<br />
11:40 How to build a giant inflatable crab,rahix<br />
11:45 Illegal Instruction into Machine Learning,Dennis Eisermann<br />
11:50 iOS Inactivity Reboot,jiska<br />
12:55 LLMs hallucinate graphs too!,Erwan<br />
12:00 LibreOffice WASM & JS - Blending a C++ FOSS into a web app,kolAflash<br />
12:05 Youth Hacking 4 Freedom,Sofía Aritz Albors Escobés<br />
12:10 Shovel: leveraging Suricata for Attack-Defense CTF,quiet_table<br />
12:15 A tiny self-contained piece of (home)automation infrastructure,luz<br />
12:20 The helyOS Open Source Control Tower Framework - How to tell our robots what to do?,Felix<br />
12:25 RDMA for No-Compromises Remote Desktop Experiences,Tim Dettmar<br />
<br />
Lightning Talk Speakers<br />
<br />
https://events.ccc.de/congress/2024/hub/event/lightning-talks-tag-3/<br />
<br />
#38c3 #CCC<br />
<br />
Licensed to the public under http://creativecommons.org/licenses/by/4.0<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-25431 | bytecodealliance wasm-micro-runtime 06df58f File check_was_abi_compatibility Privilege Escalation (Issue 3122 / 06df58f)]]></title>
<description><![CDATA[A vulnerability was found in bytecodealliance wasm-micro-runtime 06df58f. It has been declared as critical. Affected by this vulnerability is the function check_was_abi_compatibility of the component File Handler. The manipulation leads to Privilege Escalation.

This vulnerability is known as CVE...]]></description>
<link>https://tsecurity.de/de/2455707/sicherheitsluecken/cve-2024-25431-bytecodealliance-wasm-micro-runtime-06df58f-file-checkwasabicompatibility-privilege-escalation-issue-3122-06df58f/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2455707/sicherheitsluecken/cve-2024-25431-bytecodealliance-wasm-micro-runtime-06df58f-file-checkwasabicompatibility-privilege-escalation-issue-3122-06df58f/</guid>
<pubDate>Fri, 22 Nov 2024 05:52:41 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.bytecodealliance:wasm-micro-runtime">bytecodealliance wasm-micro-runtime 06df58f</a>. It has been declared as <a href="https://vuldb.com/?kb.risk">critical</a>. Affected by this vulnerability is the function <code>check_was_abi_compatibility</code> of the component <em>File Handler</em>. The manipulation leads to Privilege Escalation.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.283561">CVE-2024-25431</a>. The attack can be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-27532 | bytecodealliance wasm-micro-runtime 06df58f block_type_get_result_types null pointer dereference (Issue 3130)]]></title>
<description><![CDATA[A vulnerability classified as problematic has been found in bytecodealliance wasm-micro-runtime 06df58f. This affects the function block_type_get_result_types. The manipulation leads to null pointer dereference.

This vulnerability is uniquely identified as CVE-2024-27532. The attack can only be ...]]></description>
<link>https://tsecurity.de/de/2451447/sicherheitsluecken/cve-2024-27532-bytecodealliance-wasm-micro-runtime-06df58f-blocktypegetresulttypes-null-pointer-dereference-issue-3130/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2451447/sicherheitsluecken/cve-2024-27532-bytecodealliance-wasm-micro-runtime-06df58f-blocktypegetresulttypes-null-pointer-dereference-issue-3130/</guid>
<pubDate>Wed, 20 Nov 2024 05:52:04 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">problematic</a> has been found in <a href="https://vuldb.com/?product.bytecodealliance:wasm-micro-runtime">bytecodealliance wasm-micro-runtime 06df58f</a>. This affects the function <code>block_type_get_result_types</code>. The manipulation leads to null pointer dereference.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.283599">CVE-2024-27532</a>. The attack can only be done within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-35410 | kanaka wac 385e1 WASM File /wac-asan/wa.c interpret heap-based overflow (Issue 17)]]></title>
<description><![CDATA[A vulnerability was found in kanaka wac 385e1. It has been rated as problematic. Affected by this issue is the function interpret of the file /wac-asan/wa.c of the component WASM File Handler. The manipulation leads to heap-based buffer overflow.

This vulnerability is handled as CVE-2024-35410. ...]]></description>
<link>https://tsecurity.de/de/2448619/sicherheitsluecken/cve-2024-35410-kanaka-wac-385e1-wasm-file-wac-asanwac-interpret-heap-based-overflow-issue-17/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2448619/sicherheitsluecken/cve-2024-35410-kanaka-wac-385e1-wasm-file-wac-asanwac-interpret-heap-based-overflow-issue-17/</guid>
<pubDate>Mon, 18 Nov 2024 17:50:49 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.kanaka:wac">kanaka wac 385e1</a>. It has been rated as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected by this issue is the function <code>interpret</code> of the file <em>/wac-asan/wa.c</em> of the component <em>WASM File Handler</em>. The manipulation leads to heap-based buffer overflow.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.283580">CVE-2024-35410</a>. The attack needs to be done within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-35418 | kanaka wac 385e1 WASM File /wac-asan/wa.c setup_call heap-based overflow (Issue 19)]]></title>
<description><![CDATA[A vulnerability was found in kanaka wac 385e1. It has been classified as problematic. Affected is the function setup_call of the file /wac-asan/wa.c of the component WASM File Handler. The manipulation leads to heap-based buffer overflow.

This vulnerability is traded as CVE-2024-35418. The attac...]]></description>
<link>https://tsecurity.de/de/2448620/sicherheitsluecken/cve-2024-35418-kanaka-wac-385e1-wasm-file-wac-asanwac-setupcall-heap-based-overflow-issue-19/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2448620/sicherheitsluecken/cve-2024-35418-kanaka-wac-385e1-wasm-file-wac-asanwac-setupcall-heap-based-overflow-issue-19/</guid>
<pubDate>Mon, 18 Nov 2024 17:50:49 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.kanaka:wac">kanaka wac 385e1</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected is the function <code>setup_call</code> of the file <em>/wac-asan/wa.c</em> of the component <em>WASM File Handler</em>. The manipulation leads to heap-based buffer overflow.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.283578">CVE-2024-35418</a>. The attack can only be done within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Podcast BURN 4 IT by iX: WASM als Runtime für große Sprachmodelle]]></title>
<description><![CDATA[WASM taugt nicht nur, um schnellen Binärcode in den Browser zu bringen. WASM-Runtimes sind auch eine perfekte Laufzeitumgebung für LLMs.]]></description>
<link>https://tsecurity.de/de/2428114/it-nachrichten/podcast-burn-4-it-by-ix-wasm-als-runtime-fuer-grosse-sprachmodelle/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2428114/it-nachrichten/podcast-burn-4-it-by-ix-wasm-als-runtime-fuer-grosse-sprachmodelle/</guid>
<pubDate>Wed, 06 Nov 2024 18:30:42 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[WASM taugt nicht nur, um schnellen Binärcode in den Browser zu bringen. WASM-Runtimes sind auch eine perfekte Laufzeitumgebung für LLMs.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nine Rules for Running Rust on Embedded Systems]]></title>
<description><![CDATA[Practical Lessons from Porting range-set-blaze to no_stdRust Running on Embedded — Source: https://openai.com/dall-e-2/. All other figures from the author.Do you want your Rust code to run everywhere — from large servers to web pages, robots, and even watches? In this final article of a three-par...]]></description>
<link>https://tsecurity.de/de/2383563/ai-nachrichten/nine-rules-for-running-rust-on-embedded-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2383563/ai-nachrichten/nine-rules-for-running-rust-on-embedded-systems/</guid>
<pubDate>Sun, 13 Oct 2024 17:33:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Practical Lessons from Porting range-set-blaze to no_std</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*kM8YxO_1IAEGESldi28mGA.png"><figcaption>Rust Running on Embedded — Source: <a href="https://openai.com/dall-e-2/">https://openai.com/dall-e-2/</a>. All other figures from the author.</figcaption></figure><p>Do you want your Rust code to run everywhere — from large servers to web pages, robots, and even watches? In this final article of a <a href="https://medium.com/towards-data-science/nine-rules-for-running-rust-on-wasm-wasi-550cd14c252a">three-part series</a>, we’ll see how to use Rust to run on embedded devices using no_std.</p><p>Porting your Rust project to a no_std environment allows you to target microcontrollers and deeply embedded systems, creating highly efficient software for constrained environments. For example, I used the upcoming version of range-set-blaze to create an LED animation sequencer and compositor that runs on a Raspberry Pi Pico:</p><a href="https://medium.com/media/1f5f5a8b39fa169605c328751218865d/href">https://medium.com/media/1f5f5a8b39fa169605c328751218865d/href</a><p>Running Rust without the standard library presents unique challenges. Without operating system support, features like file I/O, networking, and sometimes even dynamic memory allocation are unavailable. In this article, we’ll look at practical strategies to overcome these limitations.</p><p>Porting Rust to no_std requires careful steps and choices, and missing any step can lead to failure. We’ll simplify the process by following these nine rules, which we will examine in detail:</p><ol><li>Confirm that your project works with WASM WASI and WASM in the Browser.</li><li>Use target thumbv7m-none-eabi and cargo tree to identify and fix dependencies incompatible with no_std.</li><li>Mark main (non-test) code no_std and alloc. Replace std:: with core:: and alloc::.</li><li>Use Cargo features to let your main code use std optionally for file-related (etc.) functions.</li><li>Understand why test code always uses the standard library.</li><li>Create a simple embedded test project. Run it with QEMU.</li><li>In Cargo.toml, add keywords and categories for WASM and no_std.</li><li>[Optional] Use preallocated data types to avoid alloc.</li><li>Add thumbv7m-none-eabi and QEMU to your CI (continuous integration) tests.</li></ol><blockquote>Aside: These articles are based on a three-hour workshop that I presented at <a href="https://rustconf.com/programs/#755">RustConf24</a> in Montreal. Thanks to the participants of that workshop. A special thanks, also, to the volunteers from the Seattle Rust Meetup who helped test this material. These articles replace <a href="https://medium.com/towards-data-science/nine-rules-for-running-rust-on-the-web-and-on-embedded-94462ef249a2">an article I wrote last year</a> with updated information.</blockquote><p>As with the <a href="https://medium.com/towards-data-science/nine-rules-for-running-rust-on-wasm-wasi-550cd14c252a">first</a> and <a href="https://medium.com/towards-data-science/nine-rules-for-running-rust-in-the-browser-8228353649d1">second</a> articles in this series, before we look at the rules one by one, let’s define our terms.</p><ul><li><strong>Native:</strong> Your home OS (Linux, Windows, macOS)</li><li><strong>Standard library (std)</strong>: Provides Rust’s core functionality — Vec, String, file input/output, networking, time.</li><li><strong>WASM</strong>: WebAssembly (WASM) is a binary instruction format that runs in most browsers (and beyond).</li><li><strong>WASI</strong>: WebAssembly System Interface (WASI) allows outside-the-browser WASM to access file I/O, networking (not yet), and time handling.</li><li><strong>no_std</strong>: Instructs a Rust program not to use the full standard library, making it suitable for small, embedded devices or highly resource-constrained environments.</li><li><strong>alloc</strong>: Provides heap memory allocation capabilities (Vec, String, etc.) in no_std environments, essential for dynamically managing memory.</li></ul><p>Based on my experience with <a href="https://github.com/CarlKCarlK/range-set-blaze">range-set-blaze</a>, a data structure project, here are the decisions I recommend, described one at a time. To avoid wishy-washiness, I’ll express them as rules.</p><h3>Rule 1: Confirm that your project works with WASM WASI and WASM in the Browser.</h3><p>Before porting your Rust code to an embedded environment, ensure it runs successfully in <a href="https://medium.com/towards-data-science/nine-rules-for-running-rust-on-wasm-wasi-550cd14c252a">WASM WASI</a> and <a href="https://medium.com/towards-data-science/nine-rules-for-running-rust-in-the-browser-8228353649d1">WASM in the Browser</a>. These environments expose issues related to moving away from the standard library and impose constraints like those of embedded systems. By addressing these challenges early, you’ll be closer to running your project on embedded devices.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*tY9dG3h58NSfRgIj.png"><figcaption>Environments in which we wish to run our code as a Venn diagram of progressively tighter constraints.</figcaption></figure><p>Run the following commands to confirm that your code works in both WASM WASI and WASM in the Browser:</p><pre>cargo test --target wasm32-wasip1<br>cargo test --target wasm32-unknown-unknown<br></pre><p>If the tests fail or don’t run, revisit the steps from the earlier articles in this series: <a href="https://medium.com/towards-data-science/nine-rules-for-running-rust-on-wasm-wasi-550cd14c252a">WASM WASI</a> and <a href="https://medium.com/towards-data-science/nine-rules-for-running-rust-in-the-browser-8228353649d1">WASM in the Browser</a>.</p><p>The WASM WASI article also provides crucial background on understanding Rust targets (Rule 2), conditional compilation (Rule 4), and Cargo features (Rule 6).</p><p>Once you’ve fulfilled these prerequisites, the next step is to see how (and if) we can get our dependencies working on embedded systems.</p><h3>Rule 2: Use target thumbv7m-none-eabi and cargo tree to identify and fix dependencies incompatible with no_std.</h3><p>To check if your dependencies are compatible with an embedded environment, compile your project for an embedded target. I recommend using the thumbv7m-none-eabi target:</p><ul><li>thumbv7m — Represents the ARM Cortex-M3 microcontroller, a popular family of embedded processors.</li><li>none — Indicates that there is no operating system (OS) available. In Rust, this typically means we can’t rely on the standard library (std), so we use no_std. Recall that the standard library provides core functionality like Vec, String, file input/output, networking, and time.</li><li>eabi — Embedded Application Binary Interface, a standard defining calling conventions, data types, and binary layout for embedded executables.</li></ul><p>Since most embedded processors share the no_std constraint, ensuring compatibility with this target helps ensure compatibility with other embedded targets.</p><p>Install the target and check your project:</p><pre>rustup target add thumbv7m-none-eabi<br>cargo check --target thumbv7m-none-eabi</pre><p>When I did this on range-set-blaze, I encountered errors complaining about dependencies, such as:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1020/1*p1_BrBhFiJhie-cQIZfDeA.png"></figure><p>This shows that my project depends on num-traits, which depends on either, ultimately depending on std.</p><p>The error messages can be confusing. To better understand the situation, run this cargo tree command:</p><pre>cargo tree --edges no-dev --format "{p} {f}"</pre><p>It displays a recursive list of your project’s dependencies and their active Cargo features. For example:</p><pre>range-set-blaze v0.1.6 (C:\deldir\branches\rustconf24.nostd) <br>├── gen_ops v0.3.0<br>├── itertools v0.13.0 default,use_alloc,use_std<br>│   └── either v1.12.0 use_std<br>├── num-integer v0.1.46 default,std<br>│   └── num-traits v0.2.19 default,i128,std<br>│       [build-dependencies]<br>│       └── autocfg v1.3.0<br>└── num-traits v0.2.19 default,i128,std (*)</pre><p>We see multiple occurrences of Cargo features named use_std and std, strongly suggesting that:</p><ul><li>These Cargo features require the standard library.</li><li>We can turn these Cargo features off.</li></ul><p>Using the techniques explained in the <a href="https://medium.com/towards-data-science/nine-rules-for-running-rust-on-wasm-wasi-550cd14c252a">first article</a>, Rule 6, we disable the use_std and std Cargo features. Recall that Cargo features are additive and have defaults. To turn off the default features, we use default-features = false. We then enable the Cargo features we want to keep by specifying, for example, features = ["use_alloc"]. The Cargo.toml now reads:</p><pre>[dependencies]<br>gen_ops = "0.3.0"<br>itertools = { version = "0.13.0", features=["use_alloc"], default-features = false }<br>num-integer = { version = "0.1.46", default-features = false }<br>num-traits = { version = "0.2.19", features=["i128"], default-features = false }<br></pre><p>Turning off Cargo features will not always be enough to make your dependencies no_std-compatible.</p><p>For example, the popular thiserror crate introduces std into your code and offers no Cargo feature to disable it. However, the community has created no_std alternatives. You can find these alternatives by searching, for example, <a href="https://crates.io/search?q=thiserror+no_std">https://crates.io/search?q=thiserror+no_std</a>.</p><p>In the case of range-set-blaze, a problem remained related to crate <a href="https://crates.io/crates/gen_ops">gen_ops</a> — a wonderful crate for conveniently defining operators such as + and &amp;. The crate used std but didn’t need to. I identified the required one-line change (using the methods we'll cover in Rule 3) and submitted a pull request. The maintainer accepted it, and they released an updated version: 0.4.0.</p><p>Sometimes, our project can’t disable std because we need capabilities like file access when running on a full operating system. On embedded systems, however, we're willing—and indeed must—give up such capabilities. In Rule 4, we'll see how to make std usage optional by introducing our own Cargo features.</p><p>Using these methods fixed all the dependency errors in range-set-blaze. However, resolving <strong>those</strong> errors revealed 281 errors in the main code. Progress!</p><h3>Rule 3: Mark main (non-test) code no_std and alloc. Replace std:: with core:: and alloc::.</h3><p>At the top of your project’s lib.rs (or main.rs) add:</p><pre>#![no_std]<br>extern crate alloc;</pre><p>This means we won’t use the standard library, but we will still allocate memory. For range-set-blaze, this change reduced the error count from 281 to 52.</p><p>Many of the remaining errors are due to using items in std that are available in core or alloc. Since much of std is just a re-export of core and alloc, we can resolve many errors by switching std references to core or alloc. This allows us to keep the essential functionality without relying on the standard library.</p><p>For example, we get an error for each of these lines:</p><pre>use std::cmp::max;<br>use std::cmp::Ordering;<br>use std::collections::BTreeMap;</pre><p>Changing std:: to either core:: or (if memory related) alloc:: fixes the errors:</p><pre>use core::cmp::max;<br>use core::cmp::Ordering;<br>use alloc::collections::BTreeMap;</pre><p>Some capabilities, such as file access, are std-only—that is, they are defined outside of core and alloc. Fortunately, for range-set-blaze, switching to core and alloc resolved all 52 errors in the main code. However, this fix revealed 89 errors in its test code. Again, progress!</p><p>We’ll address errors in the test code in Rule 5, but first, let’s figure out what to do if we need capabilities like file access when running on a full operating system.</p><h3>Rule 4: Use Cargo features to let your main code use std optionally for file-related (etc.) functions.</h3><p>If we need two versions of our code — one for running on a full operating system and one for embedded systems — we can use Cargo features (see Rule 6 in the <a href="https://medium.com/towards-data-science/nine-rules-for-running-rust-on-wasm-wasi-550cd14c252a">first article</a>). For example, let’s define a feature called foo, which will be the default. We'll include the function demo_read_ranges_from_file only when foo is enabled.</p><p>In Cargo.toml (preliminary):</p><pre>[features]<br>default = ["foo"]<br>foo = []</pre><p>In lib.rs (preliminary):</p><pre>#![no_std]<br>extern crate alloc;<br><br>// ...<br><br>#[cfg(feature = "foo")]<br>pub fn demo_read_ranges_from_file&lt;P, T&gt;(path: P) -&gt; std::io::Result&lt;RangeSetBlaze&lt;T&gt;&gt;<br>where<br>    P: AsRef&lt;std::path::Path&gt;,<br>    T: FromStr + Integer,<br>{<br>    todo!("This function is not yet implemented.");<br>}</pre><p>This says to define function demo_read_ranges_from_file only when Cargo feature foo is enabled. We can now check various versions of our code:</p><pre>cargo check # enables "foo", the default Cargo features<br>cargo check --features foo # also enables "foo"<br>cargo check --no-default-features # enables nothing</pre><p>Now let’s give our Cargo feature a more meaningful name by renaming foo to std. Our Cargo.toml (intermediate) now looks like:</p><pre>[features]<br>default = ["std"]<br>std = []</pre><p>In our lib.rs, we add these lines near the top to bring in the std library when the std Cargo feature is enabled:</p><pre>#[cfg(feature = "std")]<br>extern crate std;</pre><p>So, lib.rs (final) looks like this:</p><pre>#![no_std]<br>extern crate alloc;<br><br>#[cfg(feature = "std")]<br>extern crate std;<br><br>// ...<br><br>#[cfg(feature = "std")]<br>pub fn demo_read_ranges_from_file&lt;P, T&gt;(path: P) -&gt; std::io::Result&lt;RangeSetBlaze&lt;T&gt;&gt;<br>where<br>    P: AsRef&lt;std::path::Path&gt;,<br>    T: FromStr + Integer,<br>{<br>    todo!("This function is not yet implemented.");<br>}</pre><p>We’d like to make one more change to our Cargo.toml. We want our new Cargo feature to control dependencies and their features. Here is the resulting Cargo.toml (final):</p><pre>[features]<br>default = ["std"]<br>std = ["itertools/use_std", "num-traits/std", "num-integer/std"]<br><br>[dependencies]<br>itertools = { version = "0.13.0", features = ["use_alloc"], default-features = false }<br>num-integer = { version = "0.1.46", default-features = false }<br>num-traits = { version = "0.2.19", features = ["i128"], default-features = false }<br>gen_ops = "0.4.0"</pre><blockquote>Aside: If you’re confused by the Cargo.toml format for specifying dependencies and features, see my recent article: <a href="https://medium.com/towards-data-science/nine-rust-cargo-toml-wats-and-wat-nots-1e5e02e41648"><em>Nine Rust Cargo.toml Wats and Wat Nots: Master Cargo.toml formatting rules and avoid frustration</em></a><em> in</em> Towards Data Science.</blockquote><p>To check that your project compiles both with the standard library (std) and without, use the following commands:</p><pre>cargo check # std<br>cargo check --no-default-features # no_std</pre><p>With cargo check working, you’d think that cargo test would be straight forward. Unfortunately, it’s not. We’ll look at that next.</p><h3>Rule 5: Understand why test code always uses the standard library.</h3><p>When we compile our project with --no-default-features, it operates in a no_std environment. However, Rust's testing framework always includes the standard library, even in a no_std project. This is because cargo test requires std; for example, the #[test] attribute and the test harness itself are defined in the standard library.</p><p>As a result, running:</p><pre># DOES NOT TEST `no_std`<br>cargo test --no-default-features</pre><p>does not actually test the no_std version of your code. Functions from std that are unavailable in a true no_std environment will still be accessible during testing. For instance, the following test will compile and run successfully with --no-default-features, even though it uses std::fs:</p><pre>#[test]<br>fn test_read_file_metadata() {<br>    let metadata = std::fs::metadata("./").unwrap();<br>    assert!(metadata.is_dir());<br>}</pre><p>Additionally, when testing in std mode, you may need to add explicit imports for features from the standard library. This is because, even though std is available during testing, your project is still compiled as #![no_std], meaning the standard prelude is not automatically in scope. For example, you’ll often need the following imports in your test code:</p><pre>#![cfg(test)]<br>use std::prelude::v1::*;<br>use std::{format, print, println, vec};</pre><p>These imports bring in the necessary utilities from the standard library so that they are available during testing.</p><p>To genuinely test your code without the standard library, you’ll need to use alternative methods that do not rely on cargo test. We'll explore how to run no_std tests in the next rule.</p><h3>Rule 6: Create a simple embedded test project. Run it with QEMU.</h3><p>You can’t run your regular tests in an embedded environment. However, you <strong>can</strong> — and should — run at least one embedded test. My philosophy is that even a single test is infinitely better than none. Since “if it compiles, it works” is generally true for no_std projects, one (or a few) well-chosen test can be quite effective.</p><p>To run this test, we use QEMU (Quick Emulator, pronounced “cue-em-you”), which allows us to emulate thumbv7m-none-eabi code on our main operating system (Linux, Windows, or macOS).</p><h4>Install QEMU.</h4><p>See the QEMU <a href="https://www.qemu.org/download/">download page</a> for full information:</p><p><strong>Linux/WSL</strong></p><ul><li>Ubuntu: sudo apt-get install qemu-system</li><li>Arch: sudo pacman -S qemu-system-arm</li><li>Fedora: sudo dnf install qemu-system-arm</li></ul><p><strong>Windows</strong></p><ul><li>Method 1: <a href="https://qemu.weilnetz.de/w64">https://qemu.weilnetz.de/w64</a>. Run the installer (tell Windows that it is OK). Add "C:\Program Files\qemu\" to your path.</li><li>Method 2: Install MSYS2 from <a href="https://www.msys2.org/">https://www.msys2.org/</a>. Open MSYS2 UCRT64 terminal. pacman -S mingw-w64-x86_64-qemu. Add C:\msys64\mingw64\bin\ to your path.</li></ul><p><strong>Mac</strong></p><ul><li>brew install qemu or sudo port install qemu</li></ul><p>Test installation with:</p><pre>qemu-system-arm --version</pre><h4>Create an embedded subproject.</h4><p>Create a subproject for the embedded tests:</p><pre>cargo new tests/embedded</pre><p>This command generates a new subproject, including the configuration file at tests/embedded/Cargo.toml.</p><blockquote>Aside<strong>:</strong> This command also modifies your top-level Cargo.toml to add the subproject to your workspace. In Rust, a workspace is a collection of related packages defined in the [workspace] section of the top-level Cargo.toml. All packages in the workspace share a single Cargo.lock file, ensuring consistent dependency versions across the entire workspace.</blockquote><p>Edit tests/embedded/Cargo.toml to look like this, but replace "range-set-blaze" with the name of your top-level project:</p><pre>[package]<br>name = "embedded"<br>version = "0.1.0"<br>edition = "2021"<br><br>[dependencies]<br>alloc-cortex-m = "0.4.4"<br>cortex-m = "0.7.7"<br>cortex-m-rt = "0.7.3"<br>cortex-m-semihosting = "0.5.0"<br>panic-halt = "0.2.0"<br># Change to refer to your top-level project<br>range-set-blaze = { path = "../..", default-features = false }</pre><h4>Update the test code.</h4><p>Replace the contents of tests/embedded/src/main.rs with:</p><pre>// Based on https://github.com/rust-embedded/cortex-m-quickstart/blob/master/examples/allocator.rs<br>// and https://github.com/rust-lang/rust/issues/51540<br>#![feature(alloc_error_handler)]<br>#![no_main]<br>#![no_std]<br>extern crate alloc;<br>use alloc::string::ToString;<br>use alloc_cortex_m::CortexMHeap;<br>use core::{alloc::Layout, iter::FromIterator};<br>use cortex_m::asm;<br>use cortex_m_rt::entry;<br>use cortex_m_semihosting::{debug, hprintln};<br>use panic_halt as _;<br>#[global_allocator]<br>static ALLOCATOR: CortexMHeap = CortexMHeap::empty();<br>const HEAP_SIZE: usize = 1024; // in bytes<br>#[alloc_error_handler]<br>fn alloc_error(_layout: Layout) -&gt; ! {<br>    asm::bkpt();<br>    loop {}<br>}<br><br>#[entry]<br>fn main() -&gt; ! {<br>    unsafe { ALLOCATOR.init(cortex_m_rt::heap_start() as usize, HEAP_SIZE) }<br><br>    // Test(s) goes here. Run only under emulation<br>    use range_set_blaze::RangeSetBlaze;<br>    let range_set_blaze = RangeSetBlaze::from_iter([100, 103, 101, 102, -3, -4]);<br>    hprintln!("{:?}", range_set_blaze.to_string());<br>    if range_set_blaze.to_string() != "-4..=-3, 100..=103" {<br>        debug::exit(debug::EXIT_FAILURE);<br>    }<br><br>    debug::exit(debug::EXIT_SUCCESS);<br>    loop {}<br>}</pre><p>Most of this main.rs code is embedded system boilerplate. The actual test code is:</p><pre>use range_set_blaze::RangeSetBlaze;<br>let range_set_blaze = RangeSetBlaze::from_iter([100, 103, 101, 102, -3, -4]);<br>hprintln!("{:?}", range_set_blaze.to_string());<br>if range_set_blaze.to_string() != "-4..=-3, 100..=103" {<br>    debug::exit(debug::EXIT_FAILURE);<br>}</pre><p>If the test fails, it returns EXIT_FAILURE; otherwise, it returns EXIT_SUCCESS. We use the hprintln! macro to print messages to the console during emulation. Since this is an embedded system, the code ends in an infinite loop to run continuously.</p><h4>Add supporting files.</h4><p>Before you can run the test, you must add two files to the subproject: build.rs and memory.x from the Cortex-M <a href="https://github.com/rust-embedded/cortex-m-quickstart/tree/master">quickstart repository</a>:</p><p><strong>Linux/WSL/macOS</strong></p><pre>cd tests/embedded<br>wget https://raw.githubusercontent.com/rust-embedded/cortex-m-quickstart/master/build.rs<br>wget https://raw.githubusercontent.com/rust-embedded/cortex-m-quickstart/master/memory.</pre><p><strong>Windows (Powershell)</strong></p><pre>cd tests/embedded<br>Invoke-WebRequest -Uri 'https://raw.githubusercontent.com/rust-embedded/cortex-m-quickstart/master/build.rs' -OutFile 'build.rs'<br>Invoke-WebRequest -Uri 'https://raw.githubusercontent.com/rust-embedded/cortex-m-quickstart/master/memory.x' -OutFile 'memory.x'</pre><p>Also, create a tests/embedded/.cargo/config.toml with the following content:</p><pre>[target.thumbv7m-none-eabi]<br>runner = "qemu-system-arm -cpu cortex-m3 -machine lm3s6965evb -nographic -semihosting-config enable=on,target=native -kernel"<br><br>[build]<br>target = "thumbv7m-none-eabi"</pre><p>This configuration instructs Cargo to use QEMU to run the embedded code and sets thumbv7m-none-eabi as the default target for the subproject.</p><h4>Run the test.</h4><p>Run the test with cargo run (not cargo test):</p><pre># Setup<br># Make this subproject 'nightly' to support #![feature(alloc_error_handler)]<br>rustup override set nightly<br>rustup target add thumbv7m-none-eabi<br><br># If needed, cd tests/embedded<br>cargo run</pre><p>You should see log messages, and the process should exit without error. In my case, I see: "-4..=-3, 100..=103".</p><p>These steps may seem like a significant amount of work just to run one (or a few) tests. However, it’s primarily a one-time effort involving mostly copy and paste. Additionally, it enables running tests in a CI environment (see Rule 9). The alternative — claiming that the code works in a no_std environment without ever actually running it in no_std—risks overlooking critical issues.</p><p>The next rule is much simpler.</p><h3>Rule 7: In Cargo.toml, add keywords and categories for WASM and no_std.</h3><p>Once your package compiles and passes the additional embedded test, you may want to publish it to <a href="https://crates.io/">crates.io</a>, Rust’s package registry. To let others know that it is compatible with WASM and no_std, add the following keywords and categories to your Cargo.toml file:</p><pre>[package]<br># ... <br>categories = ["no-std", "wasm", "embedded"] # + others specific to your package<br>keywords = ["no_std", "wasm"] # + others specific to your package</pre><p>Note that for categories, we use a hyphen in no-std. For keywords, no_std (with an underscore) is more popular than no-std. Your package can have a maximum of five keywords and five categories.</p><p>Here is a list of <a href="https://crates.io/categories/">categories</a> and <a href="https://crates.io/keywords">keywords</a> of possible interest, along with the number of crates using each term:</p><ul><li><a href="https://crates.io/categories/no-std?sort=downloads">Category no-std</a> (6884)</li><li><a href="https://crates.io/categories/embedded?sort=downloads">Category embedded</a> (3455)</li><li><a href="https://crates.io/categories/wasm?sort=downloads">Category wasm</a> (2026)</li><li><a href="https://crates.io/categories/no-std::no-alloc?sort=downloads">Category no-std::no-alloc</a> (581)</li><li><a href="https://crates.io/keywords/wasm?sort=downloads">Keyword wasm</a> (1686)</li><li><a href="https://crates.io/keywords/no_std?sort=downloads">Keyword no_std</a> (1351)</li><li><a href="https://crates.io/keywords/no-std?sort=downloads">Keyword no-std</a> (1157)</li><li><a href="https://crates.io/keywords/embedded?sort=downloads">Keyword embedded</a> (925)</li><li><a href="https://crates.io/keywords/webassembly?sort=downloads">Keyword webassembly</a> (804)</li></ul><p>Good categories and keywords will help people find your package, but the system is informal. There’s no mechanism to check whether your categories and keywords are accurate, nor are you required to provide them.</p><p>Next, we’ll explore one of the most restricted environments you’re likely to encounter.</p><h3>Rule 8: [Optional] Use preallocated data types to avoid alloc.</h3><p>My project, range-set-blaze, implements a dynamic data structure that requires memory allocation from the heap (via alloc). But what if your project doesn't need dynamic memory allocation? In that case, it can run in even more restricted embedded environments—specifically those where all memory is preallocated when the program is loaded.</p><p>The reasons to avoid alloc if you can:</p><ul><li>Completely deterministic memory usage</li><li>Reduced risk of runtime failures (often caused by memory fragmentation)</li><li>Lower power consumption</li></ul><p>There are crates available that can sometimes help you replace dynamic data structures like Vec, String, and HashMap. These alternatives generally require you to specify a maximum size. The table below shows some popular crates for this purpose:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/339/1*7x5O4wXw_TY-2HAH5Ui97w.png"></figure><p>I recommend the heapless crate because it provides a collection of data structures that work well together.</p><p>Here is an example of code — using heapless — related to an LED display. This code creates a mapping from a byte to a list of integers. We limit the number of items in the map and the length of the integer list to DIGIT_COUNT (in this case, 4).</p><pre>use heapless::{LinearMap, Vec};<br>// …<br>let mut map: LinearMap&lt;u8, Vec&lt;usize, DIGIT_COUNT&gt;, DIGIT_COUNT&gt; = LinearMap::new();<br>// …<br>let mut vec = Vec::default();<br>vec.push(index).unwrap();<br>map.insert(*byte, vec).unwrap(); // actually copies</pre><p>Full details about creating a no_alloc project are beyond my experience. However, the first step is to remove this line (added in Rule 3) from your lib.rs or main.rs:</p><pre>extern crate alloc; // remove this</pre><h3>Rule 9: Add thumbv7m-none-eabi and QEMU to your CI (continuous integration) tests.</h3><p>Your project is now compiling to no_std and passing at least one embedded-specific test. Are you done? Not quite. As I said in the previous two articles:</p><blockquote>If it’s not in CI, it doesn’t exist.</blockquote><p>Recall that continuous integration (CI) is a system that can automatically run tests every time you update your code. I use GitHub Actions as my CI platform. Here’s the configuration I added to .github/workflows/ci.yml to test my project on embedded platforms:</p><pre>test_thumbv7m_none_eabi:<br>    name: Setup and Check Embedded<br>    runs-on: ubuntu-latest<br>    steps:<br>      - name: Checkout<br>        uses: actions/checkout@v4<br>      - name: Set up Rust<br>        uses: dtolnay/rust-toolchain@master<br>        with:<br>          toolchain: stable<br>          target: thumbv7m-none-eabi<br>      - name: Install check stable and nightly<br>        run: |<br>          cargo check --target thumbv7m-none-eabi --no-default-features<br>          rustup override set nightly<br>          rustup target add thumbv7m-none-eabi<br>          cargo check --target thumbv7m-none-eabi --no-default-features<br>          sudo apt-get update &amp;&amp; sudo apt-get install qemu qemu-system-arm<br>      - name: Test Embedded (in nightly)<br>        timeout-minutes: 1<br>        run: |<br>          cd tests/embedded<br>          cargo run</pre><p>By testing embedded and no_std with CI, I can be sure that my code will continue to support embedded platforms in the future.</p><p>So, there you have it — nine rules for porting your Rust code to embedded. To see a snapshot of the whole range-set-blaze project after applying all nine rules, see <a href="https://github.com/CarlKCarlK/range-set-blaze/tree/rustconf24.nostd">this branch on Github</a>.</p><p>Here is what surprised me about porting to embedded:</p><p><strong>The Bad:</strong></p><ul><li>We cannot run our existing tests on embedded systems. Instead, we must create a new subproject and write (a few) new tests.</li><li>Many popular libraries rely on std, so finding or adapting dependencies that work with no_std can be challenging.</li></ul><p><strong>The Good:</strong></p><ul><li>The Rust saying that “if it compiles, it works” holds true for embedded development. This gives us confidence in our code’s correctness without requiring extensive new tests.</li><li>Although no_std removes our immediate access to the standard library, many items continue to be available via core and alloc.</li><li>Thanks to emulation, you can develop for embedded systems without hardware.</li></ul><p>Thank you for joining me on this journey from WASI to WebAssembly in the browser and, finally, to embedded development. Rust has continued to impress me with its ability to run efficiently and safely across environments. As you explore these different domains, I hope you find Rust’s flexibility and power as compelling as I do. Whether you’re working on cloud servers, browsers, or microcontrollers, the tools we’ve discussed will help you tackle the challenges ahead with confidence.</p><blockquote>Interested in future articles? Please <a href="https://medium.com/@carlmkadie">follow me on Medium</a>. I write about Rust and Python, scientific programming, machine learning, and statistics. I tend to write about one article per month.</blockquote><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=b0c247ee877e" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/nine-rules-for-running-rust-on-embedded-systems-b0c247ee877e">Nine Rules for Running Rust on Embedded Systems</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA['Running Clang in the Browser Using WebAssembly']]></title>
<description><![CDATA[This week (MIT-licensed) WebAssembly runtime Wasmer announced "a major milestone in making any software run with WebAssembly." 

The announcement's headline? Running Clang in the browser using WebAssembly...

Thanks to the newest release of Wasmer (4.4) and the Wasmer JS SDK (0.8.0) you can now r...]]></description>
<link>https://tsecurity.de/de/2382591/it-security-nachrichten/running-clang-in-the-browser-using-webassembly/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2382591/it-security-nachrichten/running-clang-in-the-browser-using-webassembly/</guid>
<pubDate>Sat, 12 Oct 2024 17:48:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[This week (MIT-licensed) WebAssembly runtime Wasmer announced "a major milestone in making any software run with WebAssembly." 

The announcement's headline? Running Clang in the browser using WebAssembly...

Thanks to the newest release of Wasmer (4.4) and the Wasmer JS SDK (0.8.0) you can now run [compiler front-end] clang anywhere Wasmer runs! This allows compiling C programs from virtually anywhere. Including Javascript and your preferred browser! (we tested Chrome, Safari and Firefox and everything is working like a charm)... 

- You can compile C code to WebAssembly easily just using the Wasmer CLI: no toolchains or complex installations needed, install Wasmer and you are ready to go...! 

- You can compile C projects directly from JavaScript...! 

- We expect online IDEs to start adopting the SDK to allow their users compile and run C programs in the browser.... 



Do you want to use clang in your Javascript project? Thanks to our newly released Wasmer JS SDK you can do it easily, in both the browser and Node.js/Bun etc... Wasmer's clang can even optimize the file for you automatically using wasm-opt under the hood (Clang automatically detects if wasm-opt is used, and it will be automatically called when optimizing the file). Imagine using Emscripten without needing its toolchain installed — or even better, imagine running Emscripten in the browser. 

The announcement looks to a future of compiling native Python libraries, when "any project depending on LLVM can now be easily compiled to WebAssembly..." 

"This is the beginning of an awesome journey, we can't wait to see what you create next with this."<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status='Running+Clang+in+the+Browser+Using+WebAssembly'%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F24%2F10%2F12%2F0519256%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F24%2F10%2F12%2F0519256%2Frunning-clang-in-the-browser-using-webassembly%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/24/10/12/0519256/running-clang-in-the-browser-using-webassembly?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WebAssembly, WASI und Rust: Dreamteam für Microservices​]]></title>
<description><![CDATA[Das WebAssembly System Interface standardisiert das Zusammenspiel von Wasm-Modulen in unterschiedlichen Programmiersprachen, und Rust ist bestens aufgestellt.​]]></description>
<link>https://tsecurity.de/de/2382162/it-nachrichten/webassembly-wasi-und-rust-dreamteam-fuer-microservices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2382162/it-nachrichten/webassembly-wasi-und-rust-dreamteam-fuer-microservices/</guid>
<pubDate>Sat, 12 Oct 2024 10:00:47 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das WebAssembly System Interface standardisiert das Zusammenspiel von Wasm-Modulen in unterschiedlichen Programmiersprachen, und Rust ist bestens aufgestellt.​]]></content:encoded>
</item>
<item>
<title><![CDATA[Nine Rules for Running Rust in the Browser]]></title>
<description><![CDATA[Practical lessons from porting range-set-blaze to WASMRust Running on the Browser — Source: https://openai.com/dall-e-2/. All other figures from the author.Do you want your Rust code to run everywhere — from large servers to web pages, robots, and even watches? In this second of three articles, I...]]></description>
<link>https://tsecurity.de/de/2373517/ai-nachrichten/nine-rules-for-running-rust-in-the-browser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2373517/ai-nachrichten/nine-rules-for-running-rust-in-the-browser/</guid>
<pubDate>Tue, 08 Oct 2024 09:34:02 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Practical lessons from porting range-set-blaze to WASM</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bJMEk3SenNEuH7XyAUbEZQ.png"><figcaption>Rust Running on the Browser — Source: <a href="https://openai.com/dall-e-2/">https://openai.com/dall-e-2/</a>. All other figures from the author.</figcaption></figure><p>Do you want your Rust code to run everywhere — from large servers to web pages, robots, and even watches? In this second of three articles, I’ll show you how to use WebAssembly (WASM) to run your Rust code directly in the user’s browser.</p><p>With this technique, you can provide CPU-intensive, dynamic web pages from a — perhaps free — static web server. As a bonus, a user’s data never leaves their machine, avoiding privacy issues. For example, I offer a tool to search race results for friends, running club members, and teammates. To see the tool, go to <a href="https://carlkcarlk.github.io/race-results/matcher/">its web page</a>, and click “match”.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/517/1*fVWhYH4sMcFk2Kiaa2vv2g.png"></figure><blockquote>Aside: To learn more about matching names, see <a href="https://medium.com/towards-data-science/use-bayes-theorem-to-find-distinctive-names-in-a-list-5acd8fe03c2b">Use Bayes’ Theorem to Find Distinctive Names in a List</a> in <em>Towards Data Science.</em></blockquote><p>Running Rust in the browser presents challenges. Your code doesn’t have access to a full operating system like Linux, Windows, or macOS. You have no direct access to files or networks. You have only limited access to time and random numbers. We’ll explore workarounds and solutions.</p><p>Porting code to WASM in the browser requires several steps and choices, and navigating these can be time-consuming. Missing a step can lead to failure. We’ll reduce this complication by offering nine rules, which we’ll explore in detail:</p><ol><li>Confirm that your existing app works with WASM WASI and create a simple JavaScript web page.</li><li>Install the wasm32-unknown-unknown target, wasm-pack, wasm-bindgen-cli, and Chrome for Testing &amp; Chromedriver.</li><li>Make your project cdylib (and rlib), add wasm-bindgen dependencies, and test.</li><li>Learn what types wasm-bindgen supports.</li><li>Change functions to use supported types. Change files to generic BufRead.</li><li>Adapt tests, skipping those that don’t apply.</li><li>Change to JavaScript-friendly dependencies, if necessary. Run tests.</li><li>Connect your web page to your functions.</li><li>Add wasm-pack to your CI (continuous integration) tests.</li></ol><blockquote>Aside: These articles are based on a three-hour workshop that I presented at <a href="https://rustconf.com/programs/#755">RustConf24</a> in Montreal. Thanks to the participants of that workshop. A special thanks, also, to the volunteers from the Seattle Rust Meetup who helped test this material. These articles replace <a href="https://medium.com/towards-data-science/nine-rules-for-running-rust-on-the-web-and-on-embedded-94462ef249a2">an article I wrote last year</a> with updated information.</blockquote><p>As with <a href="https://medium.com/towards-data-science/nine-rules-for-running-rust-on-wasm-wasi-550cd14c252a">the first article in this series</a>, before we look at the rules one by one, let’s define our terms.</p><ul><li><strong>Native:</strong> Your home OS (Linux, Windows, macOS)</li><li><strong>Standard library (std)</strong>: Provides Rust’s core functionality — Vec, String, file input/output, networking, time.</li><li><strong>WASM</strong>: WebAssembly (WASM) is a binary instruction format that runs in most browsers (and beyond).</li><li><strong>WASI</strong>: WebAssembly System Interface (WASI) allows outside-the-browser WASM to access file I/O, networking (not yet), and time handling.</li><li><strong>no_std</strong>: Instructs a Rust program not to use the full standard library, making it suitable for small, embedded devices or highly resource-constrained environments.</li><li><strong>alloc</strong>: Provides heap memory allocation capabilities (Vec, String, etc.) in no_std environments, essential for dynamically managing memory.</li></ul><p>Based on my experience with <a href="https://github.com/CarlKCarlK/range-set-blaze">range-set-blaze</a>, a data structure project, here are the decisions I recommend, described one at a time. To avoid wishy-washiness, I’ll express them as rules.</p><h3>Rule 1: Confirm that your existing app works with WASM WASI and create a simple JavaScript web page.</h3><p>Getting your Rust code to run in the browser will be easier if you meet two prerequisites:</p><ul><li>Get your Rust code running in WASM WASI.</li><li>Get some JavaScript to run in the browser.</li></ul><p>For the first prerequisite, see <a href="https://medium.com/towards-data-science/nine-rules-for-running-rust-on-wasm-wasi-550cd14c252a">Nine Rules for Running Rust on WASM WASI</a> in <em>Towards Data Science</em>. That article — the first article in this series — details how to move your code from your native operating system to WASM WASI. With that move, you will be halfway to running on WASM in the Browser.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/700/0*tY9dG3h58NSfRgIj.png"><figcaption>Environments in which we wish to run our code as a Venn diagram of progressively tighter constraints.</figcaption></figure><p>Confirm your code runs on WASM WASI via your tests:</p><pre>rustup target add wasm32-wasip1<br>cargo install wasmtime-cli<br>cargo test --target wasm32-wasip1</pre><p>For the second prerequisite, show that you can create some JavaScript code and run it in a browser. I suggest adding this index.html file to the top level of your project:</p><pre>&lt;!DOCTYPE html&gt;<br>&lt;html lang="en"&gt;<br>&lt;head&gt;<br>    &lt;meta charset="UTF-8"&gt;<br>    &lt;meta name="viewport" content="width=device-width, initial-scale=1.0"&gt;<br>    &lt;title&gt;Line Counter&lt;/title&gt;<br>&lt;/head&gt;<br>&lt;body&gt;<br>    &lt;h1&gt;Line Counter&lt;/h1&gt;<br>    &lt;input type="file" id="fileInput" /&gt;<br>    &lt;p id="lineCount"&gt;Lines in file: &lt;/p&gt;<br>    &lt;script&gt;<br>        const output = document.getElementById('lineCount');<br>        document.getElementById('fileInput').addEventListener('change', (event) =&gt; {<br>            const file = event.target.files[0];<br>            if (!file) { output.innerHTML = ''; return } // No file selected<br>            const reader = new FileReader();<br>            // When the file is fully read<br>            reader.onload = async (e) =&gt; {                <br>                const content = e.target.result;<br>                const lines = content.split(/\r\n|\n/).length;<br>                output.textContent = `Lines in file: ${lines}`;<br>            };<br>            // Now start to read the file as text<br>            reader.readAsText(file);<br>        });<br>    &lt;/script&gt;<br>&lt;/body&gt;<br>&lt;/html&gt;</pre><p>Now, serve this page to your browser. You can serve web pages via an editor extension. I use <a href="https://marketplace.visualstudio.com/items?itemName=ms-vscode.live-server">Live Preview</a> for VS Code. Alternatively, you can install and use a standalone web server, such as <a href="https://github.com/TheWaWaR/simple-http-server">Simple Html Server</a>:</p><pre>cargo install simple-http-server<br>simple-http-server --ip 127.0.0.1 --port 3000 --index<br># then open browser to http://127.0.0.1:3000</pre><p>You should now see a web page on which you can select a file. The JavaScript on the page counts the lines in the file.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/587/1*5na_1RmA5qvuYKe65En6qQ.png"></figure><p>Let’s go over the key parts of the JavaScript because later we will change it to call Rust.</p><blockquote>Aside: Must you learn JavaScript to use Rust in the browser? Yes and no. Yes, you’ll need to create at least some simple JavaScript code. No, you may not need to “learn”<strong> </strong>JavaScript. I’ve found ChatGPT good enough to generate the simple JavaScript that I need.</blockquote><ul><li>See what file the user chose. If none, just return:</li></ul><pre>const file = event.target.files[0];<br>if (!file) { output.innerHTML = ''; return } // No file selected</pre><ul><li>Create a new FileReader object, do some setup, and then read the file as text:</li></ul><pre>const reader = new FileReader();<br>// ... some setup ...<br>// Now start to read the file as text<br>reader.readAsText(file);</pre><ul><li>Here is the setup. It says: wait until the file is fully read, read its contents as a string, split the string into lines, and display the number of lines.</li></ul><pre>// When the file is fully read<br>reader.onload = async (e) =&gt; {                <br>    const content = e.target.result;<br>    const lines = content.split(/\r\n|\n/).length;<br>    output.textContent = `Lines in file: ${lines}`;<br>    };</pre><p>With the prerequisites fulfilled, we turn next to installing the needed WASM-in-the-Browser tools.</p><h3>Rule 2: Install the wasm32-unknown-unknown target, wasm-pack, wasm-bindgen-cli, and Chrome for Testing &amp; Chromedriver.</h3><p>We start with something easy, installing these three tools:</p><pre>rustup target add wasm32-unknown-unknown<br>cargo install wasm-pack --force<br>cargo install wasm-bindgen-cli --force</pre><p>The first line installs a new target, wasm32-unknown-unknown. This target compiles Rust to WebAssembly without any assumptions about the environment the code will run in. The lack of assumptions makes it suitable to run in browsers. (For more on targets, see the <a href="https://medium.com/towards-data-science/nine-rules-for-running-rust-on-wasm-wasi-550cd14c252a">previous article</a>’s Rule #2.)</p><p>The next two lines install wasm-pack and wasm-bindgen-cli, command-line utilities. The first builds, packages, and publishes into a form suitable for use by a web page. The second makes testing easier. We use --force to ensure the utilities are up-to-date and mutually compatible.</p><p>Now, we get to the annoying part, installing Chrome for Testing &amp; Chromedriver. Chrome for Testing is an automatable version of the Chrome browser. Chromedriver is a separate program that can take your Rust tests cases and run them inside Chrome for Testing.</p><p>Why is installing them annoying? First, the process is somewhat complex. Second, the version of Chrome for Testing must match the version of Chromedriver. Third, installing Chrome for Testing will conflict with your current installation of regular Chrome.</p><p>With that background, here are my suggestions. Start by installing the two programs into a dedicated subfolder of your home directory.</p><ul><li>Linux and WSL (Windows Subsystem for Linux):</li></ul><pre>cd ~<br>mkdir -p ~/.chrome-for-testing<br>cd .chrome-for-testing/<br>wget https://storage.googleapis.com/chrome-for-testing-public/129.0.6668.70/linux64/chrome-linux64.zip<br>wget https://storage.googleapis.com/chrome-for-testing-public/129.0.6668.70/linux64/chromedriver-linux64.zip<br>unzip chrome-linux64.zip<br>unzip chromedriver-linux64.zip</pre><ul><li>Windows (PowerShell):</li></ul><pre>New-Item -Path $HOME -Name ".chrome-for-testing" -ItemType "Directory"<br>Set-Location -Path $HOME\.chrome-for-testing<br>bitsadmin /transfer "ChromeDownload" https://storage.googleapis.com/chrome-for-testing-public/129.0.6668.70/win64/chrome-win64.zip $HOME\.chrome-for-testing\chrome-win64.zip<br>bitsadmin /transfer "ChromeDriverDownload" https://storage.googleapis.com/chrome-for-testing-public/129.0.6668.70/win64/chromedriver-win64.zip $HOME\.chrome-for-testing\chromedriver-win64.zip<br>Expand-Archive -Path "$HOME\.chrome-for-testing\chrome-win64.zip" -DestinationPath "$HOME\.chrome-for-testing"<br>Expand-Archive -Path "$HOME\.chrome-for-testing\chromedriver-win64.zip" -DestinationPath "$HOME\.chrome-for-testing"</pre><blockquote>Aside: I’m sorry but I haven’t tested any Mac instructions. Please see <a href="https://googlechromelabs.github.io/chrome-for-testing/">the Chrome for Testing web page</a> and then try to adapt the Linux method. If you let me know what works, I’ll update this section.</blockquote><p>This installs version 129.0.6668.70, the stable version as of 9/30/2024. If you wish, check the <a href="https://googlechromelabs.github.io/chrome-for-testing/">Chrome for Testing Availability</a> page for newer stable versions.</p><p>Next, we need to add these programs to our PATH. We can add them temporarily, meaning only for the current terminal session:</p><ul><li>Linux and WSL (just for this session):</li></ul><pre>export PATH=~/.chrome-for-testing/chrome-linux64:~/.chrome-for-testing/chromedriver-linux64:$PATH</pre><ul><li>Windows (just for this session):</li></ul><pre># PowerShell<br>$env:PATH = "$HOME\.chrome-for-testing\chrome-win64;$HOME\.chrome-for-testing\chromedriver-win64;$PATH"<br># or, CMD<br>set PATH=%USERPROFILE%\.chrome-for-testing\chrome-win64;%USERPROFILE%\.chrome-for-testing\chromedriver-win64;%PATH%</pre><p>Alternatively, we can add them to our PATH permanently for all future terminal sessions. Understand that this may interfere with access to your regular version of Chrome.</p><p>Linux and WSL (then restart your terminal):</p><pre>echo 'export PATH=~/.chrome-for-testing/chrome-linux64:~/.chrome-for-testing/chromedriver-linux64:$PATH' &gt;&gt; ~/.bashrc</pre><p>Windows (PowerShell, then restart your terminal):</p><pre>[System.Environment]::SetEnvironmentVariable("Path", "$HOME\.chrome-for-testing\chrome-win64;$HOME\.chrome-for-testing\chromedriver-win64;" + $env:PATH, [System.EnvironmentVariableTarget]::User)</pre><p>Once installed, you can verify the installation with:</p><pre>chromedriver --version</pre><blockquote>Aside: Can you skip installing and using Chrome for Testing and Chromedriver? Yes and no. If you skip them, you’ll still be able to create WASM from your Rust. Moreover, you’ll be able to call that WASM from JavaScript in a web page.</blockquote><blockquote>However, your project — like all good code — should already contain tests. If you skip Chrome for Testing, you will not be able to run WASM-in-the-Browser test cases. Moreover, WASM in the Browser violates Rust’s “If it compiles, it works” principle. Specifically, if you use an unsupported feature, like file access, compiling to WASM won’t catch the error. Only test cases can catch such errors. This makes running test cases critically important.</blockquote><p>Now that we have the tools to run tests in the browser, let’s try (and almost certainly fail) to run those tests.</p><h3>Rule 3: Make your project cdylib (and rlib), add wasm-bindgen dependencies, and test.</h3><p>The wasm-bindgen package is a set of automatically generated bindings between Rust and JavaScript. It lets JavaScript call Rust.</p><p>To prepare your code for WASM in the Browser, you’ll make your project a library project. Additionally, you’ll add and use wasm-bindgen dependencies. Follow these steps:</p><ul><li>If your project is executable, change it to a library project by renaming src/main.rs to src/lib.rs. Also, comment out your main function.</li><li>Make your project create both a static library (the default) and a dynamic library (needed by WASM). Specifically, edit Cargo.toml to include:</li></ul><pre>[lib]<br>crate-type = ["cdylib", "rlib"]</pre><ul><li>Add wasm-bindgen dependencies:</li></ul><pre>cargo add wasm-bindgen<br>cargo add wasm-bindgen-test --dev</pre><ul><li>Create or update .cargo/config.toml (not to be confused with Cargo.toml) to include:</li></ul><pre>[target.wasm32-unknown-unknown]<br>runner = "wasm-bindgen-test-runner"</pre><p>Next, what functions do you wish to be visible to JavaScript? Mark those functions with #[wasm_bindgen] and make them pub (public). At the top of the functions’ files, add use wasm_bindgen::prelude::*;.</p><blockquote>Aside: For now, your functions may fail to compile. We’ll address this issue in subsequent rules.</blockquote><p>What about tests? Everywhere you have a #[test] add a #[wasm_bindgen_test]. Where needed for tests, add this use statement and a configuration statement:</p><pre>use wasm_bindgen_test::wasm_bindgen_test;<br>wasm_bindgen_test::wasm_bindgen_test_configure!(run_in_browser);</pre><p>If you like, you can try the preceding steps on a small, sample project. Install the sample project from GitHub:</p><pre># cd to the top of a work directory<br>git clone --branch native_version --single-branch https://github.com/CarlKCarlK/rustconf24-good-turing.git good-turing<br>cd good-turing<br>cargo test<br>cargo run pg100.txt</pre><p>Here we see all these changes on the small, sample project’s lib.rs:</p><pre>// --- May fail to compile for now. ---<br>use wasm_bindgen::prelude::*;<br>// ...<br>#[wasm_bindgen]<br>pub fn good_turing(file_name: &amp;str) -&gt; Result&lt;(u32, u32), io::Error&gt; {<br>    let reader = BufReader::new(File::open(file_name)?);<br>    // ...<br>}<br>// fn main() {<br>// ...<br>// }<br>#[cfg(test)]<br>mod tests {<br>    use wasm_bindgen_test::wasm_bindgen_test;<br>    wasm_bindgen_test::wasm_bindgen_test_configure!(run_in_browser);<br>    // ...<br>    #[test]<br>    #[wasm_bindgen_test]<br>    fn test_process_file() {<br>      let (prediction, actual) = good_turing("./pg100.txt").unwrap();<br>      // ...<br>    }<br>}</pre><p>With these changes made, we’re ready to test (and likely fail):</p><pre>cargo test --target wasm32-unknown-unknown</pre><p>On this sample, the compiler complains that WASM in the Browser doesn’t like to return tuple types, here, (u32, u32). It also complains that it doesn’t like to return a Result with io::Error. To fix these problems, we’ll need to understand which types WASM in the Browser supports. That’s the topic of Rule 4.</p><p>What will happen after we fix the type problems and can run the test? The test will still fail, but now with a runtime error. WASM in the Browser doesn’t support reading from files. The sample test, however, tries to read from a file. In Rule 5, we’ll discuss workarounds for both type limitations and file-access restrictions.</p><h3>Rule 4: Learn what types wasm-bindgen supports.</h3><p>Rust functions that JavaScript can see must have input and output types that wasm-bindgen supports. Use of unsupported types causes compiler errors. For example, passing in a u32 is fine. Passing in a tuple of (u32, 32) is not.</p><p>More generally, we can sort Rust types into three categories: “Yep!”, “Nope!”, and “Avoid”.</p><h4>Yep!</h4><p>This is the category for Rust types that JavaScript (via wasm-bindgen) understands well.</p><p>We’ll start with <strong>Rust’s simple copy types</strong>:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*O6rLEzmrbFj-upbn6mcYwQ.png"></figure><p>Two items surprised me here. First, 64-bit integers require extra work on the JavaScript side. Specifically, they require the use of JavaScript’s <a href="https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/BigInt">BigInt</a> class. Second, JavaScript does not support 128-bit integers. The 128-bit integers are “Nopes”.</p><p>Turning now to <strong>String-related and vector-related types</strong>:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*vcxo-fSLtpFUkKg-fDy5XA.png"></figure><p>These super useful types use heap-allocated memory. Because Rust and JavaScript manage memory differently, each language makes its own copy of the data. I thought I might avoid this allocation by passing a &amp;mut [u8] (mutable slice of bytes) from JavaScript to Rust. That didn’t work. <a href="https://stackoverflow.com/questions/78634475/does-wasm-bindgen-copy-mut-u8-zero-times-or-twice/78634853#78634853'">Instead of zero copies or one, it copied twice</a>.</p><p>Next, in Rust we love our <strong>Option and Result types</strong>. I’m happy to report that they are “Yeps”.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*3Rl4O5CL2uGOY1t1tI78Zw.png"></figure><p>A Rust Some(3) becomes a JavaScript 3, and a Rust None becomes a JavaScript null. In other words, wasm-bindgen converts Rust's type-safe null handling to JavaScript's old-fashioned approach. In both cases, null/None is handled idiomatically within each language.</p><p>Rust Result behaves similarly to Option. A Rust Ok(3) becomes a JavaScript 3, and a Rust Err("Some error message") becomes a JavaScript exception that can be caught with try/catch. Note that the value inside the Rust Err is restricted to types that implement the Into&lt;JsValue&gt; trait. Using String generally works well.</p><p>Finally, let’s look at <strong>struct, enum, and JSValue</strong>, our last set of “Yeps”:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*jnD6ZfHuaAA0OqFccI8yDw.png"></figure><p>Excitingly, JavaScript can construct and call methods on your Rust structs. To enable this, you need to mark the struct and any JavaScript-accessible methods with #[wasm_bindgen].</p><p>For example, suppose you want to avoid passing a giant string from JavaScript to Rust. You could define a Rust struct that processes a series of strings incrementally. JavaScript could construct the struct, feed it chunks from a file, and then ask for the result.</p><p>JavaScript’s handling of Rust enums is less exciting. It can only handle enums without associated data (C-like enums) and treats their values as integers.</p><p>In the middle of the excitement spectrum, you can pass opaque JavaScript values to Rust as JsValue. Rust can then dynamically inspect the value to determine its subtype or—if applicable—call its methods.</p><p>That ends the “Yeps”. Time to look at the “Nopes”.</p><h4>Nope!</h4><p>This is the category for Rust types that JavaScript (via wasm-bindgen) doesn’t handle.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1NaiZwmeUdidKfQf78HP6A.png"></figure><p>Not being able to pass, for example, &amp;u8 by reference is fine because you can just use u8, which is likely more efficient anyway.</p><p>Not being able to return a string slice (&amp;str) or a regular slice (&amp;[u8]) is somewhat annoying. To avoid lifetime issues, you must instead return an owned type like String or Vec&lt;u8&gt;.</p><p>You can’t accept a mutable String reference (&amp;mut String). However, you can accept a String by value, mutate it, and then return the modified String.</p><p>How do we workaround the “Nopes”? In place of fixed-length arrays, tuples, and 128-bit integers, use vectors (Vec&lt;T&gt;) or structs.</p><p>Rust has sets and maps. JavaScript has sets and maps. The wasm-bindgen library, however, will not automatically convert between them. So, how can you pass, for example, a HashSet from Rust to JavaScript? Wrap it in your own Rust struct and define needed methods. Then, mark the struct and those methods with #[wasm-bindgen].</p><p>And now our third category.</p><h4>Avoid</h4><p>This is the category for Rust types that JavaScript (via wasm-bindgen) allows but that you shouldn’t use.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*JyXlkXGoEeugehm9tvN2UQ.png"></figure><p>Avoid using usize and isize because most people will assume they are 64-bit integers, but in WebAssembly (WASM), they are 32-bit integers. Instead, use u32, i32, u64, or i64.</p><p>In Rust, char is a special u32 that can contain only valid Unicode scalar values. JavaScript, in contrast, treats a char as a string. It checks for Unicode validity but does not enforce that the string has a length of one. If you need to pass a char from JavaScript into Rust, it's better to use the String type and then check the length on the Rust side.</p><h3>Rule 5: Change functions to use supported types. Change files to generic BufRead.</h3><p>With our knowledge of wasm-bindgen supported types, we can fixup the functions we wish to make available to JavaScript. We left Rule 3’s example with a function like this:</p><pre>#[wasm_bindgen]<br>pub fn good_turing(file_name: &amp;str) -&gt; Result&lt;(u32, u32), io::Error&gt; {<br>    let reader = BufReader::new(File::open(file_name)?);<br>    // ...<br>}</pre><p>We, now, change the function by removing #[wasm_bindgen] pub. We also change the function to read from a generic reader rather than a file name. Using BufRead allows for more flexibility, enabling the function to accept different types of input streams, such as in-memory data or files.</p><pre>fn good_turing&lt;R: BufRead&gt;(reader: R) -&gt; Result&lt;(u32, u32), io::Error&gt; {<br>  // delete: let reader = BufReader::new(File::open(file_name)?);<br>  // ...<br>}</pre><p>JavaScript can’t see this function, so we create a wrapper function that calls it. For example:</p><pre>#[wasm_bindgen]<br>pub fn good_turing_byte_slice(data: &amp;[u8]) -&gt; Result&lt;Vec&lt;u32&gt;, String&gt; {<br>    let reader = BufReader::new(data);<br>    match good_turing(reader) {<br>        Ok((prediction, actual)) =&gt; Ok(vec![prediction, actual]),<br>        Err(e) =&gt; Err(format!("Error processing data: {e}")),<br>    }<br>}</pre><p>This wrapper function takes as input a byte slice (&amp;[u8]), something JavaScript can pass. The function turns the byte slice into a reader and calls the inner good_turing. The inner function returns a Result&lt;(u32, u32), io::Error&gt;. The wrapper function translates this result into Result&lt;Vec&lt;u32&gt;, String&gt;, a type that JavaScript will accept.</p><p>In general, I’m only willing to make minor changes to functions that will run both natively and in WASM in the Browser. For example, here I’m willing to change the function to work on a generic reader rather than a file name. When JavaScript compatibility requires major, non-idiomatic changes, I create a wrapper function.</p><p>In the example, after making these changes, the main code now compiles. The original test, however, does not yet compile. Fixing tests is the topic of Rule 6.</p><h3>Rule 6: Adapt tests, skipping those that don’t apply.</h3><p>Rule 3 advocated marking every regular test (#[test]) to also be a WASM-in-the-Browser test (#[wasm_bindgen_test]). However, not all tests from native Rust can be run in a WebAssembly environment, due to WASM’s limitations in accessing system resources like files.</p><p>In our example, Rule 3 gives us test code that does not compile:</p><pre>#[cfg(test)]<br>mod tests {<br>    use super::*;<br>    use wasm_bindgen_test::wasm_bindgen_test;<br>    wasm_bindgen_test::wasm_bindgen_test_configure!(run_in_browser);<br><br>    #[test]<br>    #[wasm_bindgen_test]<br>    fn test_process_file() {<br>        let (prediction, actual) = good_turing("./pg100.txt").unwrap();<br>        assert_eq!(prediction, 10223);<br>        assert_eq!(actual, 7967);<br>    }<br>}</pre><p>This test code fails because our updated good_turing function expects a generic reader rather than a file name. We can fix the test by creating a reader from the sample file:</p><pre>    use std::fs::File;<br><br>    #[test]<br>    fn test_process_file() {<br>        let reader = BufReader::new(File::open("pg100.txt").unwrap());<br>        let (prediction, actual) = good_turing(reader).unwrap();<br>        assert_eq!(prediction, 10223);<br>        assert_eq!(actual, 7967);<br>    }</pre><p>This is a fine native test. Unfortunately, we can’t run it as a WASM-in-the-Browser test because it uses a file reader — something WASM doesn’t support.</p><p>The solution is to create an additional test:</p><pre>    #[test]<br>    #[wasm_bindgen_test]<br>    fn test_good_turing_byte_slice() {<br>        let data = include_bytes!("../pg100.txt");<br>        let result = good_turing_byte_slice(data).unwrap();<br>        assert_eq!(result, vec![10223, 7967]);<br>    }</pre><p>At compile time, this test uses the macro include_bytes! to turn a file into a WASM-compatible byte slice. The good_turing_byte_slice function turns the byte slice into a reader and calls good_turing. (The include_bytes macro is <a href="https://doc.rust-lang.org/std/macro.include_bytes.html">part of the Rust standard library</a> and, therefore, available to tests.)</p><p>Note that the additional test is both a regular test and a WASM-in-the-Browser test. As much as possible, we want our tests to be both.</p><p>In my range-set-blaze project, I was able to mark almost all tests as both regular and WASM in the Browser. One exception: a test used a Criterion benchmarking function. Criterion doesn’t run in WASM in the Browser, so I marked that test regular only (#[test]).</p><p>With both our main code (Rule 5) and our test code (Rule 6) fixed, can we actually run our tests? Not necessarily, we may need to find JavaScript friendly dependences.</p><blockquote>Aside: If you are on Windows and run WASM-in-the-Browser tests, you may see “ERROR tiny_http] Error accepting new client: A blocking operation was interrupted by a call to WSACancelBlockingCall. (os error 10004)” This is not related to your tests. You may ignore it.</blockquote><h3>Rule 7: Change to JavaScript-friendly dependencies, if necessary. Run tests.</h3><h4>Dependencies</h4><p>The sample project will now compile. With my range-set-blaze project, however, fixing my code and tests was not enough. I also needed to fix several dependencies. Specifically, I needed to add this to my Cargo.toml:</p><pre>[target.'cfg(all(target_arch = "wasm32", target_os = "unknown"))'.dev-dependencies]<br>getrandom = { version = "0.2", features = ["js"] }<br>web-time = "1.1.0"</pre><p>These two dependences enable random numbers and provide an alternative time library. By default, WASM in the Browser has no access to random numbers or time. Both the dependences wrap JavaScript functions making them accessible to and idiomatic for Rust.</p><p><em>Aside: For more information on using </em><em>cfg expressions in </em><em>Cargo.toml, see my article: </em><a href="https://medium.com/towards-data-science/nine-rust-cargo-toml-wats-and-wat-nots-1e5e02e41648"><em>Nine Rust Cargo.toml Wats and Wat Nots</em></a><em>: Master Cargo.toml formatting rules and avoid frustration | </em>Towards Data Science (medium.com)<em>.</em></p><p>Look for other such JavaScript-wrapping libraries in <a href="https://crates.io/categories/wasm">WebAssembly — Categories — crates.io</a>. Popular crates that I haven’t tried but look interesting include:</p><ul><li><a href="https://crates.io/crates/reqwest">reqwest</a>— features=["wasm"]— HTTP network access</li><li><a href="https://crates.io/crates/plotters">plotters</a> — Plotting — includes a <a href="https://github.com/plotters-rs/plotters-wasm-demo">demo</a> that controls the HTML canvas object from Rust</li><li><a href="https://crates.io/crates/gloo">gloo</a> — Toolkit of JavaScript wrappers</li></ul><p>Also see Rule 7 in <a href="https://towardsdatascience.com/nine-rules-for-running-rust-on-wasm-wasi-550cd14c252a">the previous article</a> — about WASM WASI — for more about fixing dependency issues. In the next article in this series — about no_std and embedded — we’ll go deeper into more strategies for fixing dependencies.</p><h4>Run Tests</h4><p>With our dependencies fixed, we can finally run our tests, both regular and WASM in the Browser:</p><pre>cargo test<br>cargo test --target wasm32-unknown-unknown</pre><p>Recall that behind the scenes, our call to cargo test --target wasm32-unknown-unknown:</p><ul><li>Looks in .cargo/config.toml and sees wasm-bindgen-test-runner (Rule 3).</li><li>Calls wasm-bindgen-test-runner.</li><li>Uses Chromedriver to run our tests in Chrome for Testing. (Rule 2, be sure Chrome for Testing and Chromedriver are on your path).</li></ul><p>With our tests working, we’re now ready to call our Rust code from a web page.</p><h3>Rule 8: Connect your web page to your functions.</h3><p>To call your Rust functions from a web page you must first package your Rust library for the web. We installed wasm-pack in Rule 2. Now, we run it:</p><pre>wasm-pack build --target web</pre><p>This compiles your project and creates a pkg output directory that JavaScript understands.</p><h4>Example</h4><p>In Rule 1, we created an index.html file that didn’t call Rust. Let’s change it now so that it does call Rust. Here is an example of such an index.html followed by a description of the changes of interest.</p><pre>&lt;!DOCTYPE html&gt;<br>&lt;html lang="en"&gt;<br>&lt;head&gt;<br>    &lt;meta charset="UTF-8"&gt;<br>    &lt;meta name="viewport" content="width=device-width, initial-scale=1.0"&gt;<br>    &lt;title&gt;Good-Turing Estimation&lt;/title&gt;<br>&lt;/head&gt;<br>&lt;body&gt;<br>    &lt;h1&gt;Good-Turing Estimation&lt;/h1&gt;<br>    &lt;input type="file" id="fileInput" /&gt;<br>    &lt;p id="lineCount"&gt;&lt;/p&gt;<br><br>    &lt;script type="module"&gt;<br>        import init, { good_turing_byte_slice } from './pkg/good_turing.js'; // These files are generated by `wasm-pack build --target web`<br>        const output = document.getElementById('lineCount');<br>        document.getElementById('fileInput').addEventListener('change', (event) =&gt; {<br>            const file = event.target.files[0];<br>            if (!file) { output.innerHTML = ''; return } // No file selected<br>            const reader = new FileReader();<br>            // When the file is fully read<br>            reader.onload = async (e) =&gt; {<br>                await init(); // Ensure 'good_turing_byte_slice' is ready<br>                // View the memory buffer as a Uint8Array<br>                const u8array = new Uint8Array(e.target.result);<br>                try { // Actually run the WASM<br>                    const [prediction, actual] = good_turing_byte_slice(u8array);<br>                    output.innerHTML =<br>                        `Prediction (words that appear exactly once on even lines): ${prediction.toLocaleString()}&lt;br&gt;` +<br>                        `Actual distinct words that appear only on odd lines: ${actual.toLocaleString()}`;<br>                } catch (err) { // Or output an error<br>                    output.innerHTML = `Error: ${err}`;<br>                }<br>            };<br>            // Now start to read the file as memory buffer<br>            reader.readAsArrayBuffer(file);<br>        });<br>    &lt;/script&gt;<br>&lt;/body&gt;<br>&lt;/html&gt;</pre><p>Let’s go through the changes of interest.</p><ul><li>The line below imports two functions into JavaScript from the module file pkg/good_turing.js, which we created using wasm-pack. The default function, init, initializes our Rust-generated WebAssembly (WASM) module. The second function, good_turing_byte_slice, is explicitly imported by including its name in curly brackets.</li></ul><pre>import init, { good_turing_byte_slice } from './pkg/good_turing.js';</pre><ul><li>Create a new FileReader object, do some setup, and then read the file as an array of bytes.</li></ul><pre>const reader = new FileReader();<br>// ... some setup code ...<br>// Now start to read the file as bytes.<br>reader.readAsArrayBuffer(file);</pre><ul><li>Here is how we setup code that will run after the file is fully read:</li></ul><pre>reader.onload = async (e) =&gt; {<br>//...<br>};</pre><ul><li>This line ensures the WASM module is initialized. The first time it’s called, the module is initialized. On subsequent calls, it does nothing because the module is already ready.</li></ul><pre>await init(); // Ensure 'good_turing_byte_slice' is ready</pre><ul><li>Extract the byte array from the read file.</li></ul><pre>// View the memory buffer as a Uint8Array<br>const u8array = new Uint8Array(e.target.result);</pre><ul><li>Call the Rust-generated WASM function.</li></ul><pre>const [prediction, actual] = good_turing_byte_slice(u8array);</pre><blockquote>Aside: Here good_turing_byte_slice is a regular (synchronous) function. If you want, however, you can mark it async on the Rust side and then call it with await on the JavaScript side. If your Rust processing is slow, this can keep your web page more lively.</blockquote><ul><li>Display the result.</li></ul><pre>output.innerHTML =<br>    `Prediction (words that appear exactly once on even lines): ${prediction.toLocaleString()}&lt;br&gt;` +<br>    `Actual distinct words that appear only on odd lines: ${actual.toLocaleString()}`;</pre><ul><li>If there is an error, display the error message.</li></ul><pre>try { // Actually run the WASM<br>    // ...<br>} catch (err) { // Or output an error<br>    output.innerHTML = `Error: ${err}`;<br>}</pre><p>The <a href="https://github.com/CarlKCarlK/rustconf24-good-turing">final code</a> of the sample project is on GitHub, including a <a href="https://github.com/CarlKCarlK/rustconf24-good-turing/blob/main/README.md">README.md</a> that explains what it is doing. Click <a href="https://carlkcarlk.github.io/rustconf24-good-turing/">this link</a> for a live demo.</p><h4>range-set-blaze</h4><p>I ported range-set-blaze to WASM at a user’s request so that they could use it inside their own project. The <a href="https://github.com/CarlKCarlK/range-set-blaze">range-set-blaze</a> project is typically used as a library in other projects. In other words, you normally wouldn’t expect range-set-blaze to be the centerpiece of a web page. Nevertheless, I did make a small demo page. You can <a href="https://carlkcarlk.github.io/range-set-blaze/wasm-demo">browse it</a> or <a href="https://github.com/CarlKCarlK/range-set-blaze/blob/gh-pages/docs/wasm-demo/index.html">inspect its index.html</a>. The page shows how range-set-blaze can turn a list of integers into a sorted list of disjoint ranges.</p><blockquote>Aside: <strong>Host Your WASM-in-the-Browser Project on GitHub for Free</strong><br>1. In your project, create a docs folder.<br>2. Do wasm-pack build --target web.<br>3. Copy (don’t just move) index.html and pkg into docs.<br>4. Delete the .gitignore file in docs/pkg.<br>5. Check the project into GitHub.<br>6. Go to the project on GitHub. Then go to “Settings”, “Pages”.<br>7. Set the branch (in my case main) and the folder to docs. Save.<br>8. The URL will be based on your account and project names, for example, <a href="https://carlkcarlk.github.io/rustconf24-good-turing/">https://carlkcarlk.github.io/rustconf24-good-turing/</a><br>9. To update, repeat steps 2 through 5 (inclusive).</blockquote><h3>Rule 9: Add wasm-pack to your CI (continuous integration) tests.</h3><p>Your project is now compiling to WASM in the Browser, passing tests, and showcased on a web page. Are you done? Not quite. Because, as I said in the first article:</p><blockquote><em>If it’s not in CI, it doesn’t exist.</em></blockquote><p>Recall that continuous integration (CI) is a system that can automatically run your tests every time you update your code, ensuring that your code continues to work as expected. In my case, GitHub hosts my project. Here’s the configuration I added to .github/workflows/ci.yml to test my project on WASM in the browser:</p><pre>  test_wasm_unknown_unknown:<br>    name: Test WASM unknown unknown<br>    runs-on: ubuntu-latest<br>    steps:<br>      - name: Checkout<br>        uses: actions/checkout@v4<br>      - name: Set up Rust<br>        uses: dtolnay/rust-toolchain@master<br>        with:<br>          toolchain: stable<br>          target: wasm32-unknown-unknown<br>      - name: Install wasm-pack<br>        run: |<br>          curl https://rustwasm.github.io/wasm-pack/installer/init.sh -sSf | sh<br>      - name: Run WASM tests with Chrome<br>        run: |<br>          rustup target add wasm32-unknown-unknown<br>          wasm-pack test --chrome --headless</pre><p>By integrating WASM in the Browser into CI, I can confidently add new code to my project. CI will automatically test that all my code continues to support WASM in the browser in the future.</p><p>So, there you have it — nine rules for porting your Rust code to WASM in the Browser. Here is what surprised me:</p><p><strong>The Bad:</strong></p><ul><li>It’s hard to set up testing for WASM in the Browser. Specifically, Chrome for Testing and Chromedriver are hard to install and manage.</li><li>WASM in the Browser violates Rust’s saying “If it compiles, it works”. If you use an unsupported feature — for example, direct file access — the compiler won’t catch the error. Instead, you will fail at runtime.</li><li>Passing strings and byte vectors creates two copies of your data, one on the JavaScript side and one on the Rust side.</li></ul><p><strong>The Good:</strong></p><ul><li>WASM in the Browser is useful and fun.</li><li>You can mark your regular tests to also run in WASM in the Browser. Just mark your tests with both attributes:</li></ul><pre>#[test]<br>#[wasm_bindgen_test]</pre><ul><li>You can run on WASM in the Browser without needing to port to no_std. Nevertheless, WASM in the Browser is useful as a steppingstone toward running on embedded/no_std.</li></ul><p>Stay tuned! In the next article, I’ll show you how to port your Rust code to run in an embedded environment via no_std. This allows your code to run in small devices which I find very cool.</p><blockquote>Interested in future articles? Please <a href="https://medium.com/@carlmkadie">follow me on Medium</a>. I write about Rust and Python, scientific programming, machine learning, and statistics. I tend to write about one article per month.</blockquote><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=8228353649d1" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/nine-rules-for-running-rust-in-the-browser-8228353649d1">Nine Rules for Running Rust in the Browser</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-18378 | WebAssembly Binaryen 1.38.26 Wasm wasm/wasm-s-parser.c makeBlock null pointer dereference (Issue 1900)]]></title>
<description><![CDATA[A vulnerability was found in WebAssembly Binaryen 1.38.26 and classified as problematic. Affected by this issue is the function SExpressionWasmBuilder::makeBlock of the file wasm/wasm-s-parser.c of the component Wasm Handler. The manipulation leads to null pointer dereference.

This vulnerability...]]></description>
<link>https://tsecurity.de/de/2367163/sicherheitsluecken/cve-2020-18378-webassembly-binaryen-13826-wasm-wasmwasm-s-parserc-makeblock-null-pointer-dereference-issue-1900/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2367163/sicherheitsluecken/cve-2020-18378-webassembly-binaryen-13826-wasm-wasmwasm-s-parserc-makeblock-null-pointer-dereference-issue-1900/</guid>
<pubDate>Fri, 04 Oct 2024 00:50:27 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.webassembly:binaryen">WebAssembly Binaryen 1.38.26</a> and classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. Affected by this issue is the function <code>SExpressionWasmBuilder::makeBlock</code> of the file <em>wasm/wasm-s-parser.c</em> of the component <em>Wasm Handler</em>. The manipulation leads to null pointer dereference.

This vulnerability is handled as <a href="https://vuldb.com/?source_cve.237686">CVE-2020-18378</a>. The attack can only be done within the local network. There is no exploit available.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nine Rules for Running Rust on WASM WASI]]></title>
<description><![CDATA[Practical Lessons from Porting range-set-blaze to this Container-Like EnvironmentRust Running on a Container-Like Environment — Source: https://openai.com/dall-e-2/. All other figures from the author.Do you want your Rust code to run everywhere — from large servers to web pages, robots, and even ...]]></description>
<link>https://tsecurity.de/de/2356940/ai-nachrichten/nine-rules-for-running-rust-on-wasm-wasi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2356940/ai-nachrichten/nine-rules-for-running-rust-on-wasm-wasi/</guid>
<pubDate>Sat, 28 Sep 2024 07:04:25 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Practical Lessons from Porting range-set-blaze to this Container-Like Environment</h4><figure><img alt="An AI-generated picture of a crab on a square metal can labeled “WASM WASI”" src="https://cdn-images-1.medium.com/max/1024/1*wufrom42nQEGeKOpr1rCdg.png"><figcaption>Rust Running on a Container-Like Environment — Source: <a href="https://openai.com/dall-e-2/">https://openai.com/dall-e-2/</a>. All other figures from the author.</figcaption></figure><p>Do you want your Rust code to run everywhere — from large servers to web pages, robots, and even watches? In this first of three articles, I’ll detail the steps to make that happen.</p><p>Running Rust in constrained environments presents challenges. Your code may not have access to a complete operating system such as Linux, Windows, or macOS. You may have limited (or no) access to files, networks, time, random numbers, and even memory. We’ll explore workarounds and solutions.</p><p>This first article focuses on running code on “WASM WASI”, a container-like environment. We’ll see that WASM WASI may (or may not) be useful in its own right. However, it is valuable as a first step toward running Rust in browsers or embedded systems.</p><p>Porting code to run on WASM WASI requires many steps and choices. Navigating these choices can be time consuming. Missing a step can lead to failure. We’ll reduce this complication by offering nine rules, which we’ll explore in detail:</p><ol><li>Prepare for disappointment: WASM WASI is easy, but — for now — mostly useless — except as a steppingstone.</li><li>Understand Rust targets.</li><li>Install the wasm32-wasip1 target and WASMTIME, then create “Hello, WebAssembly!”.</li><li>Understand conditional compilation.</li><li>Run regular tests but with the WASM WASI target.</li><li>Understand Cargo features.</li><li>Change the things you can: dependency issues by choosing Cargo features, 64-bit/32-bit issues.</li><li>Accept that you cannot change everything: Networking, Tokio, Rayon, etc.</li><li>Add WASM WASI to your CI (continuous integration) tests.</li></ol><blockquote>Aside: These articles are based on a three-hour workshop that I presented at <a href="https://rustconf.com/programs/#755">RustConf24</a> in Montreal. Thanks to the participants of that workshop. A special thanks, also, to the volunteers from the Seattle Rust Meetup who helped test this material. These articles replace <a href="https://medium.com/towards-data-science/nine-rules-for-running-rust-on-the-web-and-on-embedded-94462ef249a2">an article I wrote last year</a> with updated information.</blockquote><p>Before we look at the rules one by one, let’s define our terms.</p><ul><li><strong>Native:</strong> Your home OS (Linux, Windows, macOS)</li><li><strong>Standard library (std)</strong>: Provides Rust’s core functionality — Vec, String, file input/output, networking, time.</li><li><strong>WASM</strong>: WebAssembly (WASM) is a binary instruction format that runs in most browsers (and beyond).</li><li><strong>WASI</strong>: WebAssembly System Interface (WASI) allows outside-the-browser WASM to access file I/O, networking (not yet), and time handling.</li><li><strong>no_std</strong>: Instructs a Rust program not to use the full standard library, making it suitable for small, embedded devices or highly resource-constrained environments.</li><li><strong>alloc</strong>: Provides heap memory allocation capabilities (Vec, String, etc.) in no_std environments, essential for dynamically managing memory.</li></ul><p>With these terms in mind, we can visualize the environments we want our code to run in as a Venn diagram of progressively tighter constraints. This article details how to move from native to WASM WASI. The second article tells how to then move to WASM in the Browser. The final article will cover running Rust in no_std environments, both with and without alloc, ideal for embedded systems.</p><figure><img alt="A diagram shows concentric circles representing Rust environments from most to least constrained: Native (std for Linux, Windows, MacOS), WASM WASI, WASM in Browser, no_std with alloc, and no_std without alloc." src="https://cdn-images-1.medium.com/max/898/1*infEhwykY8rpF-Z9X9E9Zw.png"></figure><p>Based on my experience with <a href="https://github.com/CarlKCarlK/range-set-blaze">range-set-blaze</a>, a data structure project, here are the decisions I recommend, described one at a time. To avoid wishy-washiness, I’ll express them as rules.</p><h3>Rule 1: Prepare for disappointment: WASM WASI is easy, but — for now — mostly useless — except as a steppingstone.</h3><p>In 2019, Docker co-creator Solomon Hykes <a href="https://x.com/solomonstre/status/1111004913222324225">tweeted</a>:</p><blockquote>If WASM+WASI existed in 2008, we wouldn’t have needed to created Docker. That’s how important it is. Webassembly on the server is the future of computing. A standardized system interface was the missing link. Let’s hope WASI is up to the task.</blockquote><p>Today, if you follow technology news, you’ll see optimistic headlines like these:</p><figure><img alt="A collage of headlines about WebAssembly System Interface (WASI). The first headline from Forbes reads “WebAssembly Is Finally Usable, Almost.” A YouTube video thumbnail shows “WASI Will Change .NET Forever! Run WebAssembly Outside The Browser!” with James Montemagno. The bottom headline says “Unexpectedly Useful: A Real World Use Case For WebAssembly System Interface (WASI).”" src="https://cdn-images-1.medium.com/max/712/1*rZBBQscFbU6lpiBXGksoQQ.png"></figure><p>If WASM WASI were truly ready and useful, everyone would already be using it. The fact that we keep seeing these headlines suggests it’s not yet ready. In other words, they wouldn’t need to keep insisting that WASM WASI is ready if it really were.</p><p>As of WASI Preview 1, here is how things stand: You can access some file operations, environment variables, and have access to time and random number generation. However, there is no support for networking.</p><p>WASM WASI <em>might</em> be useful for certain AWS Lambda-style web services, but even that’s uncertain. Because wouldn’t you prefer to compile your Rust code natively and run twice as fast at half the cost compared to WASM WASI?</p><p>Maybe WASM WASI is useful for plug ins and extensions. In genomics, I have a Rust extension for Python, which I compile for 25 different combinations (5 versions of Python across 5 OS targets). Even with that, I don’t cover every possible OS and chip family. Could I replace those OS targets with WASM WASI? No, it would be too slow. Could I add WASM WASI as a sixth “catch-all” target? Maybe, but if I really need portability, I’m already required to support Python and should just use Python.</p><p>So, what is WASM WASI good for? Right now, its main value lies in being a step toward running code in the browser or on embedded systems.</p><h3>Rule 2: Understand Rust targets.</h3><p>In Rule 1, I mentioned “OS targets” in passing. Let’s look deeper into Rust targets — essential information not just for WASM WASI, but also for general Rust development.</p><p>On my Windows machine, I can compile a Rust project to run on Linux or macOS. Similarly, from a Linux machine, I can compile a Rust project to target Windows or macOS. Here are the commands I use to add and check the Linux target to a Windows machine:</p><pre>rustup target add x86_64-unknown-linux-gnu<br>cargo check --target x86_64-unknown-linux-gnu</pre><blockquote>Aside: While cargo check verifies that the code compiles, building a fully functional executable requires additional tools. To cross-compile from Windows to Linux (GNU), you’ll also need to install the Linux GNU C/C++ compiler and the corresponding toolchain. That can be tricky. Fortunately, for the WASM targets we care about, the required toolchain is easy to install.</blockquote><p>To see all the targets that Rust supports, use the command:</p><pre>rustc --print target-list</pre><p>It will list over 200 targets including x86_64-unknown-linux-gnu, wasm32-wasip1, and wasm32-unknown-unknown.</p><p>Target names contain up to four parts: CPU family, vendor, OS, and environment (for example, GNU vs LVMM):</p><figure><img alt="A diagram explaining the components of the target triple x86_64-unknown-linux-gnu. It breaks down as follows: CPU architecture (64-bit x86), Vendor (unspecified, hence ‘unknown’), Operating system (Linux), and Environment (GNU C library)." src="https://cdn-images-1.medium.com/max/1024/1*UsCLYGXhPIaPrnr7OveB0w.png"><figcaption>Target Name parts — figure from author</figcaption></figure><p>Now that we understand something of targets, let’s go ahead and install the one we need for WASM WASI.</p><h3>Rule 3: Install the wasm32-wasip1 target and WASMTIME, then create “Hello, WebAssembly!”.</h3><p>To run our Rust code on WASM outside of a browser, we need to target wasm32-wasip1 (32-bit WebAssembly with WASI Preview 1). We’ll also install WASMTIME, a runtime that allows us to run WebAssembly modules outside of the browser, using WASI.</p><pre>rustup target add wasm32-wasip1<br>cargo install wasmtime-cli</pre><p>To test our setup, let’s create a new “Hello, WebAssembly!” Rust project using cargo new. This initializes a new Rust package:</p><pre>cargo new hello_wasi<br>cd hello_wasi</pre><p>Edit src/main.rs to read:</p><pre>fn main() {<br>    #[cfg(not(target_arch = "wasm32"))]<br>    println!("Hello, world!");<br>    #[cfg(target_arch = "wasm32")]<br>    println!("Hello, WebAssembly!");<br>}</pre><blockquote>Aside: We’ll look deeper into the #[cfg(...)] attribute, which enables conditional compilation, in Rule 4.</blockquote><p>Now, run the project with cargo run, and you should see Hello, world! printed to the console.</p><p>Next, create a .cargo/config.toml file, which specifies how Rust should run and test the project when targeting WASM WASI.</p><pre>[target.wasm32-wasip1]<br>runner = "wasmtime run --dir ."</pre><blockquote>Aside: This .cargo/config.toml file is different from the main Cargo.toml file, which defines your project’s dependencies and metadata.</blockquote><p>Now, if you say:</p><pre>cargo run --target wasm32-wasip1</pre><p>You should see Hello, WebAssembly!. Congratulations! You’ve just successfully run some Rust code in the container-like WASM WASI environment.</p><h3>Rule 4: Understand conditional compilation.</h3><p>Now, let’s investigate #[cfg(...)]—an essential tool for conditionally compiling code in Rust. In Rule 3, we saw:</p><pre>fn main() {<br>    #[cfg(not(target_arch = "wasm32"))]<br>    println!("Hello, world!");<br>    #[cfg(target_arch = "wasm32")]<br>    println!("Hello, WebAssembly!");<br>}</pre><p>The #[cfg(...)] lines tell the Rust compiler to include or exclude certain code items based on specific conditions. A “code item” refers to a unit of code such as a function, statement, or expression.</p><p>With #[cfg(…)] lines, you can conditionally compile your code. In other words, you can create different versions of your code for different situations. For example, when compiling for the wasm32 target, the compiler ignores the #[cfg(not(target_arch = "wasm32"))] block and only includes the following:</p><pre>fn main() {<br>    println!("Hello, WebAssembly!");<br>}</pre><p>You specify conditions via expressions, for example, target_arch = "wasm32". Supported keys include target_os and target_arch. See the Rust Reference for <a href="https://doc.rust-lang.org/reference/conditional-compilation.html#set-configuration-options">the full list</a> of supported keys. You can also create expressions with Cargo features, which we will learn about in Rule 6.</p><p>You may combine expressions with the logical operators not, any, and all. Rust’s conditional compilation doesn’t use traditional if...then...else statements. Instead, you must use #[cfg(...)] and its negation to handle different cases:</p><pre>#[cfg(not(target_arch = "wasm32"))]<br>...<br>#[cfg(target_arch = "wasm32")]<br>...</pre><p>To conditionally compile an entire file, place #![cfg(...)] at the top of the file. (Notice the “!”). This is useful when a file is only relevant for a specific target or configuration.</p><p>You can also use cfg expressions in Cargo.toml to conditionally include dependencies. This allows you to tailor dependencies to different targets. For example, this says “depend on Criterion with Rayon when not targeting wasm32”.</p><pre>[target.'cfg(not(target_arch = "wasm32"))'.dev-dependencies]<br>criterion = { version = "0.5.1", features = ["rayon"] }</pre><blockquote>Aside: For more information on using cfg expressions in Cargo.toml, see my article: <a href="https://medium.com/towards-data-science/nine-rust-cargo-toml-wats-and-wat-nots-1e5e02e41648">Nine Rust Cargo.toml Wats and Wat Nots</a>: Master Cargo.toml formatting rules and avoid frustration | <em>Towards Data Science (medium.com)</em>.</blockquote><h3>Rule 5: Run regular tests but with the WASM WASI target.</h3><p>It’s time to try to run <em>your </em>project on WASM WASI. As described in Rule 3, create a .cargo/config.toml file for your project. It tells Cargo how to run and test your project on WASM WASI.</p><pre>[target.wasm32-wasip1]<br>runner = "wasmtime run --dir ."</pre><p>Next, <a href="https://doc.rust-lang.org/rust-by-example/testing.html">your project — like all good code — should already contain tests</a>. My range-set-blaze project includes, for example, this test:</p><pre>#[test]<br>fn insert_255u8() {<br>    let range_set_blaze = RangeSetBlaze::&lt;u8&gt;::from_iter([255]);<br>    assert!(range_set_blaze.to_string() == "255..=255");<br>}</pre><p>Let’s now attempt to run your project’s tests on WASM WASI. Use the following command:</p><pre>cargo test --target wasm32-wasip1</pre><p>If this works, you may be done — but it probably won’t work. When I try this on range-set-blaze, I get this error message that complains about using Rayon on WASM.</p><pre> error: Rayon cannot be used when targeting wasi32. Try disabling default features.<br>  --&gt; C:\Users\carlk\.cargo\registry\src\index.crates.io-6f17d22bba15001f\criterion-0.5.1\src\lib.rs:31:1<br>   |<br>31 | compile_error!("Rayon cannot be used when targeting wasi32. Try disabling default features.");</pre><p>To fix this error, we must first understand Cargo features.</p><h3>Rule 6: Understand Cargo features.</h3><p>To resolve issues like the Rayon error in Rule 5, it’s important to understand how Cargo features work.</p><p>In Cargo.toml, an optional [features] section allows you to define different configurations, or versions, of your project depending on which features are enabled or disabled. For example, here is a simplified part of the Cargo.toml file from the <a href="https://github.com/bheisler/criterion.rs/blob/master/Cargo.toml">Criterion benchmarking project</a>:</p><pre>[features]<br>default = ["rayon", "plotters", "cargo_bench_support"]<br>rayon = ["dep:rayon"]<br>plotters = ["dep:plotters"]<br>html_reports = []<br>cargo_bench_support = []<br><br>[dependencies]<br>#...<br># Optional dependencies<br>rayon = { version = "1.3", optional = true }<br>plotters = { version = "^0.3.1", optional = true, default-features = false, features = [<br>    "svg_backend",<br>    "area_series",<br>    "line_series",<br>] }</pre><p>This defines four Cargo features: rayon, plotters, html_reports, and cargo_bench_support. Since each feature can be included or excluded, these four features create 16 possible configurations of the project. Note also the special default Cargo feature.</p><p>A Cargo feature can include other Cargo features. In the example, the special default Cargo feature includes three other Cargo features — rayon, plotters, and cargo_bench_support.</p><p>A Cargo feature can include a dependency. The rayon Cargo feature above includes the rayon crate as a dependent package.</p><p>Moreover, dependent packages may have their own Cargo features. For example, the plotters Cargo feature above includes the plotters dependent package with the following Cargo features enabled: svg_backend, area_series, and line_series.</p><p>You can specify which Cargo features to enable or disable when running cargo check, cargo build, cargo run, or cargo test. For instance, if you’re working on the Criterion project and want to check only the html_reports feature without any defaults, you can run:</p><pre>cargo check --no-default-features --features html_reports</pre><p>This command tells Cargo not to include any Cargo features by default but to specifically enable the html_reports Cargo feature.</p><p>Within your Rust code, you can include/exclude code items based on enabled Cargo features. The syntax uses #cfg(…), as per Rule 4:</p><pre>#[cfg(feature = "html_reports")]<br>SOME_CODE_ITEM</pre><p>With this understanding of Cargo features, we can now attempt to fix the Rayon error we encountered when running tests on WASM WASI.</p><h3>Rule 7: Change the things you can: dependency issues by choosing Cargo features, 64-bit/32-bit issues.</h3><p>When we tried running cargo test --target wasm32-wasip1, part of the error message stated: Criterion ... Rayon cannot be used when targeting wasi32. Try disabling default features. This suggests we should disable Criterion’s rayon Cargo feature when targeting WASM WASI.</p><p>To do this, we need to make two changes in our Cargo.toml. First, we need to disable the rayon feature from Criterion in the [dev-dependencies] section. So, this starting configuration:</p><pre>[dev-dependencies]<br>criterion = { version = "0.5.1", features = ["html_reports"] }</pre><p>becomes this, where we explicitly turn off the default features for Criterion and then enable all the Cargo features except rayon.</p><pre>[dev-dependencies]<br>criterion = { version = "0.5.1", features = [<br>        "html_reports",<br>        "plotters",<br>        "cargo_bench_support"],<br>      default-features = false }</pre><p>Next, to ensure rayon is still used for non-WASM targets, we add it back in with a conditional dependency in Cargo.toml as follows:</p><pre>[target.'cfg(not(target_arch = "wasm32"))'.dev-dependencies]<br>criterion = { version = "0.5.1", features = ["rayon"] }</pre><p>In general, when targeting WASM WASI, you may need to modify your dependencies and their Cargo features to ensure compatibility. Sometimes this process is straightforward, but other times it can be challenging — or even impossible, as we’ll discuss in Rule 8.</p><blockquote>Aside: In the next article in this series — about WASM in the Browser — we’ll go deeper into strategies for fixing dependencies.</blockquote><p>After running the tests again, we move past the previous error, only to encounter a new one, which is progress!</p><pre>#[test]<br>fn test_demo_i32_len() {<br>    assert_eq!(demo_i32_len(i32::MIN..=i32::MAX), u32::MAX as usize + 1);<br>                                                  ^^^^^^^^^^^^^^^^^^^^^ attempt to compute <br>`usize::MAX + 1_usize`, which would overflow<br>}</pre><p>The compiler complains that u32::MAX as usize + 1 overflows. On 64-bit Windows the expression doesn’t overflow because usize is the same as u64 and can hold u32::MAX as usize + 1. WASM, however, is a 32-bit environment so usize is the same as u32 and the expression is one too big.</p><p>The fix here is to replace usize with u64, ensuring that the expression doesn’t overflow. More generally, the compiler won’t always catch these issues, so it’s important to review your use of usize and isize. If you’re referring to the size or index of a Rust data structure, usize is correct. However, if you’re dealing with values that exceed 32-bit limits, you should use u64 or i64.</p><blockquote>Aside: In a 32-bit environment, a Rust array, Vec, BTreeSet, etc., can only hold up to 2³²−1=4,294,967,295 elements.</blockquote><p>So, we’ve fixed the dependency issue and addressed a usize overflow. But can we fix everything? Unfortunately, the answer is no.</p><h3>Rule 8: Accept that you cannot change everything: Networking, Tokio, Rayon, etc.</h3><p>WASM WASI Preview 1 (the current version) supports file access (within a specified directory), reading environment variables, and working with time and random numbers. However, its capabilities are limited compared to what you might expect from a full operating system.</p><p>If your project requires access to networking, asynchronous tasks with Tokio, or multithreading with Rayon, Unfortunately, these features aren’t supported in Preview 1.</p><p>Fortunately, WASM WASI Preview 2 is expected to improve upon these limitations, offering more features, including better support for networking and possibly asynchronous tasks.</p><h3>Rule 9: Add WASM WASI to your CI (continuous integration) tests.</h3><p>So, your tests pass on WASM WASI, and your project runs successfully. Are you done? Not quite. Because, as I like to say:</p><blockquote>If it’s not in CI, it doesn’t exist.</blockquote><p>Continuous integration (CI) is a system that can automatically run your tests every time you update your code, ensuring that your code continues to work as expected. By adding WASM WASI to your CI, you can guarantee that future changes won’t break your project’s compatibility with the WASM WASI target.</p><p>In my case, my project is hosted on GitHub, and I use GitHub Actions as my CI system. Here’s the configuration I added to .github/workflows/ci.yml to test my project on WASM WASI:</p><pre>test_wasip1:<br>      name: Test WASI P1<br>      runs-on: ubuntu-latest<br>      steps:<br>        - name: Checkout<br>          uses: actions/checkout@v4<br>        - name: Set up Rust<br>          uses: dtolnay/rust-toolchain@master<br>          with:<br>            toolchain: stable<br>            targets: wasm32-wasip1<br>        - name: Install Wasmtime<br>          run: |<br>            curl https://wasmtime.dev/install.sh -sSf | bash<br>            echo "${HOME}/.wasmtime/bin" &gt;&gt; $GITHUB_PATH<br>        - name: Run WASI tests<br>          run: cargo test --verbose --target wasm32-wasip1</pre><p>By integrating WASM WASI into CI, I can confidently add new code to my project. CI will automatically test that all my code continues to support WASM WASI in the future.</p><p>So, there you have it — nine rules for porting your Rust code to WASM WASI. Here is what surprised me about porting to WASM WASI:</p><p><strong>The Bad:</strong></p><ul><li>Running on WASM WASI offers little utility today. It, however, holds the potential to be useful tomorrow.</li><li>In Rust, there’s a common saying: “If it compiles, it works.” Unfortunately, this doesn’t always hold true for WASM WASI. If you use an unsupported feature, like networking, the compiler won’t catch the error. Instead, it will fail at runtime. For example, this code compiles and runs on WASM WASI but always returns an error because networking isn’t supported.</li></ul><pre>use std::net::TcpStream;<br><br>fn main() {<br>    match TcpStream::connect("crates.io:80") {<br>        Ok(_) =&gt; println!("Successfully connected."),<br>        Err(e) =&gt; println!("Failed to connect: {e}"),<br>    }<br>}</pre><p><strong>The Good:</strong></p><ul><li>Running on WASM WASI is a good first step toward running your code in the browser and on embedded systems.</li><li>You can run Rust code on WASM WASI without needing to port to no_std. (Porting to no_std is the topic of the third article of this series.)</li><li>You can run standard Rust tests on WASM WASI, making it easy to verify your code.</li><li>The .cargo/config.toml file and Rust’s --target option make it incredibly straightforward to configure and run your code on different targets—including WASM WASI.</li></ul><p>Stay tuned! In the next article, I’ll show you how to port your Rust code to run on WASM in the browser — an ability I find super useful. After that, the final article will explain porting code to embedded systems, which I find incredibly cool.</p><p><em>Aside: </em>Interested in future articles? <em>Please </em><a href="https://medium.com/@carlmkadie"><em>follow me on Medium</em></a><em>. I write about Rust and Python, scientific programming, machine learning, and statistics. I tend to write about one article per month.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=550cd14c252a" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/nine-rules-for-running-rust-on-wasm-wasi-550cd14c252a">Nine Rules for Running Rust on WASM WASI</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-8385 | Mozilla Firefox up to 129.x WASM type confusion]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Mozilla Firefox up to 129.x. Affected by this vulnerability is an unknown functionality of the component WASM. The manipulation leads to type confusion.

This vulnerability is known as CVE-2024-8385. The attack can be launched remotely. There is...]]></description>
<link>https://tsecurity.de/de/2314886/sicherheitsluecken/cve-2024-8385-mozilla-firefox-up-to-129x-wasm-type-confusion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2314886/sicherheitsluecken/cve-2024-8385-mozilla-firefox-up-to-129x-wasm-type-confusion/</guid>
<pubDate>Wed, 04 Sep 2024 09:37:01 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> was found in <a href="https://vuldb.com/?product.mozilla:firefox">Mozilla Firefox up to 129.x</a>. Affected by this vulnerability is an unknown functionality of the component <em>WASM</em>. The manipulation leads to type confusion.

This vulnerability is known as <a href="https://vuldb.com/?source_cve.276391">CVE-2024-8385</a>. The attack can be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apache HTTPD Vulns, Hacking IoT Speakers, Use Cases for WASM, Slack AI Leak - ASW #297]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:12 Research by Orange Tsai into Apache HTTPD's architecture reveals several vulns, NCC Group shows techniques for hacking IoT devices with Sonos speakers, finding use cases for WebAssembly, Slack's AI leaks data, DARPA wants a futur...]]></description>
<link>https://tsecurity.de/de/2300866/it-security-video/apache-httpd-vulns-hacking-iot-speakers-use-cases-for-wasm-slack-ai-leak-asw-297/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2300866/it-security-video/apache-httpd-vulns-hacking-iot-speakers-use-cases-for-wasm-slack-ai-leak-asw-297/</guid>
<pubDate>Tue, 27 Aug 2024 16:05:00 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/p_tZ38zFVsY/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:12 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/p_tZ38zFVsY?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Research by Orange Tsai into Apache HTTPD's architecture reveals several vulns, NCC Group shows techniques for hacking IoT devices with Sonos speakers, finding use cases for WebAssembly, Slack's AI leaks data, DARPA wants a future of Rust, and more!<br />
<br />
Visit https://www.securityweekly.com/asw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/asw-297<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nine Rust Cargo.toml Wats and Wat Nots]]></title>
<description><![CDATA[Master Cargo.toml formatting rules and avoid frustrationRust Cargo Suprises — Source: https://openai.com/dall-e-2/. All other figures from the author.In JavaScript and other languages, we call a surprising or inconsistent behavior a “Wat!” [that is, a “What!?”]. For example, in JavaScript, an emp...]]></description>
<link>https://tsecurity.de/de/2244231/ai-nachrichten/nine-rust-cargotoml-wats-and-wat-nots/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2244231/ai-nachrichten/nine-rust-cargotoml-wats-and-wat-nots/</guid>
<pubDate>Thu, 25 Jul 2024 00:52:09 +0200</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Master Cargo.toml formatting rules and avoid frustration</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*RYBg6aBZmTKse_m7vbEuqQ.png"><figcaption>Rust Cargo Suprises — Source: <a href="https://openai.com/dall-e-2/">https://openai.com/dall-e-2/</a>. All other figures from the author.</figcaption></figure><p>In JavaScript and other languages, we call <a href="https://www.destroyallsoftware.com/talks/wat">a surprising or inconsistent behavior a “Wat!”</a> [that is, a “What!?”]. For example, in JavaScript, an empty array plus an empty array produces an empty string, [] + [] === "". Wat!</p><p>At the other extreme, a language sometimes behaves with surprising consistency. I’m calling that a “Wat Not”.</p><p>Rust is generally (much) more consistent than JavaScript. Some Rust-related formats, however, offer surprises. Specifically, this article looks at nine wats and wat nots in Cargo.toml.</p><p>Recall that Cargo.toml is the manifest file that defines your Rust project’s configuration and dependencies. Its format, TOML (Tom's Obvious, Minimal Language), represents nested key/value pairs and/or arrays. JSON and YAML are similar formats. Like YAML, but unlike JSON, Tom designed TOML for easy reading and writing by humans.</p><p>This journey of nine wats and wat nots will not be as entertaining as JavaScript’s quirks (thank goodness). However, if you’ve ever found Cargo.toml's format confusing, I hope this article will help you feel better about yourself. Also, and most importantly, when you learn the nine wats and wat nots, I hope you will be able to write your Cargo.toml more easily and effectively.</p><p>This article is not about “fixing” Cargo.toml. The file format is great at its main purpose: specifying the configuration and dependencies of a Rust project. Instead, the article is about understanding the format and its quirks.</p><h3>Wat 1: Dependencies vs. Profile Section Names</h3><p>You probably know how to add a [dependencies] section to your Cargo.toml. Such a section specifies release dependencies, for example:</p><pre>[dependencies]<br>serde = "1.0"</pre><p>Along the same lines, you can specify development dependencies with a [dev-dependencies] section and build dependencies with a [build-dependencies] section.</p><p>You may also need to set compiler options, for example, an optimization level and whether to include debugging information. You do that with <em>profile </em>sections for release, development, and build. Can you guess the names of these three sections? Is it [profile], [dev-profile] and [build-profile]?</p><p>No! It’s [profile.release], [profile.dev], and [profile.build]. Wat?</p><p>Would [dev-profile] be better than [profile.dev]? Would [dependencies.dev] be better than [dev-dependencies]?</p><p>I personally prefer the names with dots. (In “Wat Not 9”, we’ll see the power of dots.) I am, however, willing to just remember the dependences work one way and profiles work another.</p><h3>Wat 2: Dependency Inheritance</h3><p>You might argue that dots are fine for profiles, but hyphens are better for dependencies because [dev-dependencies] inherits from [dependencies]. In other words, the dependencies in [dependencies] are also available in [dev-dependencies]. So, does this mean that [build-dependencies] inherits from [dependencies]?</p><p>No! [build-dependencies] does not inherit from [dependencies]. Wat?</p><p>I find this Cargo.toml behavior convenient but confusing.</p><h3>Wat 3: Default Keys</h3><p>You likely know that instead of this:</p><pre>[dependencies]<br>serde = { version = "1.0" }</pre><p>you can write this:</p><pre>[dependencies]<br>serde = "1.0"</pre><p>What’s the principle here? How in general TOML do you designate one key as the default key?</p><p>You can’t! General TOML has no default keys. Wat?</p><p>Cargo TOML does special processing on the version key in the [dependencies] section. This is a Cargo-specific feature, not a general TOML feature. As far as I know, Cargo TOML offers no other default keys.</p><h3>Wat 4: Sub-Features</h3><p>With Cargo.toml [features] you can create versions of your project that differ in their dependences. Those dependences may themselves differ in their features, which we’ll call sub-features.</p><p>Here we create two versions of our project. The default version depends on getrandom with default features. The wasm version depends on getrandom with the js sub-feature:</p><pre>[features]<br>default = []<br>wasm = ["getrandom-js"]<br><br>[dependencies]<br>rand = { version = "0.8" }<br>getrandom = { version = "0.2", optional = true }<br><br>[dependencies.getrandom-js]<br>package = "getrandom"<br>version = "0.2"<br>optional = true<br>features = ["js"]</pre><p>In this example, wasm is a feature of our project that depends on dependency alias getrandom-rs which represents the version of the getrandom crate with the js sub-feature.</p><p>So, how can we give this same specification while avoiding the wordy [dependencies.getrandom-js] section?</p><p>In [features], replace getrandom-js" with "getrandom/js". We can just write:</p><pre>[features]<br>default = []<br>wasm = ["getrandom/js"]<br><br>[dependencies]<br>rand = { version = "0.8" }<br>getrandom = { version = "0.2", optional = true }</pre><p>Wat!</p><p>In general, in Cargo.toml, a feature specification such as wasm = ["getrandom/js"] can list</p><ul><li>other features</li><li>dependency aliases</li><li>dependencies</li><li>one or more dependency “slash” a sub-feature</li></ul><p>This is not standard TOML. Rather, it is a Cargo.toml-specific shorthand.</p><p>Bonus: Guess how you’d use the shorthand to say that your wasm feature should include getrandom with two sub-features: js and test-in-browser?</p><p>Answer: List the dependency twice.</p><pre>wasm = ["getrandom/js","getrandom/test-in-browser"]</pre><h3>Wat 5: Dependencies for Targets</h3><p>We’ve seen how to specify dependencies for release, debug, and build.</p><pre>[dependencies]<br>#...<br>[dev-dependencies]<br>#...<br>[build-dependencies]<br>#...</pre><p>We’ve seen how to specify dependencies for various features:</p><pre>[features]<br>default = []<br>wasm = ["getrandom/js"]</pre><p>How would you guess we specify dependences for various targets (e.g. a version of Linux, Windows, etc.)?</p><p>We prefix [dependences] with target.<em>TARGET_EXPRESSION</em>, for example:</p><pre>[target.x86_64-pc-windows-msvc.dependencies]<br>winapi = { version = "0.3.9", features = ["winuser"] }</pre><p>Which, by the rules of general TOML means we can also say:</p><pre>[target]<br>x86_64-pc-windows-msvc.dependencies={winapi = { version = "0.3.9", features = ["winuser"] }}</pre><p>Wat!</p><p>I find this prefix syntax strange, but I can’t suggest a better alternative. I do, however, wonder why features couldn’t have been handle the same way:</p><pre># not allowed<br>[feature.wasm.dependencies]<br>getrandom = { version = "0.2", features=["js"]}</pre><h3>Wat Not 6: Target cfg Expressions</h3><p>This is our first “Wat Not”, that is, it is something that surprised me with its consistency.</p><p>Instead of a concrete target such as x86_64-pc-windows-msvc, you may instead use a cfg expression in single quotes. For example,</p><pre>[target.'cfg(all(windows, target_arch = "x86_64"))'.dependencies]</pre><p>I don’t consider this a “wat!”. I think it is great.</p><p>Recall that cfg, short for “configuration", is the Rust mechanism usually used to conditionally compile code. For example, in our main.rs, we can say:</p><pre>if cfg!(target_os = "linux") {<br>    println!("This is Linux!");<br>}</pre><p>In Cargo.toml, in target expressions, pretty much the whole <a href="https://doc.rust-lang.org/reference/conditional-compilation.html">cfg mini-language</a> is supported.</p><pre>all(), any(), not()<br>target_arch<br>target_feature<br>target_os<br>target_family<br>target_env<br>target_abi<br>target_endian<br>target_pointer_width<br>target_vendor<br>target_has_atomic<br>unix<br>windows</pre><p>The only parts of the cfg mini-language not supported are (I think) that you can’t set a value with the --cfg command line argument. Also, some cfg values such as test don’t make sense.</p><h3>Wat 7: Profiles for Targets</h3><p>Recall from Wat 1 that you set compiler options with [profile.release], [profile.dev], and [profile.build]. For example:</p><pre>[profile.dev]<br>opt-level = 0</pre><p>Guess how you set compiler options for a specific target, such as Windows? Is it this?</p><pre>[target.'cfg(windows)'.profile.dev]<br>opt-level = 0</pre><p>No. Instead, you create a new file named .cargo/config.toml and add this:</p><pre>[target.'cfg(windows)']<br>rustflags = ["-C", "opt-level=0"]</pre><p>Wat!</p><p>In general, Cargo.toml only supports target.<em>TARGET_EXPRESSION</em> as the prefix of dependency section. You may not prefix a profile section. In <a href="https://doc.rust-lang.org/cargo/reference/config.html">.cargo/config.toml</a>, however, you may have [target.<em>TARGET_EXPRESSION</em>] sections. In those sections, you may set environment variables that set compiler options.</p><h3>Wat Not 8: TOML Lists</h3><p>Cargo.toml supports two syntaxes for lists:</p><ul><li>Inline Array</li><li>Table Array</li></ul><p>This example uses both:</p><pre>[package]<br>name = "cargo-wat"<br>version = "0.1.0"<br>edition = "2021"<br><br>[dependencies]<br>rand = { version = "0.8" }<br># Inline array 'features'<br>getrandom = { version = "0.2", features = ["std", "test-in-browser"] }<br><br># Table array 'bin'<br>[[bin]]<br>name = "example"<br>path = "src/bin/example.rs"<br><br>[[bin]]<br>name = "another"<br>path = "src/bin/another.rs"</pre><p>Can we change the table array to an inline array? Yes!</p><pre># Inline array 'bin'<br>bins = [<br>    { name = "example", path = "src/bin/example.rs" },<br>    { name = "another", path = "src/bin/another.rs" },<br>]<br><br>[package]<br>name = "cargo-wat"<br>version = "0.1.0"<br>edition = "2021"<br><br>[dependencies]<br>rand = { version = "0.8" }<br># Inline array 'features'<br>getrandom = { version = "0.2", features = ["std", "test-in-browser"] }</pre><p>Can we change the inline array of features into a table array?</p><p>No. Inline arrays of simple values (here, strings) cannot be represented as table arrays. However, I consider this a “wat not”, not a “wat!” because this is a limitation of general TOML, not just of Cargo.toml.</p><blockquote>Aside: YAML format, like TOML format, offers two list syntaxes. However, both of YAMLs two syntaxes <a href="https://www.yaml.info/learn/flowstyle.html">work with simple values</a>.</blockquote><h3>Wat Not 9: TOML Inlining, Sections, and Dots</h3><p>Here is a typical Cargo.toml. It mixes section syntax, such as [dependences] with inline syntax such as getrandom = {version = "0.2", features = ["std", "test-in-browser"]}.</p><pre>[package]<br>name = "cargo-wat"<br>version = "0.1.0"<br>edition = "2021"<br><br>[dependencies]<br>rand = "0.8"<br>getrandom = { version = "0.2", features = ["std", "test-in-browser"] }<br><br>[target.x86_64-pc-windows-msvc.dependencies]<br>winapi = { version = "0.3.9", features = ["winuser"] }<br><br>[[bin]]<br>name = "example"<br>path = "src/bin/example.rs"<br><br>[[bin]]<br>name = "another"<br>path = "src/bin/another.rs"</pre><p>Can we re-write it to be 100% inline? Yes.</p><pre>package = { name = "cargo-wat", version = "0.1.0", edition = "2021" }<br><br>dependencies = { rand = "0.8", getrandom = { version = "0.2", features = [<br>    "std",<br>    "test-in-browser",<br>] } }<br><br>target = { 'cfg(target_os = "windows")'.dependencies = { winapi = { version = "0.3.9", features = [<br>    "winuser",<br>] } } }<br><br>bins = [<br>    { name = "example", path = "src/bin/example.rs" },<br>    { name = "another", path = "src/bin/another.rs" },<br>]</pre><p>We can also re-write it with maximum sections:</p><pre>[package]<br>name = "cargo-wat"<br>version = "0.1.0"<br>edition = "2021"<br><br>[dependencies.rand]<br>version = "0.8"<br><br>[dependencies.getrandom]<br>version = "0.2"<br>features = ["std", "test-in-browser"]<br><br><br>[target.x86_64-pc-windows-msvc.dependencies.winapi]<br>version = "0.3.9"<br>features = ["winuser"]<br><br>[[bin]]<br>name = "example"<br>path = "src/bin/example.rs"<br><br>[[bin]]<br>name = "another"<br>path = "src/bin/another.rs"</pre><p>Finally, let’s talk about dots. In TOML, dots are used to separate keys in nested tables. For example, a.b.c is a key c in a table b in a table a. Can we re-write our example with “lots of dots”? Yes:</p><pre>package.name = "cargo-wat"<br>package.version = "0.1.0"<br>package.edition = "2021"<br>dependencies.rand = "0.8"<br>dependencies.getrandom.version = "0.2"<br>dependencies.getrandom.features = ["std", "test-in-browser"]<br>target.x86_64-pc-windows-msvc.dependencies.winapi.version = "0.3.9"<br>target.x86_64-pc-windows-msvc.dependencies.winapi.features = ["winuser"]<br>bins = [<br>    { name = "example", path = "src/bin/example.rs" },<br>    { name = "another", path = "src/bin/another.rs" },<br>]</pre><p>I appreciate TOML’s flexibility with respect to sections, inlining, and dots. I count that flexibility as a “wat not”. You may find all the choices it offers confusing. I, however, like that Cargo.toml lets us use TOML’s full power.</p><h3>Conclusion</h3><p>Cargo.toml is an essential tool in the Rust ecosystem, offering a balance of simplicity and flexibility that caters to both beginners and seasoned developers. Through the nine wats and wat nots we’ve explored, we’ve seen how this configuration file can sometimes surprise with its idiosyncrasies and yet impress with its consistency and power.</p><p>Understanding these quirks can save you from potential frustrations and enable you to leverage Cargo.toml to its fullest. From managing dependencies and profiles to handling target-specific configurations and features, the insights gained here will help you write more efficient and effective Cargo.toml files.</p><p>In essence, while Cargo.toml may have its peculiarities, these characteristics are often rooted in practical design choices that prioritize functionality and readability. Embrace these quirks, and you’ll find that Cargo.toml not only meets your project’s needs but also enhances your Rust development experience.</p><p><em>Please </em><a href="https://medium.com/@carlmkadie"><em>follow Carl on Medium</em></a><em>. I write on scientific programming in Rust and Python, machine learning, and statistics. I tend to write about one article per month.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=1e5e02e41648" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/nine-rust-cargo-toml-wats-and-wat-nots-1e5e02e41648">Nine Rust Cargo.toml Wats and Wat Nots</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anzeige: Warum WebAssembly für die Edge Runtime ideal ist]]></title>
<description><![CDATA[Mit WebAssembly (Wasm) ist die Edge-Computing-Lösung FastEdge von Gcore eine ideale Wahl für leistungskritische Aufgaben und Anwendungen. Was zeichnet Wasm aus? (Wasm, Softwareentwicklung)]]></description>
<link>https://tsecurity.de/de/2221344/it-nachrichten/anzeige-warum-webassembly-fuer-die-edge-runtime-ideal-ist/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2221344/it-nachrichten/anzeige-warum-webassembly-fuer-die-edge-runtime-ideal-ist/</guid>
<pubDate>Wed, 10 Jul 2024 09:02:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit WebAssembly (Wasm) ist die Edge-Computing-Lösung FastEdge von Gcore eine ideale Wahl für leistungskritische Aufgaben und Anwendungen. Was zeichnet Wasm aus? (<a href="https://www.golem.de/specials/webassembly/">Wasm</a>, <a href="https://www.golem.de/specials/softwareentwicklung/">Softwareentwicklung</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=186754&amp;page=1&amp;ts=1720594802" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Esfahbod: State of Text Rendering 2024]]></title>
<description><![CDATA[On his blog, Behdad Esfahbod has published a lengthy and detailed look at the state of open-source text rendering.  It looks at the libraries available, application support, future directions, and gives a summary analysis of the ecosystem. 


In broad strokes, OpenType added support for color fon...]]></description>
<link>https://tsecurity.de/de/2219076/linux-tipps/esfahbod-state-of-text-rendering-2024/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2219076/linux-tipps/esfahbod-state-of-text-rendering-2024/</guid>
<pubDate>Tue, 09 Jul 2024 06:01:09 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[On his blog, Behdad Esfahbod has <a href="https://behdad.org/text2024/">published</a> a lengthy and detailed look at the state of open-source text rendering.  It looks at the libraries available, application support, future directions, and gives a summary analysis of the ecosystem. 

<blockquote class="bq">
In broad strokes, OpenType added support for <i>color fonts</i>, <i>variable fonts</i>, and the <i>Universal Shaping Engine</i>. The Free &amp; Open Source stack supports all of these advances at the lower level, but application UI support has been slower to arrive. The Open Source text stack also gained enormous market-share when Android and Google Chrome fully embraced it.
<p>
Looking forward, there is a <i>Rust</i> migration of the text stack underway, which will unify font compilation and consumption under a safe programming language. <i>Incremental Font Transfer</i> will enable streaming fonts to web browsers. And my proposed <i>Wasm-fonts</i> will enable more expressive fonts.
</p></blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[Migrate to innovate: How to be AI-ready and secure]]></title>
<description><![CDATA[In an era defined by rapid change and unprecedented challenges, agility has emerged as a business imperative. In this dynamic environment, the true catalyst for business agility is the transformative power of artificial intelligence (AI). Gartner says CIOs Must Prioritize Their AI Ambition and AI...]]></description>
<link>https://tsecurity.de/de/2198460/it-security-nachrichten/migrate-to-innovate-how-to-be-ai-ready-and-secure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2198460/it-security-nachrichten/migrate-to-innovate-how-to-be-ai-ready-and-secure/</guid>
<pubDate>Tue, 25 Jun 2024 21:20:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In an era defined by rapid change and unprecedented challenges, agility has emerged as a business imperative. In this dynamic environment, the true catalyst for business agility is the transformative power of artificial intelligence (AI). Gartner says CIOs Must Prioritize Their AI Ambition and AI-Ready Scenarios for Next 12-24 Months<sup>1</sup>, and 90% of companies will use AI in their workforce by 2025<sup>2</sup>.</p>



<p>However, amidst the pursuit of AI-driven innovation, enterprises often find themselves tethered to pressing priorities of today. From navigating economic downturns, managing cloud sprawl and tool proliferation, and fortifying defenses against cyber threats and the demands of the present seem to eclipse the pursuit of future innovation.</p>



<p><strong>Enter Azure: Microsoft Azure meets customers where they are in their cloud journey.</strong></p>



<p>Migration to Azure balances the need to innovate with AI and accelerate business growth, while taking care of pressing present-day priorities. Let’s explore!</p>



<p><strong>Migrate to be AI-ready</strong></p>



<p>While customers today are attempting to run AI workloads in various locations, our research and customer conversations indicate that customers are best able to realize their AI ambitions at scale by migrating to the cloud. Here are some common principles that apply:</p>



<ol>
<li><strong>Colocate to eliminate siloes:</strong> Over the years, organizations have shared how they have inevitably accumulated vast amounts of data and applications sitting in disparate locations, which often leads to sub-optimal performance and reduced agility to scale with business needs.</li>
</ol>



<p>AI is only as good as the data it can use to model and train, the apps it can infuse into, and the infrastructure that powers AI processes.</p>



<p>By colocating databases, applications, infrastructure, and AI services in the cloud, organizations can get optimized performance that can’t be achieved in distributed environments or on-premises. This performance is exponentially higher with our purpose-built supercomputing infrastructure, which powers leading AI models, such as ChatGPT. Azure offers up to 2x faster throughput compared to competitors for our AI infrastructure<sup>3</sup>.</p>



<p>With the foundation laid in the cloud, organizations can then seamlessly integrate, infuse, and build AI and Copilots into their operations, enhancing productivity for both employees and customers! A recent IDC study highlighted that a company realizes 3.5x return on average for every $1 invested in AI<sup>4</sup>.</p>



<p>2. <strong>Embrace Responsible AI (RAI):</strong> As AI innovation accelerates, the question of responsible implementation looms large for every customer we talk to. Microsoft has been at the forefront of AI innovation and responsible AI practices for many years. From early research to present initiatives, responsible AI principles such as fairness, inclusivity, privacy, transparency, and accountability have continued to be a core focus. Compliance is integral to responsible AI, and Microsoft leads the industry with over 100 compliance certifications.</p>



<p><strong>Securing workloads across your migration journey</strong></p>



<p>The increasing speed, scale, and sophistication of today’s cyberattacks call for a new response to security. Today, infrastructure is code and organizations wish to unleash developer creativity to build compelling and compliant applications. In fact, more than 95% of cloud breaches can be traced back to preventable mistakes, misconfigurations, mismanagement, open-source code vulnerabilities, and exposed sensitive data in storage buckets<sup>5</sup>.</p>



<p>Microsoft’s Secure Future Initiative keeps security at the heart of it all. Microsoft Azure is a comprehensive code to multicloud security platform: from foundational security to cloud-native workload protection. Microsoft has more than 10,000 dedicated security professionals and ​analyzes 65 trillion global signals daily. Let’s delve into 2 ways to secure your migration journey:</p>



<ul>
<li><strong>Unified platform for code to multicloud protection:</strong> A key solution that is part of this platform is Microsoft Defender for Cloud. It comprehensively secures across your migration journey for on premises, hybrid and multicloud environments. It proactively discovers risk and drift, remediates security vulnerabilities, and prioritizes critical threats to help reduce threat mitigation time by up to 50%<sup>6</sup>.</li>
</ul>



<p>Organizations also need to shift left. By integrating with developer tools such as GitHub, you can spot security issues before they hit your production environment</p>



<ul>
<li><strong>Protect at the speed and scale of AI:</strong> The combination of generative AI with our end-to-end security solutions is proving to be a force multiplier for empowering security teams everywhere and delivering security for all.</li>
</ul>



<p>Microsoft Copilot for Security is the first of its kind generative AI security product to help defend organizations at machine speed and scale. It combines the most advanced GPT4 model from OpenAI with a Microsoft-developed, security-specific model.</p>



<p>And the impact of Copilot is real! In a recent study to measure the productivity impact for “new in career” analysts, participants using Security Copilot demonstrated 44 percent more accurate responses and were 26 percent faster across all tasks<sup>7</sup>.</p>



<p><strong>Get started with Azure</strong></p>



<p>Want to <strong>learn more</strong> about how you can migrate to Azure? Here are some quick resources to explore:</p>



<ul>
<li>Read our latest <a href="https://tei.forrester.com/go/Microsoft/AzureAI-Readiness/" target="_blank" rel="sponsored">Forrester Total Economic Impact report</a> on migration for AI-readiness</li>



<li>Read our <a href="https://info.microsoft.com/ww-landing-how-to-migrate-to-innovate-be-ai-ready.html?lcid=en-us" target="_blank" rel="sponsored">eBook</a> and watch our <a href="https://youtu.be/90Z4AIpjPEk?si=WMgGaFb9Q1xCdym8" target="_blank" rel="sponsored">video</a> that provides prescriptive steps on migrating to Azure to be AI-ready</li>



<li>Connect with us to move forward confidently with guidance, support, and offers through <a href="https://aka.ms/AMMOffering" target="_blank" rel="sponsored">Azure Migrate and Modernize</a>.</li>
</ul>



<ol>
<li><a href="https://www.gartner.com/en/newsroom/press-releases/2023-11-06-gartner-says-ai-ambition-and-ai-ready-scenarios-must-be-a-top-priority-for-cios-for-next-12-24-months" target="_blank" rel="sponsored">Gartner Says AI Ambition and AI-Ready Scenarios Must Be a Top Priority for CIOs for Next 12-24 Months, November 2023</a></li>



<li><a href="https://www.businesswire.com/news/home/20191029005144/en/IDC-FutureScape-Outlines-the-Impact-Digital-Supremacy-Will-Have-on-Enterprise-Transformation-and-the-IT-Industry" target="_blank" rel="sponsored">Gartner</a> We Shape AI, AI Shapes Us: 2023 IT Symposium/Xpo Keynote Insights</li>



<li><a href="https://azure.microsoft.com/en-us/blog/azure-empowers-easytouse-highperformance-and-hyperscale-model-training-using-deepspeed/" target="_blank" rel="sponsored">Performance benchmark for 1-Trillion parameter model with </a><a href="https://azure.microsoft.com/en-us/blog/azure-empowers-easytouse-highperformance-and-hyperscale-model-training-using-deepspeed/" rel="sponsored">DeepSpeed</a></li>



<li><a href="https://news.microsoft.com/source/wp-content/uploads/2023/11/US51315823-IG-ADA.pdf" target="_blank" rel="sponsored">IDC, The Business Opportunity of AI November 2023</a></li>



<li><a href="https://www.gartner.com/smarterwithgartner/is-the-cloud-secure" target="_blank" rel="sponsored">Is The Cloud Secure (gartner.com)</a></li>



<li>The Total Economic Impact ™ Of Microsoft Defender for Cloud” February 2021, commissioned by Microsoft</li>



<li><a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4648700" target="_blank" rel="sponsored">Microsoft Security Copilot randomized controlled trial conducted by Microsoft Office of the Chief Economist</a>, November 2023.</li>
</ol>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Entwicklertagebuch MyLife #4: Azure wir kommen!]]></title>
<description><![CDATA[Eine praktische Lösung für ein Problem zu finden, welche man sich selbst beschert hat, bietet ein gewisses Genugtun. Im letzten Artikel dieser Reihe zu MyLife.NET sprachen wir über die Einschränkungen, welche Blazor.WASM mit sich bringt. Nun habe wir mit GitHub und Azure eine Lösung hierfür parat...]]></description>
<link>https://tsecurity.de/de/2188094/it-nachrichten/entwicklertagebuch-mylife-4-azure-wir-kommen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2188094/it-nachrichten/entwicklertagebuch-mylife-4-azure-wir-kommen/</guid>
<pubDate>Wed, 19 Jun 2024 09:35:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img src="https://www.drwindows.de/news/wp-content/uploads/2025/05/MyLife.Net-SoMe-720x360.png" class="attachment-single-thumb size-single-thumb wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.drwindows.de/news/wp-content/uploads/2025/05/MyLife.Net-SoMe-720x360.png 720w, https://www.drwindows.de/news/wp-content/uploads/2025/05/MyLife.Net-SoMe-300x150.png 300w, https://www.drwindows.de/news/wp-content/uploads/2025/05/MyLife.Net-SoMe-1024x512.png 1024w, https://www.drwindows.de/news/wp-content/uploads/2025/05/MyLife.Net-SoMe-768x384.png 768w, https://www.drwindows.de/news/wp-content/uploads/2025/05/MyLife.Net-SoMe-643x322.png 643w, https://www.drwindows.de/news/wp-content/uploads/2025/05/MyLife.Net-SoMe.png 1280w" sizes="(max-width: 720px) 100vw, 720px"></div>Eine praktische Lösung für ein Problem zu finden, welche man sich selbst beschert hat, bietet ein gewisses Genugtun. Im letzten Artikel dieser Reihe zu MyLife.NET sprachen wir über die Einschränkungen, welche Blazor.WASM mit sich bringt. Nun habe wir mit GitHub und Azure eine Lösung hierfür parat. Was für ein Entwicklerträumchen. Für alle, denen diese Artikelreihe […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Vulnerability Summary for the Week of May 13, 2024]]></title>
<description><![CDATA[High Vulnerabilities



PrimaryVendor -- Product
Description
Published
CVSS Score
Source & Patch Info




8theme--XStore Core 
Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.
2024-05-17
9.8
CVE-2...]]></description>
<link>https://tsecurity.de/de/2141243/it-security-nachrichten/vulnerability-summary-for-the-week-of-may-13-2024/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2141243/it-security-nachrichten/vulnerability-summary-for-the-week-of-may-13-2024/</guid>
<pubDate>Fri, 10 May 2024 09:09:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<h2>High Vulnerabilities</h2>
<table summary="High Vulnerabilities" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th scope="col" role="columnheader" data-tablesaw-priority="persist">Primary<br>Vendor -- Product</th>
<th scope="col" role="columnheader">Description</th>
<th scope="col" role="columnheader">Published</th>
<th scope="col" role="columnheader">CVSS Score</th>
<th scope="col" role="columnheader">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>8theme--XStore Core<br> </td>
<td>Improper Privilege Management vulnerability in 8theme XStore Core allows Privilege Escalation.This issue affects XStore Core: from n/a through 5.3.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33552&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33552" target="_blank">CVE-2024-33552</a><br><a href="https://patchstack.com/database/vulnerability/et-core-plugin/wordpress-xstore-core-plugin-5-3-5-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>8theme--XStore Core<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33556&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33556" target="_blank">CVE-2024-33556</a><br><a href="https://patchstack.com/database/vulnerability/et-core-plugin/wordpress-xstore-core-plugin-5-3-5-limited-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>AA-Team--WZone<br> </td>
<td>Improper Privilege Management vulnerability in AA-Team WZone allows Privilege Escalation.This issue affects WZone: from n/a through 14.0.10.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33549&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33549" target="_blank">CVE-2024-33549</a><br><a href="https://patchstack.com/database/vulnerability/woozone/wordpress-wzone-plugin-14-0-10-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ABB--RobotWare 6<br> </td>
<td>An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible, or execute arbitrary code.  The vulnerability could potentially be exploited to perform unauthorized actions by an attacker. This vulnerability arises under specific condition when specially crafted message is processed by the system. Below are reported vulnerabilities in the Robot Ware versions. * IRC5- RobotWare 6 &lt; 6.15.06 except 6.10.10, and 6.13.07 * OmniCore- RobotWare 7 &lt; 7.14</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1913&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1913" target="_blank">CVE-2024-1913</a><br><a href="https://search.abb.com/library/Download.aspx?DocumentID=SI20330&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch" target="_blank">cybersecurity@ch.abb.com</a></td>
</tr>
<tr>
<td>AROX SOLUTION--School ERP Pro+Responsive<br> </td>
<td>Vulnerability in School ERP Pro+Responsive 1.0 that allows SQL injection through the '/SchoolERP/office_admin/' index in the parameters groups_id, examname, classes_id, es_voucherid, es_class, etc. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the database.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4824&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4824" target="_blank">CVE-2024-4824</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-school-erp-proresponsive-arox-solution" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Abdul Hakeem--Build App Online<br> </td>
<td>Improper Privilege Management vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51479&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51479" target="_blank">CVE-2023-51479</a><br><a href="https://patchstack.com/database/vulnerability/build-app-online/wordpress-build-app-online-plugin-1-0-19-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30284&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30284" target="_blank">CVE-2024-30284</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30310&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30310" target="_blank">CVE-2024-30310</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34094&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34094" target="_blank">CVE-2024-34094</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34095&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34095" target="_blank">CVE-2024-34095</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34096&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34096" target="_blank">CVE-2024-34096</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34097&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34097" target="_blank">CVE-2024-34097</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34098&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34098" target="_blank">CVE-2024-34098</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34099&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34099" target="_blank">CVE-2024-34099</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34100&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34100" target="_blank">CVE-2024-34100</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Aero Desktop<br> </td>
<td>Adobe Aero Desktop versions 23.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30275&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30275" target="_blank">CVE-2024-30275</a><br><a href="https://helpx.adobe.com/security/products/aero/apsb24-33.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30288&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30288" target="_blank">CVE-2024-30288</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30289&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30289" target="_blank">CVE-2024-30289</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30290&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30290" target="_blank">CVE-2024-30290</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30291&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30291" target="_blank">CVE-2024-30291</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30292&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30292" target="_blank">CVE-2024-30292</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30282&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30282" target="_blank">CVE-2024-30282</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30293&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30293" target="_blank">CVE-2024-30293</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30294&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30294" target="_blank">CVE-2024-30294</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30295&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30295" target="_blank">CVE-2024-30295</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30296&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30296" target="_blank">CVE-2024-30296</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30297&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30297" target="_blank">CVE-2024-30297</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Dreamweaver Desktop<br> </td>
<td>Dreamweaver Desktop versions 21.3 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does require user interaction.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30314&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">9.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30314" target="_blank">CVE-2024-30314</a><br><a href="https://helpx.adobe.com/security/products/dreamweaver/apsb24-39.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Illustrator<br> </td>
<td>Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20791&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20791" target="_blank">CVE-2024-20791</a><br><a href="https://helpx.adobe.com/security/products/illustrator/apsb24-30.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Illustrator<br> </td>
<td>Illustrator versions 28.4, 27.9.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20792&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20792" target="_blank">CVE-2024-20792</a><br><a href="https://helpx.adobe.com/security/products/illustrator/apsb24-30.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Substance3D - Painter<br> </td>
<td>Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30274&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30274" target="_blank">CVE-2024-30274</a><br><a href="https://helpx.adobe.com/security/products/substance3d_painter/apsb24-31.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Substance3D - Painter<br> </td>
<td>Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30307&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30307" target="_blank">CVE-2024-30307</a><br><a href="https://helpx.adobe.com/security/products/substance3d_painter/apsb24-31.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Agentejo--Cockpit CMS<br> </td>
<td>A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in '/media/api' parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4825&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4825" target="_blank">CVE-2024-4825</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-upload-file-dangerous-type-vulnerability-cockpit-cms" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Apache Friends--XAMPP<br> </td>
<td>Uncontrolled resource consumption vulnerability in XAMPP Windows, versions 7.3.2 and earlier. This vulnerability exists when XAMPP attempts to process many incomplete HTTP requests, resulting in resource consumption and system crashes.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5055&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5055" target="_blank">CVE-2024-5055</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/vulnerability-uncontrolled-resource-consumption-xampp" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Asaancart--Simple PHP Shopping Cart<br> </td>
<td>SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacker to retrieve all the information stored in the database by sending a specially crafted SQL query, due to the lack of proper sanitisation of the category_id parameter in the category.php file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4826&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4826" target="_blank">CVE-2024-4826</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-simple-php-shopping-cart" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Astoundify--Simple Registration for WooCommerce<br> </td>
<td>Improper Privilege Management vulnerability in Astoundify Simple Registration for WooCommerce allows Privilege Escalation.This issue affects Simple Registration for WooCommerce: from n/a through 1.5.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32511&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32511" target="_blank">CVE-2024-32511</a><br><a href="https://patchstack.com/database/vulnerability/woocommerce-simple-registration/wordpress-simple-registration-for-woocommerce-plugin-1-5-6-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Averta--Phlox Portfolio<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Averta Phlox Portfolio allows PHP Local File Inclusion.This issue affects Phlox Portfolio: from n/a through 2.3.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38399&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38399" target="_blank">CVE-2023-38399</a><br><a href="https://patchstack.com/database/vulnerability/auxin-portfolio/wordpress-phlox-portfolio-plugin-2-3-1-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Averta--Phlox Shop<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Averta Phlox Shop allows PHP Local File Inclusion.This issue affects Phlox Shop: from n/a through 2.0.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-39163&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-39163" target="_blank">CVE-2023-39163</a><br><a href="https://patchstack.com/database/vulnerability/auxin-shop/wordpress-phlox-shop-plugin-2-0-0-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>B&amp;R Industrial Automation--Automation Studio<br> </td>
<td>Improper DLL loading algorithms in B&amp;R Automation Studio may allow an authenticated local attacker to execute code with elevated privileges. This issue affects Automation Studio versions before 4.12.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2021-22280&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-22280" target="_blank">CVE-2021-22280</a><br><a href="https://www.br-automation.com/fileadmin/2021-10_DLL_Hijacking_Vulnerability_in_Automation_Studio-7dd34511.pdf" target="_blank">cybersecurity@ch.abb.com</a></td>
</tr>
<tr>
<td>B&amp;R Industrial Automation--Scene Viewer<br> </td>
<td>An authenticated local attacker who successfully exploited this vulnerability could insert and run arbitrary code using legitimate B&amp;R software's. An Uncontrolled Search Path Element vulnerability in B&amp;R Industrial Automation Scene Viewer, B&amp;R Industrial  Automation Runtime, B&amp;R Industrial Automation mapp Vision, B&amp;R Industrial Automation mapp View, B&amp;R Industrial Automation mapp Cockpit, B&amp;R Industrial Automation mapp Safety, B&amp;R Industrial Automation VC4 could allow an authenticated local attacker to execute malicious code by placing specially crafted files in the loading search path. This issue affects Scene Viewer: before 4.4.0; Automation Runtime: before J4.93; mapp Vision: before 5.26.1; mapp View: before 5.24.2; mapp Cockpit: before 5.24.2; mapp Safety: before 5.24.2; VC4: before 4.73.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2637&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2637" target="_blank">CVE-2024-2637</a><br><a href="https://www.br-automation.com/fileadmin/SA24P005_Insecure_Loading_of_Code-c7d9e49c.pdf" target="_blank">cybersecurity@ch.abb.com</a></td>
</tr>
<tr>
<td>BoldGrid--Total Upkeep<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep allows Relative Path Traversal.This issue affects Total Upkeep: from n/a through 1.15.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24869&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24869" target="_blank">CVE-2024-24869</a><br><a href="https://patchstack.com/database/vulnerability/boldgrid-backup/wordpress-total-upkeep-plugin-1-15-8-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Booking Ultra Pro--Booking Ultra Pro<br> </td>
<td>Improper Privilege Management vulnerability in Booking Ultra Pro allows Privilege Escalation.This issue affects Booking Ultra Pro: from n/a through 1.1.12.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32960&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32960" target="_blank">CVE-2024-32960</a><br><a href="https://patchstack.com/database/vulnerability/booking-ultra-pro/wordpress-booking-ultra-pro-plugin-1-1-12-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--ConvertPlus<br> </td>
<td>The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from the 'settings_encoded' attribute of the 'smile_modal' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4838&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4838" target="_blank">CVE-2024-4838</a><br><a href="https://www.convertplug.com/plus/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/16f5a104-dce0-4249-91b9-67f99cce16d3?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--Spectra Pro<br> </td>
<td>The Spectra Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.5. This is due to the plugin allowing lower-privileged users to create registration forms and set the default role to administrator This makes it possible for authenticated attackers, with author-level access and above, to create administrator-level accounts.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3828&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3828" target="_blank">CVE-2024-3828</a><br><a href="https://wpspectra.com/whats-new/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e23e7d66-4b57-4feb-bf77-46238bc6ce7c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--Ultimate Addons for Beaver Builder<br> </td>
<td>Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Privilege Escalation.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.14.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51398&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51398" target="_blank">CVE-2023-51398</a><br><a href="https://patchstack.com/database/vulnerability/bb-ultimate-addon/wordpress-ultimate-addons-for-beaver-builder-premium-plugin-1-35-14-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--Ultimate Addons for Elementor<br> </td>
<td>Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a through 1.36.20.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-50890&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-50890" target="_blank">CVE-2023-50890</a><br><a href="https://patchstack.com/database/vulnerability/ultimate-elementor/wordpress-ultimate-addons-for-elementor-plugin-1-36-20-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--Ultimate Addons for WPBakery Page Builder<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for WPBakery Page Builder allows PHP Local File Inclusion.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through 3.19.14.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46205&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46205" target="_blank">CVE-2023-46205</a><br><a href="https://patchstack.com/database/vulnerability/ultimate_vc_addons/wordpress-ultimate-addons-for-wpbakery-page-builder-plugin-3-19-14-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Breakdance--Breakdance<br> </td>
<td>The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 via post meta data. This is due to the plugin storing custom data in metadata without an underscore prefix. This makes it possible for lower privileged users, such as contributors, to edit this data via UI. As a result they can escalate their privileges or execute arbitrary code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4605&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4605" target="_blank">CVE-2024-4605</a><br><a href="https://breakdance.com/breakdance-1-7-2-now-available-security-update/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/095b23b7-71ab-41eb-b666-73df2e1a7eb4?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>By Averta--Shortcodes and extra features for Phlox theme<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in By Averta Shortcodes and extra features for Phlox theme allows PHP Local File Inclusion.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.14.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37888&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37888" target="_blank">CVE-2023-37888</a><br><a href="https://patchstack.com/database/vulnerability/auxin-elements/wordpress-phlox-core-elements-plugin-2-14-0-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server when `register_argc_argv` option of PHP is `On`. In `cmd_realtime.php` line 119, the `$poller_id` used as part of the command execution is sourced from `$_SERVER['argv']`, which can be controlled by URL when `register_argc_argv` option of PHP is `On`. And this option is `On` by default in many environments such as the main PHP Docker image for PHP. Commit 53e8014d1f082034e0646edc6286cde3800c683d contains a patch for the issue, but this commit was reverted in commit 99633903cad0de5ace636249de16f77e57a3c8fc.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29895&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29895" target="_blank">CVE-2024-29895</a><br><a href="https://github.com/Cacti/cacti/blob/501712998589763d411a68d35e3cda98fd9cfd18/cmd_realtime.php#L119" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/commit/53e8014d1f082034e0646edc6286cde3800c683d" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/commit/99633903cad0de5ace636249de16f77e57a3c8fc" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-cr28-x256-xf5m" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server. The vulnerability is located within the `import_package()` function defined into the `/lib/import.php` script. The function blindly trusts the filename and file content provided within the XML data, and writes such files into the Cacti base path (or even outside, since path traversal sequences are not filtered). This can be exploited to write or overwrite arbitrary files on the web server, leading to execution of arbitrary PHP code or other security impacts. Version 1.2.27 contains a patch for this issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25641&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25641" target="_blank">CVE-2024-25641</a><br><a href="https://github.com/Cacti/cacti/commit/eff35b0ff26cc27c82d7880469ed6d5e3bef6210" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-7cmj-g5qc-pj88" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verifying password, it calls `compat_password_verify`. In `compat_password_verify`, `password_verify` is called if there is it, else use `md5`. `password_verify` and `password_hash` are supported on PHP &lt; 5.5.0, following PHP manual. The vulnerability is in `compat_password_verify`. Md5-hashed user input is compared with correct password in database by `$md5 == $hash`. It is a loose comparison, not `===`. It is a type juggling vulnerability. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34340&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34340" target="_blank">CVE-2024-34340</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-37x7-mfjv-mm7m" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_new_graphs_sql` function of `api_automation.php` allows authenticated users to exploit these SQL injection vulnerabilities to perform privilege escalation and remote code execution. In `api_automation.php` line 856, the `get_request_var('filter')` is being concatenated into the SQL statement without any sanitization. In `api_automation.php` line 717, The filter of `'filter'` is `FILTER_DEFAULT`, which means there is no filter for it. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31445&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31445" target="_blank">CVE-2024-31445</a><br><a href="https://github.com/Cacti/cacti/blob/501712998589763d411a68d35e3cda98fd9cfd18/lib/api_automation.php#L717" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/blob/501712998589763d411a68d35e3cda98fd9cfd18/lib/api_automation.php#L856" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/commit/fd93c6e47651958b77c3bbe6a01fff695f81e886" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-vjph-r677-6pcc" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.php` file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. There is a file inclusion issue with the `api_plugin_hook()` function in the `lib/plugin.php` file, which reads the plugin_hooks and plugin_config tables in database. The read data is directly used to concatenate the file path which is used for file inclusion. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31459&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31459" target="_blank">CVE-2024-31459</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-cx8g-hvq8-p2rv" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-gj3f-p326-gh8r" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server and served to users who access a particular page. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27082&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27082" target="_blank">CVE-2024-27082</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-j868-7vjp-rp9h" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cerberus FTP Enterprise--Cerberus FTP Enterprise<br> </td>
<td>Denial of Service (DoS) vulnerability for Cerberus Enterprise 8.0.10.3 web administration. The vulnerability exists when the web server, default port 10001, attempts to process a large number of incomplete HTTP requests.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5052&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5052" target="_blank">CVE-2024-5052</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/resource-consumption-vulnerability-cerberus-ftp-enterprise" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Cisco--Cisco ConfD<br> </td>
<td>A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerability is due to improper authorization enforcement when specific CLI commands are used. An attacker could exploit this vulnerability by executing an affected CLI command with crafted arguments. A successful exploit could allow the attacker to read or write arbitrary files on the underlying operating system with the privileges of the root user.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20326&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20326" target="_blank">CVE-2024-20326</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnfd-rwpesc-ZAOufyx8" target="_blank">ykramarz@cisco.com</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-rwpesc-qrQGnh3f" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco ConfD<br> </td>
<td>A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This vulnerability is due to improper authorization enforcement when specific CLI commands are used. An attacker could exploit this vulnerability by executing an affected CLI command with crafted arguments. A successful exploit could allow the attacker to read or write arbitrary files on the underlying operating system with the privileges of the root user.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20389&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20389" target="_blank">CVE-2024-20389</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnfd-rwpesc-ZAOufyx8" target="_blank">ykramarz@cisco.com</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-rwpesc-qrQGnh3f" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Network Services Orchestrator<br> </td>
<td>A vulnerability in the Tail-f High Availability Cluster Communications (HCC) function pack of Cisco Crosswork Network Services Orchestrator (NSO) could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability exists because a user-controlled search path is used to locate executable files. An attacker could exploit this vulnerability by configuring the application in a way that causes a malicious file to be executed. A successful exploit could allow the attacker to execute arbitrary code on an affected device as the root user. To exploit this vulnerability, the attacker would need valid credentials on an affected device.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20366&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20366" target="_blank">CVE-2024-20366</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-hcc-priv-esc-OWBWCs5D" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>CodeRevolution--Demo My WordPress<br> </td>
<td>Improper Privilege Management vulnerability in CodeRevolution Demo My WordPress allows Privilege Escalation.This issue affects Demo My WordPress: from n/a through 1.0.9.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31290&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31290" target="_blank">CVE-2024-31290</a><br><a href="https://patchstack.com/database/vulnerability/demo-my-wordpress/wordpress-demo-my-wordpress-plugin-1-0-9-1-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Contemporary Control System--BASrouter BACnet BASRT-B<br> </td>
<td>A vulnerability classified as critical was found in Contemporary Control System BASrouter BACnet BASRT-B 2.7.2. This vulnerability affects unknown code of the component Application Protocol Data Unit. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263890 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4791&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4791" target="_blank">CVE-2024-4791</a><br><a href="https://github.com/isZzzz/BASRT-B_BACnet_Router_Document/blob/main/BASER-B_APDU.pcapng" target="_blank">cna@vuldb.com</a><br><a href="https://github.com/isZzzz/BASRT-B_BACnet_Router_Document/blob/main/BASRT-B_2_CVE_apply.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263890" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263890" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.323630" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Copymatic--Copymatic AI Content Writer &amp; Generator<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Copymatic Copymatic - AI Content Writer &amp; Generator.This issue affects Copymatic - AI Content Writer &amp; Generator: from n/a through 1.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31351&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31351" target="_blank">CVE-2024-31351</a><br><a href="https://patchstack.com/database/vulnerability/copymatic/wordpress-copymatic-plugin-1-6-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Crocoblock--JetEngine<br> </td>
<td>Improper Privilege Management vulnerability in Crocoblock JetEngine allows Privilege Escalation.This issue affects JetEngine: from n/a through 3.2.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-48757&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-48757" target="_blank">CVE-2023-48757</a><br><a href="https://patchstack.com/database/vulnerability/jet-engine/wordpress-jetengine-plugin-3-2-4-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Crocoblock--JetFormBuilder<br> </td>
<td>Improper Privilege Management vulnerability in Crocoblock JetFormBuilder allows Privilege Escalation.This issue affects JetFormBuilder: from n/a through 3.0.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37866&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37866" target="_blank">CVE-2023-37866</a><br><a href="https://patchstack.com/database/vulnerability/jetformbuilder/wordpress-jetformbuilder-plugin-3-0-8-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CyberPower--CyberPower PowerPanel Enterprise<br> </td>
<td>An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can access the PDNU REST APIs, which may result in compromise of the application.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32735&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32735" target="_blank">CVE-2024-32735</a><br><a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank">vulnreport@tenable.com</a><br><a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>CyberPower--CyberPower PowerPanel Enterprise<br> </td>
<td>A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32736&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32736" target="_blank">CVE-2024-32736</a><br><a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank">vulnreport@tenable.com</a><br><a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>CyberPower--CyberPower PowerPanel Enterprise<br> </td>
<td>A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_contract_result" function within MCUDBHelper.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32737&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32737" target="_blank">CVE-2024-32737</a><br><a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank">vulnreport@tenable.com</a><br><a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>CyberPower--CyberPower PowerPanel Enterprise<br> </td>
<td>A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_lean" function within MCUDBHelper.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32738&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32738" target="_blank">CVE-2024-32738</a><br><a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank">vulnreport@tenable.com</a><br><a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>CyberPower--CyberPower PowerPanel Enterprise<br> </td>
<td>A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_verbose" function within MCUDBHelper.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32739&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32739" target="_blank">CVE-2024-32739</a><br><a href="https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&amp;fileSubType=FileReleaseNote" target="_blank">vulnreport@tenable.com</a><br><a href="https://www.tenable.com/security/research/tra-2024-14" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an attacker gaining access to the testing or production server.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32047&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32047" target="_blank">CVE-2024-32047</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>Hard-coded credentials are used by the  CyberPower PowerPanel platform to authenticate to the database, other services, and the cloud. This could result in an attacker gaining access to services with the privileges of a Powerpanel business application.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32053&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32053" target="_blank">CVE-2024-32053</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>CyberPower PowerPanel business application code contains a hard-coded JWT signing key. This could result in an attacker forging JWT tokens to bypass authentication.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33625&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33625" target="_blank">CVE-2024-33625</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>CyberPower PowerPanel business application code contains a hard-coded set of authentication credentials. This could result in an attacker bypassing authentication and gaining administrator privileges.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34025&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34025" target="_blank">CVE-2024-34025</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>An attacker with certain MQTT permissions can create malicious messages to all CyberPower PowerPanel devices. This could result in an attacker injecting SQL syntax, writing arbitrary files to the system, and executing remote code.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31856&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31856" target="_blank">CVE-2024-31856</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>A specially crafted Zip file containing path traversal characters can be imported to the CyberPower PowerPanel server, which allows file writing to the server outside the intended scope, and could allow an attacker to achieve remote code execution.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33615&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33615" target="_blank">CVE-2024-33615</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. This can allow an attacker to impersonate any client in the system and send malicious data.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31410&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31410" target="_blank">CVE-2024-31410</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CycloneDX--cyclonedx-javascript-library<br> </td>
<td>The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34345&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34345" target="_blank">CVE-2024-34345</a><br><a href="https://github.com/CycloneDX/cyclonedx-javascript-library/commit/5e5e1e0b9422f47d2de81c7c4064b803a01e7203" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/CycloneDX/cyclonedx-javascript-library/pull/1063" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/CycloneDX/cyclonedx-javascript-library/security/advisories/GHSA-38gf-rh2w-gmj7" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Darren Cooney--Instant Images<br> </td>
<td>Improper Privilege Management vulnerability in Darren Cooney Instant Images allows Privilege Escalation.This issue affects Instant Images: from n/a through 6.1.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33569&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33569" target="_blank">CVE-2024-33569</a><br><a href="https://patchstack.com/database/vulnerability/instant-images/wordpress-instant-images-plugin-6-1-0-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Dell--CPG BIOS<br> </td>
<td>Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22429&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22429" target="_blank">CVE-2024-22429</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000221102/dsa-2024-020" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>DigiWin--EasyFlow .NET<br> </td>
<td>DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4893&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4893" target="_blank">CVE-2024-4893</a><br><a href="https://www.twcert.org.tw/en/cp-139-7801-67d07-2.html" target="_blank">twcert@cert.org.tw</a><br><a href="https://www.twcert.org.tw/tw/cp-132-7800-843f1-1.html" target="_blank">twcert@cert.org.tw</a></td>
</tr>
<tr>
<td>Elementor--Elementor Website Builder<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24934&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24934" target="_blank">CVE-2024-24934</a><br><a href="https://patchstack.com/database/vulnerability/elementor/wordpress-elementor-plugin-3-19-0-arbitrary-file-deletion-and-phar-deserialization-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>EnterpriseDB--EDB Postgres Advanced Server<br> </td>
<td>All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 may allow users using edbldr to bypass role permissions from pg_read_server_files. This could allow low privilege users to read files to which they would not otherwise have access.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4545&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4545" target="_blank">CVE-2024-4545</a><br><a href="https://www.enterprisedb.com/docs/epas/15/epas_rel_notes/" target="_blank">20be33e2-bf35-4d13-8fad-18bd2f3e3659</a><br><a href="https://www.enterprisedb.com/docs/epas/latest/epas_rel_notes/" target="_blank">20be33e2-bf35-4d13-8fad-18bd2f3e3659</a><br><a href="https://www.enterprisedb.com/docs/security/advisories/cve20244545/" target="_blank">20be33e2-bf35-4d13-8fad-18bd2f3e3659</a></td>
</tr>
<tr>
<td>EverPress--Mailster<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EverPress Mailster allows PHP Local File Inclusion.This issue affects Mailster: from n/a through 4.0.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32523&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32523" target="_blank">CVE-2024-32523</a><br><a href="https://patchstack.com/database/vulnerability/mailster/wordpress-mailster-plugin-4-0-6-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Favethemes--Houzez Login Register<br> </td>
<td>Improper Privilege Management vulnerability in favethemes Houzez Login Register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through 2.6.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-26009&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-26009" target="_blank">CVE-2023-26009</a><br><a href="https://patchstack.com/database/vulnerability/houzez-login-register/wordpress-houzez-login-register-plugin-2-6-3-privilege-escalation?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Favethemes--Houzez<br> </td>
<td>Improper Privilege Management vulnerability in Favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 2.7.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-26540&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-26540" target="_blank">CVE-2023-26540</a><br><a href="https://patchstack.com/database/vulnerability/houzez/wordpress-houzez-theme-2-7-1-privilege-escalation?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiOS<br> </td>
<td>A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privileged attacker over the administrative interface to execute arbitrary code or commands via crafted HTTP or HTTPs requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46714&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46714" target="_blank">CVE-2023-46714</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-415" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiPortal<br> </td>
<td>A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an unauthenticated attack to bypass IP protection through crafted HTTP or HTTPS packets.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23105&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23105" target="_blank">CVE-2024-23105</a><br><a href="https://fortiguard.com/psirt/FG-IR-24-021" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiSandbox<br> </td>
<td>A client-side enforcement of server-side security in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31491&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31491" target="_blank">CVE-2024-31491</a><br><a href="https://fortiguard.com/psirt/FG-IR-24-054" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiVoice<br> </td>
<td>An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to read the SIP configuration of other users via crafted HTTP or HTTPS requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-40720&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40720" target="_blank">CVE-2023-40720</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-282" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>GE HealthCare--EchoPAC Software Only<br> </td>
<td>Weak account password in GE HealthCare EchoPAC products</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27107&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27107" target="_blank">CVE-2024-27107</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--EchoPAC Software Only<br> </td>
<td>Elevation of privilege vulnerability in GE HealthCare EchoPAC products</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27110&amp;vector=CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27110" target="_blank">CVE-2024-27110</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--EchoPAC Software Only<br> </td>
<td>Insufficiently protected credentials in GE HealthCare EchoPAC products</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27109&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27109" target="_blank">CVE-2024-27109</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--Venue<br> </td>
<td>OS command injection vulnerabilities in GE HealthCare ultrasound devices</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1628&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1628" target="_blank">CVE-2024-1628</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--Venue<br> </td>
<td>Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1486&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1486" target="_blank">CVE-2024-1486</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--Venue<br> </td>
<td>Path traversal vulnerability in "getAllFolderContents" function of Common Service Desktop, a GE HealthCare ultrasound device component</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1630&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1630" target="_blank">CVE-2024-1630</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>Ghost Foundation--Ghost<br> </td>
<td>Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from n/a through 1.4.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34559&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34559" target="_blank">CVE-2024-34559</a><br><a href="https://patchstack.com/database/vulnerability/ghost/wordpress-ghost-plugin-1-4-0-sensitive-data-exposure-via-log-file-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>GiveWP--GiveWP<br> </td>
<td>Improper Privilege Management vulnerability in GiveWP allows Privilege Escalation.This issue affects GiveWP: from n/a through 2.33.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41665&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41665" target="_blank">CVE-2023-41665</a><br><a href="https://patchstack.com/database/vulnerability/give/wordpress-givewp-plugin-2-33-0-givewp-manager-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Glowlogix--WP Frontend Profile<br> </td>
<td>Improper Privilege Management vulnerability in Glowlogix WP Frontend Profile allows Privilege Escalation.This issue affects WP Frontend Profile: from n/a through 1.3.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51483&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51483" target="_blank">CVE-2023-51483</a><br><a href="https://patchstack.com/database/vulnerability/wp-front-end-profile/wordpress-wp-frontend-profile-plugin-1-3-1-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>HCL Software--Commerce<br> </td>
<td>Security vulnerability in HCL Commerce 9.1.12 and 9.1.13 could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23576&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23576" target="_blank">CVE-2024-23576</a><br><a href="https://support.hcltechsw.com/csm?id=kb_article&amp;sysparm_article=KB0112907" target="_blank">psirt@hcl.com</a></td>
</tr>
<tr>
<td>Hamid Alinia idehweb--Login with phone number<br> </td>
<td>Improper Privilege Management vulnerability in Hamid Alinia - idehweb Login with phone number allows Privilege Escalation.This issue affects Login with phone number: from n/a through 1.7.16.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32507&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32507" target="_blank">CVE-2024-32507</a><br><a href="https://patchstack.com/database/vulnerability/login-with-phone-number/wordpress-login-with-phone-number-plugin-1-7-16-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>HasThemes--HT Mega<br> </td>
<td>Improper Privilege Management vulnerability in HasThemes HT Mega allows Privilege Escalation.This issue affects HT Mega: from n/a through 2.2.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37999&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37999" target="_blank">CVE-2023-37999</a><br><a href="https://patchstack.com/database/vulnerability/ht-mega-for-elementor/wordpress-ht-mega-absolute-addons-for-elementor-plugin-2-2-0-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31466&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31466" target="_blank">CVE-2024-31466</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31467&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31467" target="_blank">CVE-2024-31467</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31468&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31468" target="_blank">CVE-2024-31468</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31469&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31469" target="_blank">CVE-2024-31469</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31470&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31470" target="_blank">CVE-2024-31470</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31471&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31471" target="_blank">CVE-2024-31471</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31472&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31472" target="_blank">CVE-2024-31472</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31473&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31473" target="_blank">CVE-2024-31473</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31474&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31474" target="_blank">CVE-2024-31474</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the affected Access Point.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31475&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31475" target="_blank">CVE-2024-31475</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31476&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31476" target="_blank">CVE-2024-31476</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31477&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31477" target="_blank">CVE-2024-31477</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32997&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32997" target="_blank">CVE-2024-32997</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-52719&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52719" target="_blank">CVE-2023-52719</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Permission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32991&amp;vector=CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32991" target="_blank">CVE-2024-32991</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Insufficient verification vulnerability in the baseband module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32992&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32992" target="_blank">CVE-2024-32992</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>IBM--AIX<br> </td>
<td>IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 283985.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27260&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27260" target="_blank">CVE-2024-27260</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/283985" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7152543" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--Security Guardium<br> </td>
<td>IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47709&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47709" target="_blank">CVE-2023-47709</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/271524" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150840" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--Security Guardium<br> </td>
<td>IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. IBM X-Force ID: 271527.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47712&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47712" target="_blank">CVE-2023-47712</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/271524" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150840" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--i<br> </td>
<td>IBM i 7.2, 7.3, and 7.4 could allow a remote attacker to execute arbitrary code leading to a denial of service of network ports on the system, caused by the deserialization of untrusted data. IBM X-Force ID: 287539.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31879&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31879" target="_blank">CVE-2024-31879</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/287539" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7154380" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IOSS--WP MLM Unilevel<br> </td>
<td>Improper Privilege Management vulnerability in IOSS WP MLM Unilevel allows Privilege Escalation.This issue affects WP MLM Unilevel: from n/a through 4.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51476&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51476" target="_blank">CVE-2023-51476</a><br><a href="https://patchstack.com/database/vulnerability/wp-mlm/wordpress-wp-mlm-unilevel-plugin-4-0-unauthenticated-account-takeover-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>InstaWP Team--InstaWP Connect<br> </td>
<td>Improper Privilege Management vulnerability in InstaWP Team InstaWP Connect allows Privilege Escalation.This issue affects InstaWP Connect: from n/a through 0.1.0.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22145&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22145" target="_blank">CVE-2024-22145</a><br><a href="https://patchstack.com/database/vulnerability/instawp-connect/wordpress-instawp-connect-plugin-0-1-0-8-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>J.N. Breetvelt a.k.a. OpaJaap--WP Photo Album Plus<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.7.01.001.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31377&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31377" target="_blank">CVE-2024-31377</a><br><a href="https://patchstack.com/database/vulnerability/wp-photo-album-plus/wordpress-wp-photo-album-plus-plugin-8-7-01-001-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>JR King/Eran Schoellhorn--WP Masquerade<br> </td>
<td>Improper Privilege Management vulnerability in JR King/Eran Schoellhorn WP Masquerade allows Privilege Escalation.This issue affects WP Masquerade: from n/a through 1.1.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33550&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33550" target="_blank">CVE-2024-33550</a><br><a href="https://patchstack.com/database/vulnerability/wp-masquerade/wordpress-wp-masquerade-plugin-1-1-0-authenticated-account-takeover-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>JS Help Desk--JS Help Desk Best Help Desk &amp; Support Plugin<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk - Best Help Desk &amp; Support Plugin allows Using Malicious Files.This issue affects JS Help Desk - Best Help Desk &amp; Support Plugin: from n/a through 2.7.7.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-25444&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-25444" target="_blank">CVE-2023-25444</a><br><a href="https://patchstack.com/database/vulnerability/js-support-ticket/wordpress-js-help-desk-best-help-desk-support-plugin-plugin-2-7-7-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Jordy Meow--AI Engine: ChatGPT Chatbot<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.2.63.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34440&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34440" target="_blank">CVE-2024-34440</a><br><a href="https://patchstack.com/database/vulnerability/ai-engine/wordpress-ai-engine-plugin-2-2-63-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Joseph C Dolson--My Tickets<br> </td>
<td>Missing Authorization vulnerability in Joseph C Dolson My Tickets.This issue affects My Tickets: from n/a through 1.9.11.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23988&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23988" target="_blank">CVE-2023-23988</a><br><a href="https://patchstack.com/database/vulnerability/my-tickets/wordpress-my-tickets-plugin-1-9-11-payment-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>JumpDEMAND Inc.--ActiveDEMAND<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in JumpDEMAND Inc. ActiveDEMAND allows Using Malicious Files.This issue affects ActiveDEMAND: from n/a through 0.2.41.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32809&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32809" target="_blank">CVE-2024-32809</a><br><a href="https://patchstack.com/database/vulnerability/activedemand/wordpress-activedemand-plugin-0-2-41-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Kioware--Kioware<br> </td>
<td>KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, search through local files and, subsequently, launch any program with user privileges.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3459&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3459" target="_blank">CVE-2024-3459</a><br><a href="https://cert.pl/en/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://www.kioware.com/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Kioware--Kioware<br> </td>
<td>In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing a short time window before the forced automatic logout occurs. Then, by using some built-in function of these applications, one may launch any other programs.  In order to exploit this vulnerability external applications must be left running when the KioWare software is launched. Additionally, an attacker must know the PIN set for this Kioware instance and also slow down the application with some specific task which extends the usable time window.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3460&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3460" target="_blank">CVE-2024-3460</a><br><a href="https://cert.pl/en/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://www.kioware.com/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Kognetiks--Kognetiks Chatbot for WordPress<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Kognetiks Kognetiks Chatbot for WordPress.This issue affects Kognetiks Chatbot for WordPress: from n/a through 2.0.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32700&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32700" target="_blank">CVE-2024-32700</a><br><a href="https://patchstack.com/database/vulnerability/chatbot-chatgpt/wordpress-kognetiks-chatbot-for-wordpress-plugin-2-0-0-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>LWS--LWS Affiliation<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LWS LWS Affiliation allows PHP Local File Inclusion.This issue affects LWS Affiliation: from n/a through 2.2.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-32297&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-32297" target="_blank">CVE-2023-32297</a><br><a href="https://patchstack.com/database/vulnerability/lws-affiliation/wordpress-lws-affiliation-plugin-2-2-6-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Lenderd--1003 Mortgage Application<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Lenderd 1003 Mortgage Application allows Relative Path Traversal.This issue affects 1003 Mortgage Application: from n/a through 1.75.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-45368&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-45368" target="_blank">CVE-2022-45368</a><br><a href="https://patchstack.com/database/vulnerability/1003-mortgage-application/wordpress-1003-mortgage-application-plugin-1-73-local-file-inclusion?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Lenovo--Printers<br> </td>
<td>A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restart by sending a specially crafted web request.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3286&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3286" target="_blank">CVE-2024-3286</a><br><a href="https://iknow.lenovo.com.cn/detail/421500" target="_blank">psirt@lenovo.com</a><br><a href="https://www.lenovoimage.com/psirt/notice/158605.html" target="_blank">psirt@lenovo.com</a></td>
</tr>
<tr>
<td>MSI--MSI Afterburner<br> </td>
<td>MSI Afterburner v4.6.6.16381 Beta 3 is vulnerable to an ACL Bypass vulnerability in the RTCore64.sys driver, which leads to triggering vulnerabilities like CVE-2024-1443 and CVE-2024-1460 from a low privileged user.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3745&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3745" target="_blank">CVE-2024-3745</a><br><a href="https://fluidattacks.com/advisories/gershwin/" target="_blank">help@fluidattacks.com</a><br><a href="https://forums.guru3d.com/threads/msi-ab-rtss-development-news-thread.412822/page-227#post-6231456" target="_blank">help@fluidattacks.com</a><br><a href="https://forums.guru3d.com/threads/msi-ab-rtss-development-news-thread.412822/page-227#post-6231768" target="_blank">help@fluidattacks.com</a></td>
</tr>
<tr>
<td>MainWP--MainWP Code Snippets Extension<br> </td>
<td>Improper Control of Generation of Code ('Code Injection') vulnerability in MainWP MainWP Code Snippets Extension allows Code Injection.This issue affects MainWP Code Snippets Extension: from n/a through 4.0.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23645&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23645" target="_blank">CVE-2023-23645</a><br><a href="https://patchstack.com/database/vulnerability/mainwp-code-snippets-extension/wordpress-mainwp-code-snippets-extension-plugin-4-0-2-subscriber-arbitrary-php-code-injection-execution-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Masteriyo--LMS<br> </td>
<td>Improper Privilege Management vulnerability in Masteriyo LMS allows Privilege Escalation.This issue affects LMS: from n/a through 1.7.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24882&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24882" target="_blank">CVE-2024-24882</a><br><a href="https://patchstack.com/database/vulnerability/learning-management-system/wordpress-lms-by-masteriyo-plugin-1-7-2-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Microsoft--Azure Monitor<br> </td>
<td>Azure Monitor Agent Elevation of Privilege Vulnerability</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30060&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30060" target="_blank">CVE-2024-30060</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30060" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Dynamics 365<br> </td>
<td>Dynamics 365 Customer Insights Spoofing Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30047&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30047" target="_blank">CVE-2024-30047</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30047" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Dynamics 365<br> </td>
<td>Dynamics 365 Customer Insights Spoofing Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30048&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30048" target="_blank">CVE-2024-30048</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30048" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Microsoft SharePoint Enterprise Server 2016<br> </td>
<td>Microsoft SharePoint Server Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30044&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30044" target="_blank">CVE-2024-30044</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30044" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Office Online Server<br> </td>
<td>Microsoft Excel Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30042&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30042" target="_blank">CVE-2024-30042</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30042" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30006&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30006" target="_blank">CVE-2024-30006</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30006" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30009&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30009" target="_blank">CVE-2024-30009</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30009" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Hyper-V Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30017&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30017" target="_blank">CVE-2024-30017</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30017" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Cryptographic Services Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30020&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30020" target="_blank">CVE-2024-30020</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30020" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29994&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29994" target="_blank">CVE-2024-29994</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29994" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Common Log File System Driver Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29996&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29996" target="_blank">CVE-2024-29996</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29996" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30014&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30014" target="_blank">CVE-2024-30014</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30014" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30015&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30015" target="_blank">CVE-2024-30015</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30015" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Kernel Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30018&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30018" target="_blank">CVE-2024-30018</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30018" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30022&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30022" target="_blank">CVE-2024-30022</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30022" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30023&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30023" target="_blank">CVE-2024-30023</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30023" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30024&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30024" target="_blank">CVE-2024-30024</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30024" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Common Log File System Driver Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30025&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30025" target="_blank">CVE-2024-30025</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30025" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>NTFS Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30027&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30027" target="_blank">CVE-2024-30027</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30027" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Win32k Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30028&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30028" target="_blank">CVE-2024-30028</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30028" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30029&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30029" target="_blank">CVE-2024-30029</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30029" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows CNG Key Isolation Service Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30031&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30031" target="_blank">CVE-2024-30031</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30031" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows DWM Core Library Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30032&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30032" target="_blank">CVE-2024-30032</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30032" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows DWM Core Library Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30035&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30035" target="_blank">CVE-2024-30035</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30035" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Common Log File System Driver Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30037&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30037" target="_blank">CVE-2024-30037</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30037" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Win32k Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30038&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30038" target="_blank">CVE-2024-30038</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30038" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30049&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30049" target="_blank">CVE-2024-30049</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30049" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 21H2<br> </td>
<td>Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-26238&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-26238" target="_blank">CVE-2024-26238</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26238" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2008 Service Pack 2<br> </td>
<td>Win32k Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30030&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30030" target="_blank">CVE-2024-30030</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30030" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2019<br> </td>
<td>Windows Hyper-V Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30010&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30010" target="_blank">CVE-2024-30010</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30010" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2022, 23H2 Edition (Server Core installation)<br> </td>
<td>Microsoft Brokering File System Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30007&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30007" target="_blank">CVE-2024-30007</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30007" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2022<br> </td>
<td>Windows Search Service Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30033&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30033" target="_blank">CVE-2024-30033</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30033" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>MongoDB Inc--MongoDB Server<br> </td>
<td>Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application behavior including unavailability of serverStatus responses. This issue affects MongoDB Server v7.0 versions prior to 7.0.6, MongoDB Server v6.0 versions prior to 6.0.14 and MongoDB Server v.5.0 versions prior to 5.0.25.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3372&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3372" target="_blank">CVE-2024-3372</a><br><a href="https://jira.mongodb.org/browse/SERVER-85263" target="_blank">cna@mongodb.com</a></td>
</tr>
<tr>
<td>N/A--Pk Favicon Manager<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Pk Favicon Manager.This issue affects Pk Favicon Manager: from n/a through 2.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34416&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34416" target="_blank">CVE-2024-34416</a><br><a href="https://patchstack.com/database/vulnerability/phpsword-favicon-manager/wordpress-pk-favicon-manager-plugin-2-1-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>N/A--VMware Workstation<br> </td>
<td>VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial of service condition.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22268&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22268" target="_blank">CVE-2024-22268</a><br><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank">security@vmware.com</a></td>
</tr>
<tr>
<td>N/A--VMware Workstation<br> </td>
<td>VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22269&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22269" target="_blank">CVE-2024-22269</a><br><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank">security@vmware.com</a></td>
</tr>
<tr>
<td>N/A--VMware Workstation<br> </td>
<td>VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22270&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22270" target="_blank">CVE-2024-22270</a><br><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank">security@vmware.com</a></td>
</tr>
<tr>
<td>NA--VMware Workstation<br> </td>
<td>VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22267&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22267" target="_blank">CVE-2024-22267</a><br><a href="https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280" target="_blank">security@vmware.com</a></td>
</tr>
<tr>
<td>NI--FlexLogger<br> </td>
<td>A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects NI FlexLogger 2024 Q1 and prior versions as well as NI InstrumentStudio 2024 Q1 and prior versions.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4044&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4044" target="_blank">CVE-2024-4044</a><br><a href="https://ni.com/r/CVE-2024-4044" target="_blank">security@ni.com</a></td>
</tr>
<tr>
<td>Netflix--Genie<br> </td>
<td>A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4701&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L" target="_blank" title="CVSS V3 Score">9.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4701" target="_blank">CVE-2024-4701</a><br><a href="https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2024-001.md" target="_blank">security-report@netflix.com</a></td>
</tr>
<tr>
<td>Nota-Info--Bookly<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Nota-Info Bookly allows Path Traversal, Manipulating Web Input to File System Calls.This issue affects Bookly: from n/a through 21.7.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-26526&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-26526" target="_blank">CVE-2023-26526</a><br><a href="https://patchstack.com/database/vulnerability/bookly-responsive-appointment-booking-tool/wordpress-bookly-plugin-21-7-1-authenticated-arbitrary-file-deletion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Nozomi Networks--Arc<br> </td>
<td>Multiple functions use archives without properly validating the filenames therein, rendering the application vulnerable to path traversal via 'zip slip' attacks. An administrator able to provide tampered archives to be processed by the affected versions of Arc may be able to have arbitrary files extracted to arbitrary filesystem locations. Leveraging this issue, an attacker may be able to overwrite arbitrary files on the target filesystem and cause critical impacts on the system (e.g., arbitrary command execution on the victim's machine).</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5938&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5938" target="_blank">CVE-2023-5938</a><br><a href="https://security.nozominetworks.com/NN-2023:16-01" target="_blank">prodsec@nozominetworks.com</a></td>
</tr>
<tr>
<td>Nozomi Networks--Arc<br> </td>
<td>When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks authentication and may thus be abused by a local attacker or malware running on the machine itself. A malicious local user or process, during a window of opportunity when the local web interface is active, may be able to extract sensitive information or change Arc's configuration. This could also lead to arbitrary code execution if a malicious update package is installed.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5935&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5935" target="_blank">CVE-2023-5935</a><br><a href="https://security.nozominetworks.com/NN-2023:13-01" target="_blank">prodsec@nozominetworks.com</a></td>
</tr>
<tr>
<td>Nozomi Networks--Arc<br> </td>
<td>On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a malicious local user in the system may be able to trigger arbitrary code execution with root privileges.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5936&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5936" target="_blank">CVE-2023-5936</a><br><a href="https://security.nozominetworks.com/NN-2023:14-01" target="_blank">prodsec@nozominetworks.com</a></td>
</tr>
<tr>
<td>OceanWP--OceanWP<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OceanWP allows PHP Local File Inclusion.This issue affects OceanWP: from n/a through 3.4.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23700&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23700" target="_blank">CVE-2023-23700</a><br><a href="https://patchstack.com/database/vulnerability/oceanwp/wordpress-oceanwp-theme-3-4-1-authenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>OctoPrint--OctoPrint<br> </td>
<td>OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication if the `autologinLocal` option is enabled within `config.yaml`, even if they come from networks that are not configured as `localNetworks`, spoofing their IP via the `X-Forwarded-For` header. If autologin is not enabled, this vulnerability does not have any impact. The vulnerability has been patched in version 1.10.1. Until the patch has been applied, OctoPrint administrators who have autologin enabled on their instances should disable it and/or to make the instance inaccessible from potentially hostile networks like the internet.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32977&amp;vector=CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32977" target="_blank">CVE-2024-32977</a><br><a href="https://github.com/OctoPrint/OctoPrint/commit/5afbec8d23508edc25b0f1bdef1620580136add4" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-2vjq-hg5w-5gm7" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Remote Code Execution has been discovered in OpenTextâ„¢ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3483&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3483" target="_blank">CVE-2024-3483</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>XML External Entity injection vulnerability found in OpenTextâ„¢ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3486&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3486" target="_blank">CVE-2024-3486</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Remote Code Execution has been discovered in OpenTextâ„¢ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3967&amp;vector=CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3967" target="_blank">CVE-2024-3967</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Remote Code Execution has been discovered in OpenTextâ„¢ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upload task.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3968&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3968" target="_blank">CVE-2024-3968</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>Owlet--Cam v2<br> </td>
<td>A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6321&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6321" target="_blank">CVE-2023-6321</a><br><a href="https://bitdefender.com/blog/labs/notes-on-throughtek-kalay-vulnerabilities-and-their-impact/" target="_blank">cve-requests@bitdefender.com</a></td>
</tr>
<tr>
<td>P-THEMES--Porto Theme - Functionality<br> </td>
<td>The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the 'porto_portfolios' shortcode 'portfolio_layout' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3808&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3808" target="_blank">CVE-2024-3808</a><br><a href="https://themeforest.net/item/porto-responsive-wordpress-ecommerce-theme/9207399" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/fea96f84-f75b-4f02-9ca8-f8fda439d565?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>P-THEMES--Porto Theme - Functionality<br> </td>
<td>The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.9 via the 'slideshow_type' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3809&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3809" target="_blank">CVE-2024-3809</a><br><a href="https://themeforest.net/item/porto-responsive-wordpress-ecommerce-theme/9207399" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f5cdd3c1-6353-4bee-a4f9-5b7972f0970c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>P-THEMES--Porto<br> </td>
<td>The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the 'porto_ajax_posts' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3806&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3806" target="_blank">CVE-2024-3806</a><br><a href="https://themeforest.net/item/porto-responsive-wordpress-ecommerce-theme/9207399" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/98ccc604-79c6-4be9-acb0-23fc82a31dfa?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>P-THEMES--Porto<br> </td>
<td>The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'porto_page_header_shortcode_type', 'slideshow_type' and 'post_layout' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included. This was partially patched in version 7.1.0 and fully patched in version 7.1.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3807&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3807" target="_blank">CVE-2024-3807</a><br><a href="https://themeforest.net/item/porto-responsive-wordpress-ecommerce-theme/9207399" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4bc3da9e-4b5f-4200-9df9-0ae953571377?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>PHOENIX CONTACT--CHARX SEC-3000<br> </td>
<td>A local low privileged attacker can use an untrusted search path in a CHARX system utility to gain root privileges. </td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28133&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28133" target="_blank">CVE-2024-28133</a><br><a href="https://cert.vde.com/en/advisories/VDE-2024-019" target="_blank">info@cert.vde.com</a></td>
</tr>
<tr>
<td>PHOENIX CONTACT--CHARX SEC-3000<br> </td>
<td>An unauthenticated remote attacker can extract a session token with a MitM attack and gain web-based management access with the privileges of the currently logged in user due to cleartext transmission of sensitive information. No additional user interaction is required. The access is limited as only non-sensitive information can be obtained but the availability can be seriously affected. </td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28134&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28134" target="_blank">CVE-2024-28134</a><br><a href="https://cert.vde.com/en/advisories/VDE-2024-019" target="_blank">info@cert.vde.com</a></td>
</tr>
<tr>
<td>PHOENIX CONTACT--CHARX SEC-3000<br> </td>
<td>A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28136&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28136" target="_blank">CVE-2024-28136</a><br><a href="https://cert.vde.com/en/advisories/VDE-2024-019" target="_blank">info@cert.vde.com</a></td>
</tr>
<tr>
<td>PHOENIX CONTACT--CHARX SEC-3000<br> </td>
<td>A local attacker with low privileges can perform a privilege escalation with an init script due to a TOCTOU vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28137&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28137" target="_blank">CVE-2024-28137</a><br><a href="https://cert.vde.com/en/advisories/VDE-2024-019" target="_blank">info@cert.vde.com</a></td>
</tr>
<tr>
<td>PHPGurukul--Online Course Registration System<br> </td>
<td>A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264922 is the identifier assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5063&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5063" target="_blank">CVE-2024-5063</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20Authentication%20Bypass.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264922" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264922" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336236" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>PHPGurukul--Online Course Registration System<br> </td>
<td>A vulnerability was found in PHPGurukul Online Course Registration System 3.1. It has been rated as critical. This issue affects some unknown processing of the file news-details.php. The manipulation of the argument nid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264923.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5064&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5064" target="_blank">CVE-2024-5064</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20SQL%20Injection%20-%202%20(Unauthenticated).md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264923" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264923" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336238" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>PHPGurukul--Online Course Registration System<br> </td>
<td>A vulnerability classified as critical has been found in PHPGurukul Online Course Registration System 3.1. Affected is an unknown function of the file /onlinecourse/. The manipulation of the argument regno leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264924.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5065&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5065" target="_blank">CVE-2024-5065</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20SQL%20Injection%20-%203%20(Unauthenticated).md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264924" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264924" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336239" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>POSIMYTH Innovation--The Plus Addons for Elementor Pro<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows PHP Local File Inclusion.This issue affects The Plus Addons for Elementor Pro: from n/a through 5.2.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47178&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47178" target="_blank">CVE-2023-47178</a><br><a href="https://patchstack.com/database/vulnerability/theplus_elementor_addon/wordpress-the-plus-addons-for-elementor-pro-plugin-5-2-8-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Phoenix--SecureCore for Intel Gemini Lake<br> </td>
<td>Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCoreâ„¢ for Intel Gemini Lake.This issue affects: SecureCoreâ„¢ for Intel Gemini Lake: from 4.1.0.1 before 4.1.0.567.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1598&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1598" target="_blank">CVE-2024-1598</a><br><a href="https://www.phoenix.com/security-notifications/cve-2024-1598/" target="_blank">22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de</a></td>
</tr>
<tr>
<td>Phoenix--SecureCore for Intel Kaby Lake<br> </td>
<td>Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCoreâ„¢ for select Intel platforms This issue affects: Phoenix SecureCoreâ„¢ for Intel Kaby Lake: from 4.0.1.1 before 4.0.1.998; Phoenix SecureCoreâ„¢ for Intel Coffee Lake: from 4.1.0.1 before 4.1.0.562; Phoenix SecureCoreâ„¢ for Intel Ice Lake: from 4.2.0.1 before 4.2.0.323; Phoenix SecureCoreâ„¢ for Intel Comet Lake: from 4.2.1.1 before 4.2.1.287; Phoenix SecureCoreâ„¢ for Intel Tiger Lake: from 4.3.0.1 before 4.3.0.236; Phoenix SecureCoreâ„¢ for Intel Jasper Lake: from 4.3.1.1 before 4.3.1.184; Phoenix SecureCoreâ„¢ for Intel Alder Lake: from 4.4.0.1 before 4.4.0.269; Phoenix SecureCoreâ„¢ for Intel Raptor Lake: from 4.5.0.1 before 4.5.0.218; Phoenix SecureCoreâ„¢ for Intel Meteor Lake: from 4.5.1.1 before 4.5.1.15.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0762&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0762" target="_blank">CVE-2024-0762</a><br><a href="https://www.phoenix.com/security-notifications/cve-2024-0762/" target="_blank">22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de</a></td>
</tr>
<tr>
<td>Phoenix--WinFlash Driver<br> </td>
<td>Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash Driver: before 4.5.0.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-35841&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-35841" target="_blank">CVE-2023-35841</a><br><a href="https://blogs.vmware.com/security/2023/10/hunting-vulnerable-kernel-drivers.html" target="_blank">22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de</a><br><a href="https://jvn.jp/en/vu/JVNVU93886750/index.html" target="_blank">22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de</a><br><a href="https://www.phoenix.com/security-notifications/cve-2023-35841/" target="_blank">22d9ba52-f336-4b0d-bf1f-0efbdcc3c1de</a></td>
</tr>
<tr>
<td>PluginOps--Landing Page Builder<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Reflected XSS.This issue affects Landing Page Builder: from n/a through 1.5.1.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34752&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34752" target="_blank">CVE-2024-34752</a><br><a href="https://patchstack.com/database/vulnerability/page-builder-add/wordpress-landing-page-builder-1-5-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PluginUS--HUSKY Products Filter for WooCommerce (formerly WOOF)<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in PluginUS HUSKY - Products Filter for WooCommerce (formerly WOOF) allows Using Malicious Files, Code Inclusion.This issue affects HUSKY - Products Filter for WooCommerce (formerly WOOF): from n/a through 1.3.5.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32680&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32680" target="_blank">CVE-2024-32680</a><br><a href="https://patchstack.com/database/vulnerability/woocommerce-products-filter/wordpress-husky-plugin-1-3-5-2-remote-code-execution-rce-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Podlove--Podlove Podcast Publisher<br> </td>
<td>Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32712&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32712" target="_blank">CVE-2024-32712</a><br><a href="https://patchstack.com/database/vulnerability/podlove-podcasting-plugin-for-wordpress/wordpress-podlove-podcast-publisher-plugin-4-0-14-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PowerDNS--DNSdist<br> </td>
<td>When incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or DNS over TLS backend, an attacker can trigger an assertion failure in DNSdist by sending a request for a zone transfer (AXFR or IXFR) over DNS over HTTPS, causing the process to stop and thus leading to a Denial of Service. DNS over HTTPS is not enabled by default, and backends are using plain DNS (Do53) by default.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25581&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25581" target="_blank">CVE-2024-25581</a><br><a href="https://dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2024-03.html" target="_blank">security@open-xchange.com</a></td>
</tr>
<tr>
<td>Premmerce--Premmerce Permalink Manager for WooCommerce<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Premmerce Premmerce Permalink Manager for WooCommerce allows PHP Local File Inclusion.This issue affects Premmerce Permalink Manager for WooCommerce: from n/a through 2.3.10.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27971&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27971" target="_blank">CVE-2024-27971</a><br><a href="https://patchstack.com/database/vulnerability/woo-permalink-manager/wordpress-premmerce-permalink-manager-for-woocommerce-plugin-2-3-10-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PrestaShop--PrestaShop<br> </td>
<td>PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting from PrestaShop 8.1.0 and prior to PrestaShop 8.1.6. When the customer thread feature flag is enabled through the front-office contact form, a hacker can upload a malicious file containing an XSS that will be executed when an admin opens the attached file in back office. The script injected can access the session and the security token, which allows it to perform any authenticated action in the scope of the administrator's right. This vulnerability is patched in 8.1.6. A workaround is to disable the customer-thread feature-flag.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34716&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34716" target="_blank">CVE-2024-34716</a><br><a href="https://github.com/PrestaShop/PrestaShop/releases/tag/8.1.6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-45vm-3j38-7p78" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>ProfilePress Membership Team--ProfilePress<br> </td>
<td>Improper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress: from n/a through 4.13.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41954&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41954" target="_blank">CVE-2023-41954</a><br><a href="https://patchstack.com/database/vulnerability/wp-user-avatar/wordpress-profilepress-plugin-4-13-1-unauthenticated-limited-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Progress Software Corporation--Telerik Reporting<br> </td>
<td>In ProgressÂ® TelerikÂ® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4200&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4200" target="_blank">CVE-2024-4200</a><br><a href="https://docs.telerik.com/reporting/knowledge-base/deserialization-vulnerability-cve-2024-4200" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Progress Software Corporation--Telerik Reporting<br> </td>
<td>In ProgressÂ® TelerikÂ® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4202&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4202" target="_blank">CVE-2024-4202</a><br><a href="https://docs.telerik.com/reporting/knowledge-base/instantiation-vulnerability-cve-2024-4202" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Progress Software Corporation--Telerik UI for WinForms<br> </td>
<td>A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3892&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3892" target="_blank">CVE-2024-3892</a><br><a href="https://docs.telerik.com/devtools/winforms/knowledge-base/local-code-execution-vulnerability-cve-2024-3892" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Proofpoint--Enterprise Protection<br> </td>
<td>The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create additional Encryption user accounts under the attacker's control.  These accounts are able to send spoofed email to any users within the domains configured by the Administrator.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3676&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3676" target="_blank">CVE-2024-3676</a><br><a href="https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2024-0002" target="_blank">security@proofpoint.com</a></td>
</tr>
<tr>
<td>Propovoice--Propovoice CRM<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Propovoice Propovoice CRM allows Stored XSS.This issue affects Propovoice CRM: from n/a through 1.7.6.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4747&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4747" target="_blank">CVE-2024-4747</a><br><a href="https://patchstack.com/database/vulnerability/propovoice/wordpress-propovoice-crm-plugin-1-7-6-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>QuanticaLabs--Chauffeur Taxi Booking System for WordPress<br> </td>
<td>Missing Authorization vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Chauffeur Taxi Booking System for WordPress: from n/a through 6.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32692&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32692" target="_blank">CVE-2024-32692</a><br><a href="https://patchstack.com/database/vulnerability/chauffeur-booking-system/wordpress-chauffeur-taxi-booking-system-for-wordpress-plugin-6-9-broken-authentication-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Qube One Ltd.--Redirection for Contact Form 7<br> </td>
<td>Improper Privilege Management vulnerability in Qube One Ltd. Redirection for Contact Form 7 wpcf7-redirect allows Privilege Escalation.This issue affects Redirection for Contact Form 7: from n/a through 2.7.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23990&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23990" target="_blank">CVE-2023-23990</a><br><a href="https://patchstack.com/database/vulnerability/wpcf7-redirect/wordpress-redirection-for-contact-form-7-plugin-2-7-0-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Rank Math--Rank Math SEO<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rank Math Rank Math SEO allows Path Traversal.This issue affects Rank Math SEO: from n/a through 1.0.107.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23888&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23888" target="_blank">CVE-2023-23888</a><br><a href="https://patchstack.com/database/vulnerability/seo-by-rank-math/wordpress-rank-math-seo-plugin-1-0-107-2-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Red Hat--Migration Toolkit for Containers<br> </td>
<td>A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3727&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3727" target="_blank">CVE-2024-3727</a><br><a href="https://access.redhat.com/security/cve/CVE-2024-3727" target="_blank">secalert@redhat.com</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2274767" target="_blank">secalert@redhat.com</a></td>
</tr>
<tr>
<td>Repute Infosystems--ARMember<br> </td>
<td>Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51356&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51356" target="_blank">CVE-2023-51356</a><br><a href="https://patchstack.com/database/vulnerability/armember-membership/wordpress-armember-plugin-4-0-10-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Roku--Indoor Camera SE<br> </td>
<td>A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version 4.36.11.5859. A specially crafted message can lead to stack-based buffer overflow. An attacker can make authenticated requests to trigger this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6322&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6322" target="_blank">CVE-2023-6322</a><br><a href="https://bitdefender.com/blog/labs/notes-on-throughtek-kalay-vulnerabilities-and-their-impact/" target="_blank">cve-requests@bitdefender.com</a></td>
</tr>
<tr>
<td>Room 34 Creative Services, LLC--ICS Calendar<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF) vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Absolute Path Traversal, : Server Side Request Forgery.This issue affects ICS Calendar: from n/a through 10.12.0.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46784&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46784" target="_blank">CVE-2023-46784</a><br><a href="https://patchstack.com/database/vulnerability/ics-calendar/wordpress-ics-calendar-plugin-10-12-0-2-ssrf-and-arbitrary-file-read-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SAASPROJECT Booking Package--Booking Package<br> </td>
<td>Improper Privilege Management vulnerability in SAASPROJECT Booking Package Booking Package allows Privilege Escalation.This issue affects Booking Package: from n/a through 1.5.98.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37389&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37389" target="_blank">CVE-2023-37389</a><br><a href="https://patchstack.com/database/vulnerability/booking-package/wordpress-booking-package-saasproject-plugin-1-5-98-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP BusinessObjects Business Intelligence Platform<br> </td>
<td>SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to manipulate a parameter in the Opendocument URL which could lead to high impact on Confidentiality and Integrity of the application</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28165&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28165" target="_blank">CVE-2024-28165</a><br><a href="https://me.sap.com/notes/3431794" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP NetWeaver Application Server ABAP and ABAP Platform<br> </td>
<td>An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system. </td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33006&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33006" target="_blank">CVE-2024-33006</a><br><a href="https://me.sap.com/notes/3448171" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SUBNET--PowerSYSTEM Center<br> </td>
<td>SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28042&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28042" target="_blank">CVE-2024-28042</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-135-02" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>SailPoint--Identity Security Cloud<br> </td>
<td>An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined templates as part of attribute transforms which could allow remote code execution on the host.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3319&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3319" target="_blank">CVE-2024-3319</a><br><a href="https://www.sailpoint.com/security-advisories/" target="_blank">psirt@sailpoint.com</a></td>
</tr>
<tr>
<td>Saleswonder Team--WebinarIgnition<br> </td>
<td>Improper Privilege Management vulnerability in Saleswonder Team WebinarIgnition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through 3.05.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51424&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51424" target="_blank">CVE-2023-51424</a><br><a href="https://patchstack.com/database/vulnerability/webinar-ignition/wordpress-webinarignition-plugin-3-05-0-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SiAdmin--SiAdmin<br> </td>
<td>Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_pass/aksi_pass.php parameter in nama_lengkap. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in it.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4991&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4991" target="_blank">CVE-2024-4991</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-siadmin" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>SiAdmin--SiAdmin<br> </td>
<td>Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_kuliah/aksi_kuliah.php parameter in nim. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in it.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4992&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4992" target="_blank">CVE-2024-4992</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-siadmin" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Siemens--CPC80 Central Processing/Communication<br> </td>
<td>A vulnerability has been identified in CPC80 Central Processing/Communication (All versions &lt; V16.41), CPCI85 Central Processing/Communication (All versions &lt; V5.30). The affected device firmwares contain an improper null termination vulnerability while parsing a specific HTTP header. This could allow an attacker to execute code in the context of the current process or lead to denial of service condition.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31484&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31484" target="_blank">CVE-2024-31484</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-871704.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--CPCI85 Central Processing/Communication<br> </td>
<td>A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions &lt; V5.30), SICORE Base system (All versions &lt; V1.3.0). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31485&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31485" target="_blank">CVE-2024-31485</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-871704.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--JT2Go<br> </td>
<td>A vulnerability has been identified in JT2Go (All versions &lt; V2312.0001), Teamcenter Visualization V14.1 (All versions &lt; V14.1.0.13), Teamcenter Visualization V14.2 (All versions &lt; V14.2.0.10), Teamcenter Visualization V14.3 (All versions &lt; V14.3.0.7), Teamcenter Visualization V2312 (All versions &lt; V2312.0001). The affected applications contain a stack overflow vulnerability while parsing specially crafted XML files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34085&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34085" target="_blank">CVE-2024-34085</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-661579.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--JT2Go<br> </td>
<td>A vulnerability has been identified in JT2Go (All versions &lt; V2312.0001), Teamcenter Visualization V14.1 (All versions &lt; V14.1.0.13), Teamcenter Visualization V14.2 (All versions &lt; V14.2.0.10), Teamcenter Visualization V14.3 (All versions &lt; V14.3.0.7), Teamcenter Visualization V2312 (All versions &lt; V2312.0001). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted CGM file. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34086&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34086" target="_blank">CVE-2024-34086</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-661579.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32055&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32055" target="_blank">CVE-2024-32055</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21562)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32057&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32057" target="_blank">CVE-2024-32057</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected application is vulnerable to memory corruption while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21563)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32058&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32058" target="_blank">CVE-2024-32058</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21564)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32059&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32059" target="_blank">CVE-2024-32059</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21565)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32060&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32060" target="_blank">CVE-2024-32060</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21566)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32061&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32061" target="_blank">CVE-2024-32061</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21568)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32062&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32062" target="_blank">CVE-2024-32062</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected application contains a type confusion vulnerability while parsing IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21573)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32063&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32063" target="_blank">CVE-2024-32063</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21575)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32064&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32064" target="_blank">CVE-2024-32064</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21577)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32065&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32065" target="_blank">CVE-2024-32065</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--PS/IGES Parasolid Translator Component<br> </td>
<td>A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions &lt; V27.1.215). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21578)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32066&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32066" target="_blank">CVE-2024-32066</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-976324.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Parasolid V35.1<br> </td>
<td>A vulnerability has been identified in Parasolid V35.1 (All versions &lt; V35.1.256), Parasolid V36.0 (All versions &lt; V36.0.210), Parasolid V36.1 (All versions &lt; V36.1.185). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted X_T part file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-23468)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31980&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31980" target="_blank">CVE-2024-31980</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-489698.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Parasolid V35.1<br> </td>
<td>A vulnerability has been identified in Parasolid V35.1 (All versions &lt; V35.1.256), Parasolid V36.0 (All versions &lt; V36.0.208), Parasolid V36.1 (All versions &lt; V36.1.173). The affected applications contain an out of bounds read past the unmapped memory region while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32635&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32635" target="_blank">CVE-2024-32635</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-046364.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Parasolid V35.1<br> </td>
<td>A vulnerability has been identified in Parasolid V35.1 (All versions &lt; V35.1.256), Parasolid V36.0 (All versions &lt; V36.0.208), Parasolid V36.1 (All versions &lt; V36.1.173). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32636&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32636" target="_blank">CVE-2024-32636</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-046364.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems allow the upload of arbitrary files of any unauthenticated user. An attacker could leverage this vulnerability and achieve arbitrary code execution with system privileges.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27939&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27939" target="_blank">CVE-2024-27939</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems allow any authenticated user to send arbitrary SQL commands to the SQL server. An attacker could use this vulnerability to compromise the whole database.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27940&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27940" target="_blank">CVE-2024-27940</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected client systems do not properly sanitize input data before sending it to the SQL server. An attacker could use this vulnerability to compromise the whole database.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27941&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27941" target="_blank">CVE-2024-27941</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems allow any unauthenticated client to disconnect any active user from the server. An attacker could use this vulnerability to prevent any user to perform actions in the system, causing a denial of service situation.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27942&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27942" target="_blank">CVE-2024-27942</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems allow a privileged user to upload generic files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27943&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27943" target="_blank">CVE-2024-27943</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems allow a privileged user to upload firmware files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27944&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27944" target="_blank">CVE-2024-27944</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The bulk import feature of the affected systems allow a privileged user to upload files to the root installation directory of the system. By replacing specific files, an attacker could tamper specific files or even achieve remote code execution.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27945&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27945" target="_blank">CVE-2024-27945</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC CN 4100<br> </td>
<td>A vulnerability has been identified in SIMATIC CN 4100 (All versions &lt; V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default . An attacker who manages to crack the password hash gains root access to the device.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32741&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32741" target="_blank">CVE-2024-32741</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-273900.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC CN 4100<br> </td>
<td>A vulnerability has been identified in SIMATIC CN 4100 (All versions &lt; V3.0). The affected device contains undocumented users and credentials. An attacker could misuse the credentials to compromise the device locally or over the network.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32740&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32740" target="_blank">CVE-2024-32740</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-273900.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC CN 4100<br> </td>
<td>A vulnerability has been identified in SIMATIC CN 4100 (All versions &lt; V3.0). The affected device contains an unrestricted USB port. An attacker with local access to the device could potentially misuse the port for booting another operating system and gain complete read/write access to the filesystem.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32742&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32742" target="_blank">CVE-2024-32742</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-273900.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). The affected systems use symmetric cryptography with a hard-coded key to protect the communication between client and server. This could allow an unauthenticated remote attacker to compromise confidentiality and integrity of the communication and, subsequently, availability of the system. A successful exploit requires the attacker to gain knowledge of the hard-coded key and to be able to intercept the communication between client and server on the network.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30207&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30207" target="_blank">CVE-2024-30207</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected systems transmit client-side resources without proper cryptographic protection. This could allow an attacker to eavesdrop on and modify resources in transit. A successful exploit requires an attacker to be in the network path between the RTLS Locating Manager server and a client (MitM).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30209&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30209" target="_blank">CVE-2024-30209</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). The affected application assigns incorrect permissions to a user management component. This could allow a privileged attacker to escalate their privileges from the Administrators group to the Systemadministrator group.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33499&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33499" target="_blank">CVE-2024-33499</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected SIMATIC RTLS Locating Manager Clients do not properly check the integrity of update files. This could allow an unauthenticated remote attacker to alter update files in transit and trick an authorized user into installing malicious code. A successful exploit requires the attacker to be able to modify the communication between server and client on the network.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30206&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30206" target="_blank">CVE-2024-30206</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Simcenter Nastran 2306<br> </td>
<td>A vulnerability has been identified in Simcenter Nastran 2306 (All versions), Simcenter Nastran 2312 (All versions), Simcenter Nastran 2406 (All versions &lt; V2406.90). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33577&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33577" target="_blank">CVE-2024-33577</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-258494.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 5). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33489&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33489" target="_blank">CVE-2024-33489</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33490&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33490" target="_blank">CVE-2024-33490</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33491&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33491" target="_blank">CVE-2024-33491</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33492&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33492" target="_blank">CVE-2024-33492</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 5). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33493&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33493" target="_blank">CVE-2024-33493</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 2). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34771&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34771" target="_blank">CVE-2024-34771</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 4). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34772&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34772" target="_blank">CVE-2024-34772</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Solid Edge<br> </td>
<td>A vulnerability has been identified in Solid Edge (All versions &lt; V224.0 Update 2). The affected applications contain a stack overflow vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34773&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34773" target="_blank">CVE-2024-34773</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-589937.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Tecnomatix Plant Simulation V2302<br> </td>
<td>A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions &lt; V2302.0011). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted MODEL file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-22974)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32639&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32639" target="_blank">CVE-2024-32639</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-923361.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Sirv--Sirv<br> </td>
<td>Improper Privilege Management vulnerability in Sirv allows Privilege Escalation.This issue affects Sirv: from n/a through 7.2.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32959&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32959" target="_blank">CVE-2024-32959</a><br><a href="https://patchstack.com/database/vulnerability/sirv/wordpress-sirv-plugin-7-2-2-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Sizam Design--Rehub<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allows PHP Local File Inclusion.This issue affects Rehub: from n/a through 19.6.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31231&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31231" target="_blank">CVE-2024-31231</a><br><a href="https://patchstack.com/database/vulnerability/rehub-theme/wordpress-rehub-theme-19-6-1-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Sizam Design--Rehub<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allows PHP Local File Inclusion.This issue affects Rehub: from n/a through 19.6.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31232&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31232" target="_blank">CVE-2024-31232</a><br><a href="https://patchstack.com/database/vulnerability/rehub-theme/wordpress-rehub-theme-19-6-1-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Snow Software AB--Snow License Manager<br> </td>
<td>Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to perform an Authentication Bypass if Active Directory Authentication is enabled.This issue affects Snow License Manager: from 9.33.2 through 9.34.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4129&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4129" target="_blank">CVE-2024-4129</a><br><a href="https://community.snowsoftware.com/s/feed/0D5Td000008dv8sKAA" target="_blank">security@snowsoftware.com</a></td>
</tr>
<tr>
<td>SolarWinds--Access Rights Manager<br> </td>
<td>The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28075&amp;vector=CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28075" target="_blank">CVE-2024-28075</a><br><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm" target="_blank">psirt@solarwinds.com</a><br><a href="https://documentation.solarwinds.com/en/success_center/arm/content/secure-your-arm-deployment.htm" target="_blank">psirt@solarwinds.com</a><br><a href="https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-28075" target="_blank">psirt@solarwinds.com</a></td>
</tr>
<tr>
<td>SolarWinds--Access Rights Manager<br> </td>
<td>The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability allows access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23473&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23473" target="_blank">CVE-2024-23473</a><br><a href="https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm" target="_blank">psirt@solarwinds.com</a><br><a href="https://www.solarwinds.com/trust-center/security-advisories/CVE-2024-23473" target="_blank">psirt@solarwinds.com</a></td>
</tr>
<tr>
<td>Sonatype--Nexus Repository<br> </td>
<td>Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4956&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4956" target="_blank">CVE-2024-4956</a><br><a href="https://support.sonatype.com/hc/en-us/articles/29416509323923" target="_blank">103e4ec9-0a87-450b-af77-479448ddef11</a></td>
</tr>
<tr>
<td>SourceCodester--Best House Rental Management System<br> </td>
<td>A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265072.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5093&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5093" target="_blank">CVE-2024-5093</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/House%20Rental%20Management%20System/House%20Rental%20Management%20System%20-%20Authentication%20Bypass.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.265072" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.265072" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335712" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Best House Rental Management System<br> </td>
<td>A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This issue affects some unknown processing of the file view_payment.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-265073 was assigned to this vulnerability.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5094&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5094" target="_blank">CVE-2024-5094</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/House%20Rental%20Management%20System/House%20Rental%20Management%20System%20-%20SQL%20Injection%20-%202.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.265073" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.265073" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335714" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Discussion Forum Site<br> </td>
<td>A vulnerability was found in SourceCodester Online Discussion Forum Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file registerH.php. The manipulation of the argument ima leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264455.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4920&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4920" target="_blank">CVE-2024-4920</a><br><a href="https://github.com/CveSecLook/cve/issues/27" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264455" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264455" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333477" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Examination System<br> </td>
<td>A vulnerability was found in SourceCodester Online Examination System 1.0. It has been rated as critical. This issue affects some unknown processing of the file registeracc.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264743.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5046&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5046" target="_blank">CVE-2024-5046</a><br><a href="https://github.com/CveSecLook/cve/issues/32" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264743" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264743" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335527" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--SchoolWebTech<br> </td>
<td>A vulnerability was found in SourceCodester SchoolWebTech 1.0. It has been classified as critical. Affected is an unknown function of the file /improve/home.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264534 is the identifier assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4966&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4966" target="_blank">CVE-2024-4966</a><br><a href="https://github.com/CveSecLook/cve/issues/30" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264534" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264534" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.334216" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Student Management System<br> </td>
<td>A vulnerability classified as critical has been found in SourceCodester Student Management System 1.0. Affected is an unknown function of the file /student/controller.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264744.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5047&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5047" target="_blank">CVE-2024-5047</a><br><a href="https://github.com/I-Schnee-I/cev/blob/main/SourceCodester%20Student%20Management%20System%201.0%20controller.php%20Unrestricted%20Upload.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264744" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264744" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335633" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>StylemixThemes--Consulting<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting allows PHP Local File Inclusion.This issue affects Consulting: from n/a through 6.5.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37385&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37385" target="_blank">CVE-2023-37385</a><br><a href="https://patchstack.com/database/vulnerability/consulting/wordpress-consulting-theme-6-3-6-local-file-inclusion?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Tenable--Nessus Agent<br> </td>
<td>A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus Agent host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host. - CVE-2024-3292</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3292&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3292" target="_blank">CVE-2024-3292</a><br><a href="https://www.tenable.com/security/tns-2024-09" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>Tenable--Nessus Agent<br> </td>
<td>When installing Nessus Agent to a directory outside of the default location on a Windows host, Nessus Agent versions prior to 10.6.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3291&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3291" target="_blank">CVE-2024-3291</a><br><a href="https://www.tenable.com/security/tns-2024-09" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>Tenable--Nessus<br> </td>
<td>A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3290&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3290" target="_blank">CVE-2024-3290</a><br><a href="https://www.tenable.com/security/tns-2024-08" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>Tenable--Nessus<br> </td>
<td>When installing Nessus to a directory outside of the default location on a Windows host, Nessus versions prior to 10.7.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3289&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3289" target="_blank">CVE-2024-3289</a><br><a href="https://www.tenable.com/security/tns-2024-08" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>Teplitsa of social technologies--Leyka<br> </td>
<td>Improper Privilege Management vulnerability in Teplitsa of social technologies Leyka allows Privilege Escalation.This issue affects Leyka: from n/a through 3.30.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-33327&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-33327" target="_blank">CVE-2023-33327</a><br><a href="https://patchstack.com/database/vulnerability/leyka/wordpress-leyka-plugin-3-29-2-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThemeKraft--BuddyForms<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forgery, Relative Path Traversal.This issue affects BuddyForms: from n/a through 2.8.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32830&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32830" target="_blank">CVE-2024-32830</a><br><a href="https://patchstack.com/database/vulnerability/buddyforms/wordpress-buddyforms-plugin-2-8-8-arbitrary-file-read-and-ssrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThemeNectar--Salient Core<br> </td>
<td>The Salient Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.7 via the 'nectar_icon' shortcode 'icon_linea' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3812&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3812" target="_blank">CVE-2024-3812</a><br><a href="https://themeforest.net/item/salient-responsive-multipurpose-theme/4363266" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ebd3b70e-a06a-4dcc-a6af-dbe64fd57c82?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>ThemeNectar--Salient Shortcodes<br> </td>
<td>The Salient Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.5.3 via the 'icon' shortcode 'image' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3810&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3810" target="_blank">CVE-2024-3810</a><br><a href="https://themeforest.net/item/salient-responsive-multipurpose-theme/4363266" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d1b3d4d5-9d2b-4924-a830-27c07fa1ba98?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Themify--Themify Ultra<br> </td>
<td>Improper Privilege Management vulnerability in Themify Themify Ultra allows Privilege Escalation.This issue affects Themify Ultra: from n/a through 7.3.5.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46145&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46145" target="_blank">CVE-2023-46145</a><br><a href="https://patchstack.com/database/vulnerability/themify-ultra/wordpress-themify-ultra-theme-7-3-3-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Thomas Scholl--canvasio3D Light<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in Thomas Scholl canvasio3D Light.This issue affects canvasio3D Light: from n/a through 2.5.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34411&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34411" target="_blank">CVE-2024-34411</a><br><a href="https://patchstack.com/database/vulnerability/canvasio3d-light/wordpress-canvasio3d-light-plugin-2-5-0-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Thrive Themes--Thrive Theme Builder<br> </td>
<td>Improper Privilege Management vulnerability in Thrive Themes Thrive Theme Builder allows Privilege Escalation.This issue affects Thrive Theme Builder: from n/a before 3.24.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47782&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47782" target="_blank">CVE-2023-47782</a><br><a href="https://patchstack.com/database/vulnerability/thrive-theme/wordpress-thrive-theme-builder-theme-3-20-1-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThroughTek--Kalay SDK<br> </td>
<td>ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6324&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6324" target="_blank">CVE-2023-6324</a><br><a href="https://bitdefender.com/blog/labs/notes-on-throughtek-kalay-vulnerabilities-and-their-impact/" target="_blank">cve-requests@bitdefender.com</a></td>
</tr>
<tr>
<td>Timber Team &amp; Contributors--Timber<br> </td>
<td>Deserialization of Untrusted Data vulnerability in Timber Team &amp; Contributors Timber.This issue affects Timber: from n/a through 1.23.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29800&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29800" target="_blank">CVE-2024-29800</a><br><a href="https://patchstack.com/database/vulnerability/timber-library/wordpress-timber-plugin-1-23-0-deserialization-of-untrusted-data-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Tips and Tricks HQ--WP Express Checkout (Accept PayPal Payments)<br> </td>
<td>Improper Validation of Specified Quantity in Input vulnerability in Tips and Tricks HQ WP Express Checkout (Accept PayPal Payments) allows Manipulating Hidden Fields.This issue affects WP Express Checkout (Accept PayPal Payments): from n/a through 2.3.7.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30527&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30527" target="_blank">CVE-2024-30527</a><br><a href="https://patchstack.com/database/vulnerability/wp-express-checkout/wordpress-wp-express-checkout-plugin-2-3-7-price-manipulation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Trellix--ePolicy Orchestrator<br> </td>
<td>Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacker with admin privileges on the ePO server to read the contents of the orion.keystore file, allowing them to access the ePO database encryption key. This was possible through using a hard coded password for the keystore. Access Control restrictions on the file mean this would not be exploitable unless the user is the system admin for the server that ePO is running on.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4844&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4844" target="_blank">CVE-2024-4844</a><br><a href="https://thrive.trellix.com/s/article/000013505" target="_blank">trellixpsirt@trellix.com</a></td>
</tr>
<tr>
<td>URBAN BASE--Z-Downloads<br> </td>
<td>Unrestricted Upload of File with Dangerous Type vulnerability in URBAN BASE Z-Downloads.This issue affects Z-Downloads: from n/a through 1.11.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34555&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34555" target="_blank">CVE-2024-34555</a><br><a href="https://patchstack.com/database/vulnerability/z-downloads/wordpress-z-downloads-plugin-1-11-3-arbitrary-file-upload-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>UkrSolution--Barcode Scanner with Inventory &amp; Order Manager<br> </td>
<td>Improper Privilege Management vulnerability in UkrSolution Barcode Scanner with Inventory &amp; Order Manager allows Privilege Escalation.This issue affects Barcode Scanner with Inventory &amp; Order Manager: from n/a through 1.5.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33567&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33567" target="_blank">CVE-2024-33567</a><br><a href="https://patchstack.com/database/vulnerability/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/wordpress-barcode-scanner-with-inventory-order-manager-plugin-1-5-3-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Vova Anokhin--Shortcodes Ultimate<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vova Anokhin Shortcodes Ultimate allows Absolute Path Traversal.This issue affects Shortcodes Ultimate: from n/a through 5.12.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-25050&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-25050" target="_blank">CVE-2023-25050</a><br><a href="https://patchstack.com/database/vulnerability/shortcodes-ultimate/wordpress-shortcodes-ultimate-plugin-5-12-6-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Automatic--Automatic<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27954&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">9.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27954" target="_blank">CVE-2024-27954</a><br><a href="https://patchstack.com/database/vulnerability/wp-automatic/wordpress-automatic-plugin-3-92-0-unauthenticated-arbitrary-file-download-and-ssrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Automatic--Automatic<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in WP Automatic Automatic allows Privilege Escalation.This issue affects Automatic: from n/a through 3.92.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27955&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27955" target="_blank">CVE-2024-27955</a><br><a href="https://patchstack.com/database/vulnerability/wp-automatic/wordpress-automatic-plugin-3-92-0-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Hive--Events Rich Snippets for Google<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in WP Hive Events Rich Snippets for Google allows Exploitation of Trusted Credentials.This issue affects Events Rich Snippets for Google: from n/a through 1.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-44478&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-44478" target="_blank">CVE-2023-44478</a><br><a href="https://patchstack.com/database/vulnerability/rich-snippets-vevents/wordpress-events-rich-snippets-for-google-plugin-1-8-csrf-leading-to-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Sharks--s2Member Pro<br> </td>
<td>Improper Privilege Management vulnerability in WP Sharks s2Member Pro allows Privilege Escalation.This issue affects s2Member Pro: from n/a through 240315.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31237&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31237" target="_blank">CVE-2024-31237</a><br><a href="https://patchstack.com/database/vulnerability/s2member/wordpress-s2member-plugin-240315-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP-etracker--WP etracker<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-etracker WP etracker allows Reflected XSS.This issue affects WP etracker: from n/a through 1.0.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34431&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34431" target="_blank">CVE-2024-34431</a><br><a href="https://patchstack.com/database/vulnerability/wp-etracker/wordpress-wp-etracker-plugin-1-0-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPCustomify--Customify Site Library<br> </td>
<td>Improper Control of Generation of Code ('Code Injection') vulnerability in WPCustomify Customify Site Library allows Code Injection.This issue affects Customify Site Library: from n/a through 0.0.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33644&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33644" target="_blank">CVE-2024-33644</a><br><a href="https://patchstack.com/database/vulnerability/customify-sites/wordpress-customify-site-library-plugin-0-0-9-remote-code-execution-rce-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPDeveloper--Essential Addons for Elementor<br> </td>
<td>Improper Privilege Management vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.This issue affects Essential Addons for Elementor: from n/a through 5.8.8.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41955&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41955" target="_blank">CVE-2023-41955</a><br><a href="https://patchstack.com/database/vulnerability/essential-addons-for-elementor-lite/wordpress-essential-addons-for-elementor-plugin-5-8-8-contributor-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPFactory--EAN for WooCommerce<br> </td>
<td>Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34370&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34370" target="_blank">CVE-2024-34370</a><br><a href="https://patchstack.com/database/vulnerability/ean-for-woocommerce/wordpress-ean-for-woocommerce-plugin-4-8-9-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPvivid Team--WPvivid Backup and Migration<br> </td>
<td>Improper Privilege Management vulnerability in WPvivid Team WPvivid Backup and Migration allows Privilege Escalation.This issue affects WPvivid Backup and Migration: from n/a through 0.9.90.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41243&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41243" target="_blank">CVE-2023-41243</a><br><a href="https://patchstack.com/database/vulnerability/wpvivid-backuprestore/wordpress-wpvivid-backup-plugin-plugin-0-9-90-privilege-escalation-on-staging-environment-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WatchGuard--AuthPoint Password Manager<br> </td>
<td>Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoint Password Manager on MacOS allows an a adversary with local access to execute code under the context of the AuthPoint Password Manager application. This issue affects AuthPoint Password Manager for MacOS versions before 1.0.6.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1417&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1417" target="_blank">CVE-2024-1417</a><br><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00006" target="_blank">5d1c2695-1a31-4499-88ae-e847036fd7e3</a></td>
</tr>
<tr>
<td>WebToffee--WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels<br> </td>
<td>Improper Privilege Management vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Privilege Escalation.This issue affects WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels: from n/a through 4.2.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51546&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51546" target="_blank">CVE-2023-51546</a><br><a href="https://patchstack.com/database/vulnerability/print-invoices-packing-slip-labels-for-woocommerce/wordpress-woocommerce-pdf-invoices-packing-slips-delivery-notes-and-shipping-labels-plugin-4-2-1-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WebWizards--SalesKing<br> </td>
<td>Improper Privilege Management vulnerability in WebWizards SalesKing allows Privilege Escalation.This issue affects SalesKing: from n/a through 1.6.15.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22157&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22157" target="_blank">CVE-2024-22157</a><br><a href="https://patchstack.com/database/vulnerability/salesking/wordpress-salesking-plugin-1-6-15-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WebinarPress--WebinarPress<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress.This issue affects WebinarPress: from n/a through 1.33.17.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34818&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34818" target="_blank">CVE-2024-34818</a><br><a href="https://patchstack.com/database/vulnerability/wp-webinarsystem/wordpress-webinar-plugin-1-33-17-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WhatArmy--WatchTowerHQ<br> </td>
<td>Improper Privilege Management vulnerability in WhatArmy WatchTowerHQ allows Privilege Escalation.This issue affects WatchTowerHQ: from n/a through 3.6.16.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-25701&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-25701" target="_blank">CVE-2023-25701</a><br><a href="https://patchstack.com/database/vulnerability/watchtowerhq/wordpress-watchtowerhq-plugin-3-6-16-privilege-escalation?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Wholesale--WholesaleX<br> </td>
<td>Improper Privilege Management vulnerability in Wholesale WholesaleX allows Privilege Escalation.This issue affects WholesaleX: from n/a through 1.3.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30542&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30542" target="_blank">CVE-2024-30542</a><br><a href="https://patchstack.com/database/vulnerability/wholesalex/wordpress-wholesalex-plugin-1-3-2-unauthenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Woo product importer--Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy<br> </td>
<td>Missing Authorization vulnerability in Woo product importer Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy.This issue affects Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy: from n/a through 2.1.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32724&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32724" target="_blank">CVE-2024-32724</a><br><a href="https://patchstack.com/database/vulnerability/woo-aliexpress-dropshipping/wordpress-sharkdropship-and-affiliate-for-aliexpress-ebay-amazon-etsy-plugin-2-1-1-arbitrary-content-deletion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WooCommerce--WooCommerce One Page Checkout<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WooCommerce WooCommerce One Page Checkout allows PHP Local File Inclusion.This issue affects WooCommerce One Page Checkout: from n/a through 2.3.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-35881&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-35881" target="_blank">CVE-2023-35881</a><br><a href="https://patchstack.com/database/vulnerability/woocommerce-one-page-checkout/wordpress-woocommerce-one-page-checkout-plugin-2-3-0-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>XTemos--Woodmart Core<br> </td>
<td>Improper Privilege Management vulnerability in XTemos Woodmart Core allows Privilege Escalation.This issue affects Woodmart Core: from n/a through 1.0.36.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-32244&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-32244" target="_blank">CVE-2023-32244</a><br><a href="https://patchstack.com/database/vulnerability/woodmart-core/wordpress-woodmart-core-plugin-1-0-36-privilege-escalation?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>YARPP--YARPP<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YARPP allows PHP Local File Inclusion.This issue affects YARPP: from n/a through 5.30.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-45374&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-45374" target="_blank">CVE-2022-45374</a><br><a href="https://patchstack.com/database/vulnerability/yet-another-related-posts-plugin/wordpress-yet-another-related-posts-plugin-yarpp-plugin-5-30-2-local-file-inclusion?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>YMS--VIS Pro<br> </td>
<td>YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for system credentials generation and weak password policy, passwords can be easily guessed and enumerated through brute force attacks. Successful attacks can lead to unauthorised access and execution of operations based on assigned user permissions. This vulnerability affects VIS Pro in versions &lt;= 3.3.0.6. This vulnerability has been mitigated by changes in authentication mechanisms and implementation of additional authentication layer and strong password policies.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3263&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3263" target="_blank">CVE-2024-3263</a><br><a href="https://remediata.com/blog/cve-2024-3263-improper-authentication-in-yms-vis-pro/" target="_blank">incident@nbu.gov.sk</a><br><a href="https://www.svps.sk/vis/" target="_blank">incident@nbu.gov.sk</a></td>
</tr>
<tr>
<td>ZTE--ZXUN-ePDG<br> </td>
<td>ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during establishing a secure connection(IKE) with the mobile devices connecting over the internet . If the set of keys are leaked or cracked, the user session informations using the keys may be leaked.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22064&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" target="_blank" title="CVSS V3 Score">8.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22064" target="_blank">CVE-2024-22064</a><br><a href="https://support.zte.com.cn/support/news/LoopholeInfoDetail.aspx?newsId=1035524" target="_blank">psirt@zte.com.cn</a></td>
</tr>
<tr>
<td>Zabbix--Zabbix<br> </td>
<td>Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22120&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22120" target="_blank">CVE-2024-22120</a><br><a href="https://support.zabbix.com/browse/ZBX-24505" target="_blank">security@zabbix.com</a></td>
</tr>
<tr>
<td>abetlen--llama-cpp-python<br> </td>
<td>llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA, LoRa settings`, `loading tokenizers,` and `hardware settings`, `__init__` also loads the `chat template` from targeted `.gguf` 's Metadata and furtherly parses it to `llama_chat_format.Jinja2ChatFormatter.to_chat_handler()` to construct the `self.chat_handler` for this model. Nevertheless, `Jinja2ChatFormatter` parse the `chat template` within the Metadate with sandbox-less `jinja2.Environment`, which is furthermore rendered in `__call__` to construct the `prompt` of interaction. This allows `jinja2` Server Side Template Injection which leads to remote code execution by a carefully constructed payload.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34359&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34359" target="_blank">CVE-2024-34359</a><br><a href="https://github.com/abetlen/llama-cpp-python/commit/b454f40a9a1787b2b5659cd2cb00819d983185df" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/abetlen/llama-cpp-python/security/advisories/GHSA-56xg-wfcc-g829" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>alttextai--Alt Text AI Automatically generate image alt text for SEO and accessibility<br> </td>
<td>The Alt Text AI - Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to generic SQL Injection via the 'last_post_id' parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4847&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4847" target="_blank">CVE-2024-4847</a><br><a href="https://plugins.trac.wordpress.org/browser/alttext-ai/trunk/includes/class-atai-attachment.php#L677" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086107/" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/alttext-ai/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3c192623-eb46-4f1d-b897-433ac80608cb?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>appscreo--Easy Social Share Buttons<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in appscreo Easy Social Share Buttons allows PHP Local File Inclusion.This issue affects Easy Social Share Buttons: from n/a through 9.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31300&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31300" target="_blank">CVE-2024-31300</a><br><a href="https://patchstack.com/database/vulnerability/easy-social-share-buttons3/wordpress-easy-social-share-buttons-plugin-9-4-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>artbees--JupiterX<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in artbees JupiterX allows PHP Local File Inclusion.This issue affects JupiterX: from n/a through 3.0.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-32110&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-32110" target="_blank">CVE-2023-32110</a><br><a href="https://patchstack.com/database/vulnerability/jupiterx/wordpress-jupiterx-theme-3-0-0-subscriber-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>aws--amazon-redshift-jdbc-driver<br> </td>
<td>The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions. Prior to version 2.1.0.28, SQL injection is possible when using the non-default connection property `preferQueryMode=simple` in combination with application code which has a vulnerable SQL that negates a parameter value. There is no vulnerability in the driver when using the default, extended query mode. Note that `preferQueryMode` is not a supported parameter in Redshift JDBC driver, and is inherited code from Postgres JDBC driver. Users who do not override default settings to utilize this unsupported query mode are not affected. This issue is patched in driver version 2.1.0.28. As a workaround, do not use the connection property `preferQueryMode=simple`. (NOTE: Those who do not explicitly specify a query mode use the default of extended query mode and are not affected by this issue.)</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32888&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32888" target="_blank">CVE-2024-32888</a><br><a href="https://github.com/aws/amazon-redshift-jdbc-driver/commit/0d354a5f26ca23f7cac4e800e3b8734220230319" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/aws/amazon-redshift-jdbc-driver/commit/12a5e8ecfbb44c8154fc66041cca2e20ecd7b339" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/aws/amazon-redshift-jdbc-driver/commit/bc93694201a291493778ce5369a72befeca5ba7d" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/aws/amazon-redshift-jdbc-driver/security/advisories/GHSA-x3wm-hffr-chwm" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>dataease--dataease<br> </td>
<td>DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it is possible to exploit certain malicious parameters to achieve arbitrary file reading. The vulnerability has been fixed in v1.18.19.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31441&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31441" target="_blank">CVE-2024-31441</a><br><a href="https://github.com/dataease/dataease/security/advisories/GHSA-h7hj-7wg6-p5wh" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>dotmesh-io--dotmesh<br> </td>
<td>Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations outside the designated target folder. The routine `untarFile` attempts to guard against creating symbolic links that point outside the directory a tar archive is extracted to. However, a malicious tarball first linking `subdir/parent` to `..` (allowed, because `subdir/..` falls within the archive root) and then linking `subdir/parent/escapes` to `..` results in a symbolic link pointing to the tarball's parent directory, contrary to the routine's goals. This issue may lead to arbitrary file write (with same permissions as the program running the unpack operation) if the attacker can control the archive file. Additionally, if the attacker has read access to the unpacked files, they may be able to read arbitrary system files the parent process has permissions to read. As of time of publication, no patch for this issue is available.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2020-26312&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2020-26312" target="_blank">CVE-2020-26312</a><br><a href="https://github.com/dotmesh-io/dotmesh/blob/master/pkg/archiver/tar.go#L255" target="_blank">security-advisories@github.com</a><br><a href="https://securitylab.github.com/advisories/GHSL-2020-254-zipslip-dotmesh/" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>eProsima--Fast-DDS<br> </td>
<td>FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves a malformed `RTPS` packet, the subscriber crashes when creating `pthread`. This can remotely crash any Fast-DDS process, potentially leading to a DOS attack. Versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8 contain a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30258&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30258" target="_blank">CVE-2024-30258</a><br><a href="https://drive.google.com/file/d/19W5UC52hPnAqVq_boZWO45d1TJ4WoCSh/view?usp=sharing" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/eProsima/Fast-DDS/commit/65236f93e9c4ea3ff9a49fba4dfd9e43eb94037b" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-53xw-465j-rxfh" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>eProsima--Fast-DDS<br> </td>
<td>FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves malformed `RTPS` packet, heap buffer overflow occurs on the subscriber. This can remotely crash any Fast-DDS process, potentially leading to a DOS attack. Versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8 contain a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30259&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30259" target="_blank">CVE-2024-30259</a><br><a href="https://drive.google.com/file/d/1Y2bGvP3UIOJCLh_XEURLdhrM2Sznlvlp/view?usp=sharing" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-qcj9-939p-p662" target="_blank">security-advisories@github.com</a><br><a href="https://vimeo.com/907641887?share=copy" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>freescout-helpdesk--freescout<br> </td>
<td>FreeScout is a free, self-hosted help desk and shared mailbox. A stored HTML Injection vulnerability has been identified in the Email Receival Module of the Freescout Application. The vulnerability allows attackers to inject malicious HTML content into emails sent to the application's mailbox. This vulnerability arises from improper handling of HTML content within incoming emails, allowing attackers to embed malicious HTML code in the context of the application's domain. Unauthenticated attackers can exploit this vulnerability to inject malicious HTML content into emails. This could lead to various attacks such as form hijacking, application defacement, or data exfiltration via CSS injection. Although unauthenticated attackers are limited to HTML injection, the consequences can still be severe. Version 1.8.139 implements strict input validation and sanitization mechanisms to ensure that any HTML content received via emails is properly sanitized to prevent malicious HTML injections.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34697&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34697" target="_blank">CVE-2024-34697</a><br><a href="https://github.com/freescout-helpdesk/freescout/commit/99a4b4b4e153c82e273e549b9efbf6db4a2d8328" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/freescout-helpdesk/freescout/security/advisories/GHSA-985r-6qfc-hg8m" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>froxlor--Froxlor<br> </td>
<td>Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging Feature of the Froxlor Application. An unauthenticated User can inject malicious scripts in the loginname parameter on the Login attempt, which will then be executed when viewed by the Administrator in the System Logs. By exploiting this vulnerability, the attacker can perform various malicious actions such as forcing the Administrator to execute actions without their knowledge or consent. For instance, the attacker can force the Administrator to add a new administrator controlled by the attacker, thereby giving the attacker full control over the application. This vulnerability is fixed in 2.1.9.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34070&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34070" target="_blank">CVE-2024-34070</a><br><a href="https://github.com/froxlor/Froxlor/commit/a862307bce5cdfb1c208b835f3e8faddd23046e6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/froxlor/Froxlor/security/advisories/GHSA-x525-54hf-xr53" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>getgrav--grav<br> </td>
<td>Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using Twig Syntax. This includes Grav user account files - `/grav/user/accounts/*.yaml`. This file stores hashed user password, 2FA secret, and the password reset token. This can allow an adversary to compromise any registered account and read any file in the web server by resetting a password for a user to get access to the password reset token from the file or by cracking the hashed password. A low privileged user may also perform a full account takeover of other registered users including Administrators. Version 1.7.46 contains a patch.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34082&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L" target="_blank" title="CVSS V3 Score">8.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34082" target="_blank">CVE-2024-34082</a><br><a href="https://github.com/getgrav/grav/commit/b6bba9eb99bf8cb55b8fa8d23f18873ca594e348" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/getgrav/grav/security/advisories/GHSA-f8v5-jmfh-pr69" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>git--git<br> </td>
<td>Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is disabled in Git (e.g. via `git config --global core.symlinks false`), the described attack won't work. As always, it is best to avoid cloning repositories from untrusted sources.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32002&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32002" target="_blank">CVE-2024-32002</a><br><a href="https://git-scm.com/docs/git-clone#Documentation/git-clone.txt---recurse-submodulesltpathspecgt" target="_blank">security-advisories@github.com</a><br><a href="https://git-scm.com/docs/git-config#Documentation/git-config.txt-coresymlinks" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/commit/97065761333fd62db1912d81b489db938d8c991d" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/security/advisories/GHSA-8h77-4q3w-gfgv" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>git--git<br> </td>
<td>Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid cloning repositories from untrusted sources.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32004&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32004" target="_blank">CVE-2024-32004</a><br><a href="https://git-scm.com/docs/git-clone" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/commit/f4aa8c8bb11dae6e769cd930565173808cbb69c8" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/security/advisories/GHSA-xfc6-vwr8-r389" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>git--git<br> </td>
<td>Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the context of cloning local repositories owned by other users, this vulnerability has been covered in CVE-2024-32004. But there are circumstances where the fixes for CVE-2024-32004 are not enough: For example, when obtaining a `.zip` file containing a full copy of a Git repository, it should not be trusted by default to be safe, as e.g. hooks could be configured to run within the context of that repository. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround, avoid using Git in repositories that have been obtained via archives from untrusted sources.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32465&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32465" target="_blank">CVE-2024-32465</a><br><a href="https://git-scm.com/docs/git#_security" target="_blank">security-advisories@github.com</a><br><a href="https://git-scm.com/docs/git-clone" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/commit/7b70e9efb18c2cc3f219af399bd384c5801ba1d7" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/security/advisories/GHSA-vm9j-46j9-qvq4" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>google -- chrome<br> </td>
<td>Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4671&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4671" target="_blank">CVE-2024-4671</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/339266700" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>hakeemnala--Build App Online<br> </td>
<td>The Build App Online plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.21. This is due to missing authentication checking in the 'set_user_cart' function with the 'user_id' header value. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3658&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3658" target="_blank">CVE-2024-3658</a><br><a href="https://plugins.trac.wordpress.org/browser/build-app-online/tags/1.0.21/public/class-build-app-online-public.php#L814" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/65d423ad-da51-4616-860d-2b9354d44147?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>hoppscotch--hoppscotch-extension<br> </td>
<td>The Hoppscotch Browser Extension is a browser extension for Hoppscotch, a community-driven end-to-end open-source API development ecosystem. Due to an oversight during a change made to the extension in the commit d4e8e4830326f46ba17acd1307977ecd32a85b58, a critical check for the origin list was missed and allowed for messages to be sent to the extension which the extension gladly processed and responded back with the results of, while this wasn't supposed to happen and be blocked by the origin not being present in the origin list. This vulnerability exposes Hoppscotch Extension users to sites which call into Hoppscotch Extension APIs internally. This fundamentally allows any site running on the browser with the extension installed to bypass CORS restrictions if the user is running extensions with the given version. This security hole was patched in the commit 7e364b928ab722dc682d0fcad713a96cc38477d6 which was released along with the extension version `0.35`. As a workaround, Chrome users can use the Extensions Settings to disable the extension access to only the origins that you want. Firefox doesn't have an alternative to upgrading to a fixed version.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34714&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34714" target="_blank">CVE-2024-34714</a><br><a href="https://github.com/hoppscotch/hoppscotch-extension/commit/7e364b928ab722dc682d0fcad713a96cc38477d6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/hoppscotch/hoppscotch-extension/commit/d4e8e4830326f46ba17acd1307977ecd32a85b58" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/hoppscotch/hoppscotch-extension/security/advisories/GHSA-jjh5-pvqx-gg5v" target="_blank">security-advisories@github.com</a><br><a href="https://server.yadhu.in/poc/hoppscotch-poc.html" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>icegram--Email Subscribers by Icegram Express Email Marketing, Newsletters, Automation for WordPress &amp; WooCommerce<br> </td>
<td>The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the handle_ajax_request function in all versions up to, and including, 5.7.19. This makes it possible for authenticated attackers, with subscriber-level access and above, to cause a loss of confidentiality, integrity, and availability, by performing multiple unauthorized actions. Some of these actions could also be leveraged to conduct PHP Object Injection and SQL Injection attacks.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4010&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4010" target="_blank">CVE-2024-4010</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083762/email-subscribers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/23bfcdd1-b99d-47eb-9f88-96f9ecc53b32?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>jetmonsters--Hotel Booking Lite<br> </td>
<td>The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4413&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4413" target="_blank">CVE-2024-4413</a><br><a href="https://plugins.trac.wordpress.org/browser/motopress-hotel-booking-lite/trunk/includes/shortcodes/checkout-shortcode/step-checkout.php#L149" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3084187%40motopress-hotel-booking-lite%2Ftrunk&amp;old=3081058%40motopress-hotel-booking-lite%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1d7f1283-a274-49a2-8bec-da178771b13a?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>jottlieb--Last Viewed Posts by WPBeginner<br> </td>
<td>The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input from the LastViewedPosts Cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3070&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3070" target="_blank">CVE-2024-3070</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3062246%40last-viewed-posts&amp;new=3062246%40last-viewed-posts&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b6c5cc05-b147-46f6-aaa9-4c82aae1b544?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>kognetiks--Kognetiks Chatbot for WordPress<br> </td>
<td>The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the chatbot_chatgpt_upload_file_to_assistant function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers, with to upload arbitrary files on the affected site's server which may make remote code execution possible.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4560&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4560" target="_blank">CVE-2024-4560</a><br><a href="https://plugins.trac.wordpress.org/browser/chatbot-chatgpt/trunk/includes/utilities/chatbot-file-upload.php#L17" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7bc33a05-d462-492e-9ea5-cf37b887cc94?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>lobehub--lobe-chat<br> </td>
<td>Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32964&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32964" target="_blank">CVE-2024-32964</a><br><a href="https://github.com/lobehub/lobe-chat/commit/465665a735556669ee30446c7ea9049a20cc7c37" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/lobehub/lobe-chat/security/advisories/GHSA-mxhq-xw3g-rphc" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>mantisbt--mantisbt<br> </td>
<td>MantisBT (Mantis Bug Tracker) is an open source issue tracker. Insufficient access control in the registration and password reset process allows an attacker to reset another user's password and takeover their account, if the victim has an incomplete request pending. The exploit is only possible while the verification token is valid, i.e for 5 minutes after the confirmation URL sent by e-mail has been opened, and the user did not complete the process by updating their password. A brute-force attack calling account_update.php with increasing user IDs is possible. A successful takeover would grant the attacker full access to the compromised account, including sensitive information and functionalities associated with the account, the extent of which depends on its privileges and the data it has access to. Version 2.26.2 contains a patch for the issue. As a workaround, one may mitigate the risk by reducing the verification token's validity (change the value of the `TOKEN_EXPIRY_AUTHENTICATED` constant in `constants_inc.php`).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34077&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34077" target="_blank">CVE-2024-34077</a><br><a href="https://github.com/mantisbt/mantisbt/commit/92d11a01b195a1b6717a2f205218089158ea6d00" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/mantisbt/mantisbt/security/advisories/GHSA-93x3-m7pw-ppqm" target="_blank">security-advisories@github.com</a><br><a href="https://mantisbt.org/bugs/view.php?id=34433" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>metaphorcreations--Ditty Responsive News Tickers, Sliders, and Lists<br> </td>
<td>The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of untrusted input when adding a new ditty. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3954&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3954" target="_blank">CVE-2024-3954</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3081335%40ditty-news-ticker&amp;new=3081335%40ditty-news-ticker&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0f00b138-5c4b-4f75-94b1-82721cba2668?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>micromatch--braces<br> </td>
<td>The NPM package `braces` fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, which will cause the program to start allocating heap memory without freeing it at any moment of the loop. Eventually, the JavaScript heap limit is reached, and the program will crash.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4068&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4068" target="_blank">CVE-2024-4068</a><br><a href="https://devhub.checkmarx.com/cve-details/CVE-2024-4068/" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a><br><a href="https://github.com/micromatch/braces/blob/98414f9f1fabe021736e26836d8306d5de747e0d/lib/parse.js#L308" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a><br><a href="https://github.com/micromatch/braces/issues/35" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a></td>
</tr>
<tr>
<td>micromatch--micromatch<br> </td>
<td>The NPM package `micromatch` is vulnerable to Regular Expression Denial of Service (ReDoS). The vulnerability occurs in `micromatch.braces()` in `index.js` because the pattern `.*` will greedily match anything. By passing a malicious payload, the pattern matching will keep backtracking to the input while it doesn't find the closing bracket. As the input size increases, the consumption time will also increase until it causes the application to hang or slow down. There was a merged fix but further testing shows the issue persists. This issue should be mitigated by using a safe pattern that won't start backtracking the regular expression due to greedy matching.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4067&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4067" target="_blank">CVE-2024-4067</a><br><a href="https://devhub.checkmarx.com/cve-details/CVE-2024-4067/" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a><br><a href="https://github.com/micromatch/micromatch/blob/2c56a8604b68c1099e7bc0f807ce0865a339747a/index.js#L448" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a><br><a href="https://github.com/micromatch/micromatch/issues/243" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a><br><a href="https://github.com/micromatch/micromatch/pull/247" target="_blank">596c5446-0ce5-4ba2-aa66-48b3b757a647</a></td>
</tr>
<tr>
<td>microsoft -- windows_10_1507<br> </td>
<td>Windows MSHTML Platform Security Feature Bypass Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30040&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30040" target="_blank">CVE-2024-30040</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30040" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>microsoft -- windows_10_1507<br> </td>
<td>Windows DWM Core Library Elevation of Privilege Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30051&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30051" target="_blank">CVE-2024-30051</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30051" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>miniOrange--WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn)<br> </td>
<td>Improper Privilege Management vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Privilege Escalation.This issue affects WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn): from n/a through 7.6.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47683&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47683" target="_blank">CVE-2023-47683</a><br><a href="https://patchstack.com/database/vulnerability/miniorange-login-openid/wordpress-social-login-social-sharing-by-miniorange-plugin-7-6-6-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>monetizemore--Advanced Ads  Ad Manager &amp; AdSense<br> </td>
<td>The Advanced Ads plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.52.1 via deserialization of untrusted input in the 'placement_slug' parameter. This makes it possible for authenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2290&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2290" target="_blank">CVE-2024-2290</a><br><a href="https://plugins.trac.wordpress.org/browser/advanced-ads/trunk/modules/import-export/classes/import.php#L155" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3081914%40advanced-ads&amp;new=3081914%40advanced-ads&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f64336f7-ab2a-4e22-a76f-d077c51f9c57?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Arc(TM) &amp; Iris(R) Xe Graphics software<br> </td>
<td>Improper neutralization in some Intel(R) Arc(TM) &amp; Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent network access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21864&amp;vector=CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21864" target="_blank">CVE-2024-21864</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01053.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) BIOS Guard firmware<br> </td>
<td>Improper conditions check in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-27504&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-27504" target="_blank">CVE-2023-27504</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00814.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) BIOS Guard firmware<br> </td>
<td>Improper input validation in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-28402&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-28402" target="_blank">CVE-2023-28402</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00814.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) DTT software installers<br> </td>
<td>Exposure of resource to wrong sphere in some Intel(R) DTT software installers may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21813&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">7.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21813" target="_blank">CVE-2024-21813</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00984.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware<br> </td>
<td>Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-37341&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-37341" target="_blank">CVE-2022-37341</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00756.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA Framework software installers<br> </td>
<td>Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43748&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43748" target="_blank">CVE-2023-43748</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA software installers<br> </td>
<td>Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-24460&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-24460" target="_blank">CVE-2023-24460</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA software installers<br> </td>
<td>Improper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-40071&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40071" target="_blank">CVE-2023-40071</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA software installers<br> </td>
<td>Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43629&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43629" target="_blank">CVE-2023-43629</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Neural Compressor software<br> </td>
<td>Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22476&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">10</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22476" target="_blank">CVE-2024-22476</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01109.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>Buffer overflow in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38581&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38581" target="_blank">CVE-2023-38581</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>Improper neutralization in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-42773&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-42773" target="_blank">CVE-2023-42773</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>Improper access control in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45217&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45217" target="_blank">CVE-2023-45217</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>Use after free in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46691&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:H" target="_blank" title="CVSS V3 Score">7.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46691" target="_blank">CVE-2023-46691</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for macOS<br> </td>
<td>Improper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-40070&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40070" target="_blank">CVE-2023-40070</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for macOS<br> </td>
<td>Improper neutralization in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46689&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46689" target="_blank">CVE-2023-46689</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Stratix 10 and Intel(R) Agilex 7 FPGAs<br> </td>
<td>Unchecked return value in SDM firmware for Intel(R) Stratix 10 and Intel(R) Agilex 7 FPGAs before version 23.3 may allow an authenticated user to potentially enable denial of service via adjacent access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41092&amp;vector=CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">7.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41092" target="_blank">CVE-2023-41092</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01007.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) TDX module software<br> </td>
<td>Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45745&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45745" target="_blank">CVE-2023-45745</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01036.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Thunderbolt driver software<br> </td>
<td>Improper access control for some Intel(R) Thunderbolt driver software before version 89 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-37410&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-37410" target="_blank">CVE-2022-37410</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00916.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products<br> </td>
<td>Improper input validation in PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22382&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22382" target="_blank">CVE-2024-22382</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--UEFI firmware for some Intel(R) Server D50DNP Family products<br> </td>
<td>Improper input validation in PlatformVariableInitDxe driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22095&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22095" target="_blank">CVE-2024-22095</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--UEFI firmware for some Intel(R) Server D50DNP Family products<br> </td>
<td>Improper input validation in UserAuthenticationSmm driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23487&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23487" target="_blank">CVE-2024-23487</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--UEFI firmware for some Intel(R) Server D50FCP Family products<br> </td>
<td>Improper buffer restrictions in PlatformPfrDxe driver in UEFI firmware for some Intel(R) Server D50FCP Family products may allow a privileged user to enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23980&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23980" target="_blank">CVE-2024-23980</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--UEFI firmware for some Intel(R) Server M50FCP Family products<br> </td>
<td>Improper input validation in PfrSmiUpdateFw driver in UEFI firmware for some Intel(R) Server M50FCP Family products may allow a privileged user to enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24981&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24981" target="_blank">CVE-2024-24981</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows. Because it is possible to tamper with the directory and DLL files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (An attacker must already have user privileges)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31954&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31954" target="_blank">CVE-2024-31954</a><br><a href="https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31954/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--some Intel(R) PROSet/Wireless WiFi software for Windows<br> </td>
<td>Improper input validation for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38654&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38654" target="_blank">CVE-2023-38654</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>nautobot--nautobot<br> </td>
<td>Nautobot is a Network Source of Truth and Network Automation Platform. A Nautobot user with admin privileges can modify the `BANNER_TOP`, `BANNER_BOTTOM`, and `BANNER_LOGIN` configuration settings via the `/admin/constance/config/` endpoint. Normally these settings are used to provide custom banner text at the top and bottom of all Nautobot web pages (or specifically on the login page in the case of `BANNER_LOGIN`) but it was reported that an admin user can make use of these settings to inject arbitrary HTML, potentially exposing Nautobot users to security issues such as cross-site scripting (stored XSS). The vulnerability is fixed in Nautobot 1.6.22 and 2.2.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34707&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34707" target="_blank">CVE-2024-34707</a><br><a href="https://github.com/nautobot/nautobot/commit/4f0a66bd6307bfe0e0acb899233e0d4ad516f51c" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/nautobot/nautobot/commit/f640aedc69c848d3d1be57f0300fc40033ff6423" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/nautobot/nautobot/pull/5697" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/nautobot/nautobot/pull/5698" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/nautobot/nautobot/security/advisories/GHSA-r2hr-4v48-fjv3" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>nocodb--nocodb<br> </td>
<td>NocoDB is software for building databases as spreadsheets. Prior to 0.202.9, a stored cross-site scripting vulnerability exists within the Formula virtual cell comments functionality. The nc-gui/components/virtual-cell/Formula.vue displays a v-html tag with the value of "urls" whose contents are processed by the function replaceUrlsWithLink(). This function recognizes the pattern URI::(XXX) and creates a hyperlink tag &lt;a&gt; with href=XXX. However, it leaves all the other contents outside of the pattern URI::(XXX) unchanged. This vulnerability is fixed in 0.202.9.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-49781&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-49781" target="_blank">CVE-2023-49781</a><br><a href="https://github.com/nocodb/nocodb/commit/7f58ce3726dfec71537d8b80474a0f95a48a1574" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/nocodb/nocodb/security/advisories/GHSA-h6r4-xvw6-jc5h" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>npgsql--npgsql<br> </td>
<td>Npgsql is the .NET data provider for PostgreSQL. The `WriteBind()` method in `src/Npgsql/Internal/NpgsqlConnector.FrontendMessages.cs` uses `int` variables to store the message length and the sum of parameter lengths. Both variables overflow when the sum of parameter lengths becomes too large. This causes Npgsql to write a message size that is too small when constructing a Postgres protocol message to send it over the network to the database. When parsing the message, the database will only read a small number of bytes and treat any following bytes as new messages while they belong to the old message. Attackers can abuse this to inject arbitrary Postgres protocol messages into the connection, leading to the execution of arbitrary SQL statements on the application's behalf. This vulnerability is fixed in 4.0.14, 4.1.13, 5.0.18, 6.0.11, 7.0.7, and 8.0.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32655&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32655" target="_blank">CVE-2024-32655</a><br><a href="https://github.com/npgsql/npgsql/commit/091655eed0c84e502ab424950c930339d17c1928" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/3183efb2bdcca159c8c2e22af57e18ea8f853cf0" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/67acbe027e28477ac2199e15cfb554bb2ffaf169" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/703d9af8fa48dfe8c0180e36edb8278f34342d7b" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/a22a42d8141d7a3528f43c02c095a409507cf1af" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/e34e2ba8042e666d9af54a1b255fba4d5b11df56" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/commit/f7e7ead0702d776a8f551f5786c4cac2d65c4bc6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v4.0.14" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v4.1.13" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v5.0.18" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v6.0.11" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v7.0.7" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/releases/tag/v8.0.3" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/npgsql/npgsql/security/advisories/GHSA-x9vc-6hfv-hg8c" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>nvidia--ChatRTX<br> </td>
<td>NVIDIA ChatRTX for Windows contains a vulnerability in Chat RTX UI, where a user can cause an improper privilege management issue by sending user inputs to change execution flow. A successful exploit of this vulnerability might lead to information disclosure, escalation of privileges, and data tampering.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0096&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0096" target="_blank">CVE-2024-0096</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5533" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>nvidia--ChatRTX<br> </td>
<td>NVIDIA ChatRTX for Windows contains a vulnerability in ChatRTX UI, where a user can cause an improper privilege management issue by exploiting interprocess communication between different processes. A successful exploit of this vulnerability might lead to information disclosure, escalation of privileges, and data tampering.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0097&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0097" target="_blank">CVE-2024-0097</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5533" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>nvidia--NVIDIA Triton Inference Server<br> </td>
<td>NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, logs are appended to the file. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0087&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H" target="_blank" title="CVSS V3 Score">9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0087" target="_blank">CVE-2024-0087</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5535" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>pencidesign--Penci Soledad Data Migrator<br> </td>
<td>The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.0 via the 'data' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included. This is limited to just PHP files.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3551&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3551" target="_blank">CVE-2024-3551</a><br><a href="https://themeforest.net/item/soledad-multiconcept-blogmagazine-wp-theme/12945398" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a4f8df3a-f247-4365-a9f6-6124065b4883?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>plainware--ShiftController Employee Shift Scheduling<br> </td>
<td>The ShiftController Employee Shift Scheduling plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the `hc3_session`-cookie in versions up to, and including, 4.9.57. This makes it possible for an authenticated attacker with contributor access-level or above to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4733&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4733" target="_blank">CVE-2024-4733</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3087047%40shiftcontroller%2Ftrunk&amp;old=3080165%40shiftcontroller%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9c8ab916-240d-43c3-92d4-7efd75862a5e?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>plugins360--All-in-One Video Gallery<br> </td>
<td>The All-in-One Video Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.5 via the aiovg_search_form shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4670&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4670" target="_blank">CVE-2024-4670</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085217/all-in-one-video-gallery" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e2793547-5edf-4d2a-bc3b-fcaeed62963d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>powerfulwp--Local Delivery Drivers for WooCommerce<br> </td>
<td>Improper Privilege Management vulnerability in powerfulwp Local Delivery Drivers for WooCommerce allows Privilege Escalation.This issue affects Local Delivery Drivers for WooCommerce: from n/a through 1.9.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51481&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51481" target="_blank">CVE-2023-51481</a><br><a href="https://patchstack.com/database/vulnerability/local-delivery-drivers-for-woocommerce/wordpress-local-delivery-drivers-for-woocommerce-plugin-1-9-0-unauthenticated-account-takeover-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ravanh--XML Sitemap &amp; Google News<br> </td>
<td>The XML Sitemap &amp; Google News plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.8 via the 'feed' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4441&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4441" target="_blank">CVE-2024-4441</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3082081%40xml-sitemap-feed&amp;new=3082081%40xml-sitemap-feed&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/87888350-1230-4fec-9de2-c58fa24e6a05?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>smp7, wp.insider--Simple Membership<br> </td>
<td>Improper Authentication vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.3.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41956&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41956" target="_blank">CVE-2023-41956</a><br><a href="https://patchstack.com/database/vulnerability/simple-membership/wordpress-simple-membership-plugin-4-3-4-authenticated-account-takeover-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>smp7, wp.insider--Simple Membership<br> </td>
<td>Improper Privilege Management vulnerability in smp7, wp.Insider Simple Membership allows Privilege Escalation.This issue affects Simple Membership: from n/a through 4.3.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41957&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L" target="_blank" title="CVSS V3 Score">8.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41957" target="_blank">CVE-2023-41957</a><br><a href="https://patchstack.com/database/vulnerability/simple-membership/wordpress-simple-membership-plugin-4-3-4-unauthenticated-membership-role-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>spacemeshos--go-spacemesh<br> </td>
<td>go-spacemesh is a Go implementation of the Spacemesh protocol full node. Nodes can publish activations transactions (ATXs) which reference the incorrect previous ATX of the Smesher that created the ATX. ATXs are expected to form a single chain from the newest to the first ATX ever published by an identity. Allowing Smeshers to reference an earlier (but not the latest) ATX as previous breaks this protocol rule and can serve as an attack vector where Nodes are rewarded for holding their PoST data for less than one epoch but still being eligible for rewards. This vulnerability is fixed in go-spacemesh 1.5.2-hotfix1 and Spacemesh API 1.37.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34360&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">8.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34360" target="_blank">CVE-2024-34360</a><br><a href="https://github.com/spacemeshos/api/commit/1d5bd972bbe225d024c3e0ae5214ddb6b481716e" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/spacemeshos/go-spacemesh/commit/9aff88d54be809ac43d60e8a8b4d65359c356b87" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/spacemeshos/go-spacemesh/security/advisories/GHSA-jcqq-g64v-gcm7" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>spoonthemes--Adifier System<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spoonthemes Adifier System allows PHP Local File Inclusion.This issue affects Adifier System: from n/a before 3.1.4.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-49753&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-49753" target="_blank">CVE-2023-49753</a><br><a href="https://patchstack.com/database/vulnerability/adifier-system/wordpress-adifier-classified-ads-wordpress-theme-theme-3-9-3-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>stalwartlabs--mail-server<br> </td>
<td>Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execution as the stalwart-mail user (including web interface admins) can gain complete root access to the system. Usually, system services are run as a separate user (not as root) to isolate an attacker with Arbitrary Code Execution to the current service. Therefore, other system services and the system itself remains protected in case of a successful attack. stalwart-mail runs as a separate user, but it can give itself full privileges again in a simple way, so this protection is practically ineffective. Server admins who handed out the admin credentials to the mail server, but didn't want to hand out complete root access to the system, as well as any attacked user when the attackers gained Arbitrary Code Execution using another vulnerability, may be vulnerable. Version 0.8.0 contains a patch for the issue.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35187&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35187" target="_blank">CVE-2024-35187</a><br><a href="https://github.com/stalwartlabs/mail-server/security/advisories/GHSA-rwp5-f854-ppg6" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>strongSwan--strongSwan<br> </td>
<td>strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate clients in TLS-based EAP methods, the IKE or EAP identity supplied by a client is not enforced to be contained in the client's certificate. So clients can authenticate with any trusted certificate and claim an arbitrary IKE/EAP identity as their own. This is problematic if the identity is used to make policy decisions. A fix was released in strongSwan version 5.9.6 in August 2022 (e4b4aabc4996fc61c37deab7858d07bc4d220136).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-4967&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-4967" target="_blank">CVE-2022-4967</a><br><a href="https://github.com/strongswan/strongswan/commit/e4b4aabc4996fc61c37deab7858d07bc4d220136" target="_blank">security@ubuntu.com</a><br><a href="https://www.cve.org/CVERecord?id=CVE-2022-4967" target="_blank">security@ubuntu.com</a><br><a href="https://www.strongswan.org/blog/2024/05/13/strongswan-vulnerability-(cve-2022-4967).html" target="_blank">security@ubuntu.com</a></td>
</tr>
<tr>
<td>supsystic.com--Popup by Supsystic<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path Traversal.This issue affects Popup by Supsystic: from n/a through 1.10.19.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46197&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46197" target="_blank">CVE-2023-46197</a><br><a href="https://patchstack.com/database/vulnerability/popup-by-supsystic/wordpress-popup-by-supsystic-plugin-1-10-19-unauthenticated-subscriber-email-addresses-disclosure?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>techjewel--Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder<br> </td>
<td>The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to grant users with Fluent Form management permissions which gives them access to all of the plugin's settings and features. This also makes it possible for unauthenticated attackers to delete manager accounts.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2771&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2771" target="_blank">CVE-2024-2771</a><br><a href="https://plugins.trac.wordpress.org/changeset/3088078/fluentform/trunk/app/Http/Policies/RoleManagerPolicy.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/071195d6-3452-4241-a8d3-92efc84e4850?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>techjewel--Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder<br> </td>
<td>The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to modify all of the plugin's settings.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2782&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2782" target="_blank">CVE-2024-2782</a><br><a href="https://plugins.trac.wordpress.org/changeset/3088078/fluentform/trunk/app/Http/Policies/GlobalSettingsPolicy.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0814e7b3-404a-4db5-b564-46c9086ec048?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>techjewel--Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder<br> </td>
<td>The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' parameter in versions up to, and including, 5.1.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, and access granted by an administrator, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4709&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4709" target="_blank">CVE-2024-4709</a><br><a href="https://plugins.trac.wordpress.org/browser/fluentform/trunk/app/Services/FormBuilder/Notifications/EmailNotification.php#L106" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/fluentform/trunk/app/Services/FormBuilder/Notifications/EmailNotification.php#L164" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/fluentform/trunk/app/Services/FormBuilder/Notifications/EmailNotification.php#L194" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3088078/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5fe317a6-a391-441a-aac8-c8fa57e73169?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themeisle--Visualizer: Tables and Charts Manager for WordPress<br> </td>
<td>The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability check on the getQueryData() function in all versions up to, and including, 3.10.15. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform arbitrary SQL queries that can be leveraged for privilege escalation among many other actions.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3750&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3750" target="_blank">CVE-2024-3750</a><br><a href="https://plugins.trac.wordpress.org/browser/visualizer/trunk/classes/Visualizer/Module/Chart.php#L1421" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086048/visualizer/tags/3.11.0/classes/Visualizer/Module/Chart.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086048/visualizer/tags/3.11.0/classes/Visualizer/Source/Query.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6d27544c-97a5-42cd-ab07-358f819acbc4?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themeum--Tutor LMS eLearning and online course solution<br> </td>
<td>The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to add, modify, or delete data.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4223&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4223" target="_blank">CVE-2024-4223</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086489/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ce4c4395-6d1a-4d5f-885f-383e5c44c0f8?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themeum--Tutor LMS eLearning and online course solution<br> </td>
<td>The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the 'question_id' parameter in versions up to, and including, 2.7.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Instructor-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4318&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4318" target="_blank">CVE-2024-4318</a><br><a href="https://plugins.trac.wordpress.org/browser/tutor/tags/2.7.0/classes/Utils.php#L4456" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/tutor/tags/2.7.0/classes/Utils.php#L4575" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086489/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9bbb3c65-f02c-4d6d-bd4e-b3232af5e21b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themium--Tutor LMS Pro<br> </td>
<td>The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' function in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to gain control of an existing administrator account.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4351&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4351" target="_blank">CVE-2024-4351</a><br><a href="https://www.themeum.com/product/tutor-lms/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/59859583-49e5-4a80-8659-b9ca7ddc089d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themium--Tutor LMS Pro<br> </td>
<td>The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'get_calendar_materials' function. The plugin is also vulnerable to SQL Injection via the 'year' parameter of that function due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4352&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4352" target="_blank">CVE-2024-4352</a><br><a href="https://www.themeum.com/product/tutor-lms/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c647beda-cf73-4372-975f-a8c8ed05217f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themium--Tutor LMS Pro<br> </td>
<td>The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to add, modify, or delete user meta and plugin options.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4222&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4222" target="_blank">CVE-2024-4222</a><br><a href="https://www.themeum.com/product/tutor-lms/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/942fffb6-2719-4b70-9759-21b2d50002c5?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thimpress--LearnPress WordPress LMS Plugin<br> </td>
<td>The LearnPress - WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'term_id' parameter in versions up to, and including, 4.2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4434&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4434" target="_blank">CVE-2024-4434</a><br><a href="https://inky-knuckle-2c2.notion.site/Unauthenticated-SQLI-in-Learnpress-plugin-Latest-Version-4-2-6-5-a86fe63bcc7b4c9988802688211817fd?pvs=25" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.6.5/inc/Databases/class-lp-course-db.php#L508" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082204/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2d64e1c6-1e25-4438-974d-b7da0979cc40?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thimpress--LearnPress WordPress LMS Plugin<br> </td>
<td>The LearnPress - WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_post_materials' function in versions up to, and including, 4.2.6.5. This makes it possible for authenticated attackers, with Instructor-level permissions and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4397&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4397" target="_blank">CVE-2024-4397</a><br><a href="https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.6.5/inc/rest-api/v1/frontend/class-lp-rest-material-controller.php#L98" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083657/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ec20d5c4-4c41-4ec9-8d0a-ec8f03634f7d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>unitecms--Unlimited Elements For Elementor (Free Widgets, Addons, Templates)<br> </td>
<td>The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up to, and including, 1.5.102 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3055&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">8.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3055" target="_blank">CVE-2024-3055</a><br><a href="https://plugins.trac.wordpress.org/browser/unlimited-elements-for-elementor/tags/1.5.93/inc_php/framework/db.class.php#L238" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3081509%40unlimited-elements-for-elementor%2Ftrunk&amp;old=3076456%40unlimited-elements-for-elementor%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ebc0c8e6-a365-4ef7-9c1a-41454855096c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>unitecms--Unlimited Elements For Elementor (Free Widgets, Addons, Templates)<br> </td>
<td>The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to command injection in all versions up to, and including, 1.5.102. This is due to insufficient filtering of template attributes during the creation of HTML for custom widgets This makes it possible for authenticated attackers, with administrator-level access and above, to execute arbitrary commands on the server.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2662&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2662" target="_blank">CVE-2024-2662</a><br><a href="https://plugins.trac.wordpress.org/changeset/3071404/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_template_engine.class.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/58492dbb-b9e0-4477-b85d-ace06dba954c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>valtimo-platform--valtimo-frontend-libraries<br> </td>
<td>Valtimo is an open source business process and case management platform. When opening a form in Valtimo, the access token (JWT) of the user is exposed to `api.form.io` via the the `x-jwt-token` header. An attacker can retrieve personal information from this token, or use it to execute requests to the Valtimo REST API on behalf of the logged-in user. This issue is caused by a misconfiguration of the Form.io component. The following conditions have to be met in order to perform this attack: An attacker needs to have access to the network traffic on the `api.form.io` domain; the content of the `x-jwt-token` header is logged or otherwise available to the attacker; an attacker needs to have network access to the Valtimo API; and an attacker needs to act within the time-to-live of the access token. The default TTL in Keycloak is 5 minutes. Versions 10.8.4, 11.1.6 and 11.2.2 have been patched.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34706&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">9.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34706" target="_blank">CVE-2024-34706</a><br><a href="https://github.com/valtimo-platform/valtimo-frontend-libraries/commit/1aaba5ef5750dafebbc7476fb08bf2375a25f19e" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/valtimo-platform/valtimo-frontend-libraries/commit/8c2dbf2a41180d2b0358d878290e4d37168f0fb6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/valtimo-platform/valtimo-frontend-libraries/commit/d65e05fd2784bd4a628778b34a5b79ce2f0cef8c" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/valtimo-platform/valtimo-frontend-libraries/security/advisories/GHSA-xcp4-62vj-cq3r" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>vendor or project--product name<br> </td>
<td>A potential vulnerability has been identified for OpenText Operations Bridge Reporter. The vulnerability could be exploited to inject malicious SQL queries. An attack requires to be an authenticated administrator of OBR with network access to the OBR web application.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2021-22508&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-22508" target="_blank">CVE-2021-22508</a><br><a href="https://support.microfocus.com/kb/kmdoc.php?id=KM03793174" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>vercel--next.js<br> </td>
<td>Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by Next.js, leading to desynchronized responses. This led to a response queue poisoning vulnerability in the affected Next.js versions. For a request to be exploitable, the affected route also had to be making use of the [rewrites](https://nextjs.org/docs/app/api-reference/next-config-js/rewrites) feature in Next.js. The vulnerability is resolved in Next.js `13.5.1` and newer.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34350&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34350" target="_blank">CVE-2024-34350</a><br><a href="https://github.com/vercel/next.js/security/advisories/GHSA-77r5-gw3j-2mpf" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>vercel--next.js<br> </td>
<td>Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was identified in Next.js Server Actions. If the `Host` header is modified, and the below conditions are also met, an attacker may be able to make requests that appear to be originating from the Next.js application server itself. The required conditions are 1) Next.js is running in a self-hosted manner; 2) the Next.js application makes use of Server Actions; and 3) the Server Action performs a redirect to a relative path which starts with a `/`. This vulnerability was fixed in Next.js `14.1.1`.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34351&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">7.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34351" target="_blank">CVE-2024-34351</a><br><a href="https://github.com/vercel/next.js/commit/8f7a6ca7d21a97bc9f7a1bbe10427b5ad74b9085" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/vercel/next.js/pull/62561" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/vercel/next.js/security/advisories/GHSA-fr5h-rqp8-mj6g" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>weDevs--WP User Frontend<br> </td>
<td>Improper Privilege Management vulnerability in weDevs WP User Frontend allows Privilege Escalation.This issue affects WP User Frontend: from n/a through 3.6.5.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47682&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">7.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47682" target="_blank">CVE-2023-47682</a><br><a href="https://patchstack.com/database/vulnerability/wp-user-frontend/wordpress-wp-user-frontend-plugin-3-6-5-authenticated-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>wpForo--wpForo Forum<br> </td>
<td>Improper Privilege Management vulnerability in wpForo wpForo Forum allows Privilege Escalation.This issue affects wpForo Forum: from n/a through 2.2.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47868&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">7.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47868" target="_blank">CVE-2023-47868</a><br><a href="https://patchstack.com/database/vulnerability/wpforo/wordpress-wpforo-plugin-2-2-3-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
</tbody>
</table>
<p><a href="https://www.cisa.gov/#top">Back to top</a></p>
</div>
<div>
<h2>Medium Vulnerabilities</h2>
<table summary="Medium Vulnerabilities" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th scope="col" role="columnheader" data-tablesaw-priority="persist">Primary<br>Vendor -- Product</th>
<th scope="col" role="columnheader">Description</th>
<th scope="col" role="columnheader">Published</th>
<th scope="col" role="columnheader">CVSS Score</th>
<th scope="col" role="columnheader">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>10Web Form Builder Team--Form Maker by 10Web<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Stored XSS.This issue affects Form Maker by 10Web: from n/a through 1.15.24.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34437&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34437" target="_blank">CVE-2024-34437</a><br><a href="https://patchstack.com/database/vulnerability/form-maker/wordpress-form-maker-by-10web-plugin-1-15-24-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>1Panel-dev--1Panel<br> </td>
<td>1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. The mirror configuration write symbol `&gt;` can be used to achieve arbitrary file writing. This vulnerability is fixed in v1.10.3-lts.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34352&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34352" target="_blank">CVE-2024-34352</a><br><a href="https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-f8ch-w75v-c847" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>ABB--RobotWare 6<br> </td>
<td>An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible. The vulnerability could potentially be exploited to perform unauthorized actions by an attacker. This vulnerability arises under specific condition when specially crafted message is processed by the system. Below are reported vulnerabilities in the Robot Ware versions. * IRC5- RobotWare 6 &lt; 6.15.06 except 6.10.10, and 6.13.07 * OmniCore- RobotWare 7 &lt; 7.14</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1914&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1914" target="_blank">CVE-2024-1914</a><br><a href="https://search.abb.com/library/Download.aspx?DocumentID=SI20330&amp;LanguageCode=en&amp;DocumentPartId=&amp;Action=Launch" target="_blank">cybersecurity@ch.abb.com</a></td>
</tr>
<tr>
<td>AREOI--All Bootstrap Blocks<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AREOI All Bootstrap Blocks allows Stored XSS.This issue affects All Bootstrap Blocks: from n/a through 1.3.15.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35169&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35169" target="_blank">CVE-2024-35169</a><br><a href="https://patchstack.com/database/vulnerability/all-bootstrap-blocks/wordpress-all-bootstrap-blocks-plugin-1-3-15-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>AROX SOLUTION--School ERP Pro+Responsive<br> </td>
<td>Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the username and password parameters in '/index.php'. This vulnerability allows an attacker to partially take control of the victim's browser session.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4822&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4822" target="_blank">CVE-2024-4822</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-school-erp-proresponsive-arox-solution" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>AROX SOLUTION--School ERP Pro+Responsive<br> </td>
<td>Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the index '/schoolerp/office_admin/' in the parameters es_bankacc, es_bank_name, es_bank_pin, es_checkno, es_teller_number, dc1 and dc2. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4823&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4823" target="_blank">CVE-2024-4823</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-school-erp-proresponsive-arox-solution" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Academy LMS--Academy LMS<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Academy LMS: from n/a through 1.9.25.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35171&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35171" target="_blank">CVE-2024-35171</a><br><a href="https://patchstack.com/database/vulnerability/academy/wordpress-academy-lms-plugin-1-9-25-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Adam DeHaven--Perfect Pullquotes<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam DeHaven Perfect Pullquotes allows Stored XSS.This issue affects Perfect Pullquotes: from n/a through 1.7.5.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33951&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33951" target="_blank">CVE-2024-33951</a><br><a href="https://patchstack.com/database/vulnerability/perfect-pullquotes/wordpress-perfect-pullquotes-plugin-1-7-5-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30311&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30311" target="_blank">CVE-2024-30311</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30312&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30312" target="_blank">CVE-2024-30312</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Acrobat Reader<br> </td>
<td>Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34101&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34101" target="_blank">CVE-2024-34101</a><br><a href="https://helpx.adobe.com/security/products/acrobat/apsb24-29.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30283&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30283" target="_blank">CVE-2024-30283</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30286&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30286" target="_blank">CVE-2024-30286</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Adobe Framemaker<br> </td>
<td>Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30287&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30287" target="_blank">CVE-2024-30287</a><br><a href="https://helpx.adobe.com/security/products/framemaker/apsb24-37.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Animate<br> </td>
<td>Animate versions 24.0.2, 23.0.5 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30298&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30298" target="_blank">CVE-2024-30298</a><br><a href="https://helpx.adobe.com/security/products/animate/apsb24-36.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Illustrator<br> </td>
<td>Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20793&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20793" target="_blank">CVE-2024-20793</a><br><a href="https://helpx.adobe.com/security/products/illustrator/apsb24-30.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Substance3D - Designer<br> </td>
<td>Substance3D - Designer versions 13.1.1 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30281&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30281" target="_blank">CVE-2024-30281</a><br><a href="https://helpx.adobe.com/security/products/substance3d_designer/apsb24-35.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Substance3D - Painter<br> </td>
<td>Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30308&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30308" target="_blank">CVE-2024-30308</a><br><a href="https://helpx.adobe.com/security/products/substance3d_painter/apsb24-31.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Adobe--Substance3D - Painter<br> </td>
<td>Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30309&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30309" target="_blank">CVE-2024-30309</a><br><a href="https://helpx.adobe.com/security/products/substance3d_painter/apsb24-31.html" target="_blank">psirt@adobe.com</a></td>
</tr>
<tr>
<td>Aleksei Polechin (alek)--Archives Calendar Widget<br> </td>
<td>Administrator Cross Site Scripting (XSS) in Archives Calendar Widget &lt;= 1.0.15 versions.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33950&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33950" target="_blank">CVE-2024-33950</a><br><a href="https://patchstack.com/database/vulnerability/archives-calendar-widget/wordpress-archives-calendar-widget-plugin-1-0-15-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>AlexaCRM--Dynamics 365 Integration<br> </td>
<td>Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365 Integration.This issue affects Dynamics 365 Integration: from n/a through 1.3.17.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34550&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34550" target="_blank">CVE-2024-34550</a><br><a href="https://patchstack.com/database/vulnerability/integration-dynamics/wordpress-dynamics-365-integration-plugin-1-3-17-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Andy Moyle--Church Admin<br> </td>
<td>Missing Authorization vulnerability in Andy Moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through 4.1.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31281&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31281" target="_blank">CVE-2024-31281</a><br><a href="https://patchstack.com/database/vulnerability/church-admin/wordpress-church-admin-plugin-4-1-6-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Andy Moyle--Church Admin<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.1.32.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34828&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34828" target="_blank">CVE-2024-34828</a><br><a href="https://patchstack.com/database/vulnerability/church-admin/wordpress-church-admin-plugin-4-1-32-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>AppPresser Team--AppPresser<br> </td>
<td>Missing Authorization vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32776&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32776" target="_blank">CVE-2024-32776</a><br><a href="https://patchstack.com/database/vulnerability/apppresser/wordpress-apppresser-plugin-4-3-0-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Artbees--SellKit<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Artbees SellKit allows Relative Path Traversal.This issue affects SellKit: from n/a through 1.8.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30509&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30509" target="_blank">CVE-2024-30509</a><br><a href="https://patchstack.com/database/vulnerability/sellkit/wordpress-sellkit-plugin-1-8-1-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Atanas Yonkov--Pliska<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atanas Yonkov Pliska allows Stored XSS.This issue affects Pliska: from n/a through 0.3.5.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33954&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33954" target="_blank">CVE-2024-33954</a><br><a href="https://patchstack.com/database/vulnerability/pliska/wordpress-pliska-theme-0-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Automattic--WP Job Manager<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n/a through 2.2.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34549&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34549" target="_blank">CVE-2024-34549</a><br><a href="https://patchstack.com/database/vulnerability/wp-job-manager/wordpress-wp-job-manager-plugin-2-2-2-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>BdThemes--Ultimate Store Kit Elementor Addons<br> </td>
<td>Deserialization of Untrusted Data vulnerability in BdThemes Ultimate Store Kit Elementor Addons.This issue affects Ultimate Store Kit Elementor Addons: from n/a through 1.6.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4606&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4606" target="_blank">CVE-2024-4606</a><br><a href="https://patchstack.com/database/vulnerability/ultimate-store-kit/wordpress-ultimate-store-kit-elementor-addons-woocommerce-builder-edd-builder-plugin-1-6-2-php-object-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Benoti--Brozzme Scroll Top<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benoti Brozzme Scroll Top allows Stored XSS.This issue affects Brozzme Scroll Top: from n/a through 1.8.5.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34426&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34426" target="_blank">CVE-2024-34426</a><br><a href="https://patchstack.com/database/vulnerability/brozzme-scroll-top/wordpress-brozzme-scroll-top-plugin-1-8-5-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>BestWebSoft--Captcha by BestWebSoft<br> </td>
<td>Guessable CAPTCHA vulnerability in BestWebSoft Captcha by BestWebSoft allows Functionality Bypass.This issue affects Captcha by BestWebSoft: from n/a through 5.2.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31295&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31295" target="_blank">CVE-2024-31295</a><br><a href="https://patchstack.com/database/vulnerability/captcha-bws/wordpress-captcha-by-bestwebsoft-plugin-5-2-0-captcha-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>BetterAddons--Better Elementor Addons<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BetterAddons Better Elementor Addons better-elementor-addons allows Stored XSS.This issue affects Better Elementor Addons: from n/a through 1.4.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34432&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34432" target="_blank">CVE-2024-34432</a><br><a href="https://patchstack.com/database/vulnerability/better-elementor-addons/wordpress-better-elementor-addons-plugin-1-4-4-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Bootstrapped Ventures--Easy Affiliate Links<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bootstrapped Ventures Easy Affiliate Links allows Stored XSS.This issue affects Easy Affiliate Links: from n/a through 3.7.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34441&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34441" target="_blank">CVE-2024-34441</a><br><a href="https://patchstack.com/database/vulnerability/easy-affiliate-links/wordpress-easy-affiliate-links-plugin-3-7-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Brainstorm Force--Ultimate Addons for Beaver Builder<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder allows Relative Path Traversal.This issue affects Ultimate Addons for Beaver Builder: from n/a through 1.35.13.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-51401&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-51401" target="_blank">CVE-2023-51401</a><br><a href="https://patchstack.com/database/vulnerability/bb-ultimate-addon/wordpress-ultimate-addons-for-beaver-builder-premium-plugin-1-35-13-limited-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Byzoro--Smart S200 Management Platform<br> </td>
<td>A vulnerability was found in Byzoro Smart S200 Management Platform up to 20240507. It has been rated as critical. This issue affects some unknown processing of the file /useratte/userattestation.php. The manipulation of the argument web_img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264437 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4904&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4904" target="_blank">CVE-2024-4904</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/upload.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264437" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264437" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.330636" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>CRM Perks--Integration for Contact Form 7 HubSpot<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 HubSpot.This issue affects Integration for Contact Form 7 HubSpot: from n/a through 1.3.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34756&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34756" target="_blank">CVE-2024-34756</a><br><a href="https://patchstack.com/database/vulnerability/cf7-hubspot/wordpress-integration-for-hubspot-and-contact-form-7-plugin-1-3-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CRM Perks--Integration for Contact Form 7 and Salesforce<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Contact Form 7 and Salesforce.This issue affects Integration for Contact Form 7 and Salesforce: from n/a through 1.3.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34755&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34755" target="_blank">CVE-2024-34755</a><br><a href="https://patchstack.com/database/vulnerability/cf7-salesforce/wordpress-integration-for-salesforce-and-contact-form-7-wpforms-elementor-formidable-ninja-forms-plugin-1-3-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CRM Perks--Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.2.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34817&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34817" target="_blank">CVE-2024-34817</a><br><a href="https://patchstack.com/database/vulnerability/integration-for-contact-form-7-and-pipedrive/wordpress-integration-for-pipedrive-and-contact-form-7-wpforms-elementor-ninja-forms-plugin-1-2-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. A reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows attackers to obtain cookies of administrator and other users and fake their login using obtained cookies. This issue is fixed in commit a38b9046e9772612fda847b46308f9391a49891e.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30268&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30268" target="_blank">CVE-2024-30268</a><br><a href="https://github.com/Cacti/cacti/blob/08497b8bcc6a6037f7b1aae303ad8f7dfaf7364e/settings.php#L66" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/commit/a38b9046e9772612fda847b46308f9391a49891e" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-9m3v-whmr-pc2q" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_nodes()` function from `lib/api_automation.php` , finally resulting in SQL injection. Using SQL based secondary injection technology, attackers can modify the contents of the Cacti database, and based on the modified content, it may be possible to achieve further impact, such as arbitrary file reading, and even remote code execution through arbitrary file writing. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31460&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31460" target="_blank">CVE-2024-31460</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-cx8g-hvq8-p2rv" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-gj3f-p326-gh8r" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js to fix CVE-2023-50250 (among others). However, it still generates the code out of unescaped PHP variables `$title` and `$header`. If those variables contain single quotes, they can be used to inject JavaScript code. An attacker exploiting this vulnerability could execute actions on behalf of other users. This ability to impersonate users could lead to unauthorized changes to settings. Version 1.2.27 fixes this issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29894&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29894" target="_blank">CVE-2024-29894</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-grj5-8fcj-34gh" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-xwqc-7jc4-xm73" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_pane_tree()` function from `lib/html.php` , finally resulting in cross-site scripting. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31443&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31443" target="_blank">CVE-2024-31443</a><br><a href="https://github.com/Cacti/cacti/commit/f946fa537d19678f938ddbd784a10e3290d275cf" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-rqc8-78cm-85j3" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the HTML statement in `form_confirm()` function from `lib/html.php` , finally resulting in cross-site scripting. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31444&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">4.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31444" target="_blank">CVE-2024-31444</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-p4ch-7hjw-6m87" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Cacti--cacti<br> </td>
<td>Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not thoroughly checked and is used to concatenate the SQL statement in `draw_nontemplated_fields_graph_item()` function from `lib/html_form_templates.php` , finally resulting in SQL injection. Version 1.2.27 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31458&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">4.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31458" target="_blank">CVE-2024-31458</a><br><a href="https://github.com/Cacti/cacti/security/advisories/GHSA-jrxg-8wh8-943x" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /view/show_student1.php. The manipulation of the argument grade leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264441 was assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4906&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4906" target="_blank">CVE-2024-4906</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%202.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264441" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264441" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333292" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /view/show_student2.php. The manipulation of the argument grade leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264442 is the identifier assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4907&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4907" target="_blank">CVE-2024-4907</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%203.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264442" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264442" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333293" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /view/student_attendance_history1.php. The manipulation of the argument index leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264443.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4908&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4908" target="_blank">CVE-2024-4908</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%204.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264443" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264443" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333294" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /view/student_due_payment.php. The manipulation of the argument due_year leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264444.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4909&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4909" target="_blank">CVE-2024-4909</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%205.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264444" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264444" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333295" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /view/student_exam_mark_insert_form1.php. The manipulation of the argument grade leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264445 was assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4910&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4910" target="_blank">CVE-2024-4910</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%206.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264445" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264445" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333296" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /view/student_exam_mark_update_form.php. The manipulation of the argument exam leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264446 is the identifier assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4911&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4911" target="_blank">CVE-2024-4911</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20sql/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%207.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264446" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264446" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333297" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the file /admin/general-setting of the component Setting Handler. The manipulation of the argument favicon/logo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263622 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4681&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4681" target="_blank">CVE-2024-4681</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/file_upload.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263622" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263622" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331468" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability classified as critical has been found in Campcodes Online Examination System 1.0. This affects an unknown part of the file addExamExe.php. The manipulation of the argument examTitle leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264447.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4912&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4912" target="_blank">CVE-2024-4912</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_addExamExe.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264447" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264447" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333402" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability classified as critical was found in Campcodes Online Examination System 1.0. This vulnerability affects unknown code of the file exam.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264448.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4913&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4913" target="_blank">CVE-2024-4913</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_exam.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264448" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264448" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333403" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability, which was classified as critical, has been found in Campcodes Online Examination System 1.0. This issue affects some unknown processing of the file ranking-exam.php. The manipulation of the argument exam_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264449 was assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4914&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4914" target="_blank">CVE-2024-4914</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_ranking-exam.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264449" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264449" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333407" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Campcodes Online Examination System 1.0. Affected is an unknown function of the file result.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264450 is the identifier assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4915&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4915" target="_blank">CVE-2024-4915</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_result.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264450" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264450" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333408" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file selExamAttemptExe.php. The manipulation of the argument thisId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264451.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4916&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4916" target="_blank">CVE-2024-4916</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_selExamAttemptExe.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264451" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264451" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333409" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability was found in Campcodes Online Examination System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file submitAnswerExe.php. The manipulation of the argument exmne_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264452.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4917&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4917" target="_blank">CVE-2024-4917</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_submitAnswerExe.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264452" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264452" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333410" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability was found in Campcodes Online Examination System 1.0. It has been classified as critical. This affects an unknown part of the file updateQuestion.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264453 was assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4918&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4918" target="_blank">CVE-2024-4918</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_updateQuestion.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264453" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264453" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333415" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Examination System<br> </td>
<td>A vulnerability was found in Campcodes Online Examination System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/addCourseExe.php. The manipulation of the argument course_name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264454 is the identifier assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4919&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4919" target="_blank">CVE-2024-4919</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Examination%20System%20With%20Timer/SQL_addCourseExe.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264454" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264454" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333416" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability, which was classified as critical, has been found in Campcodes Online Laundry Management System 1.0. This issue affects some unknown processing of the file /admin_class.php. The manipulation of the argument id/delete_category/delete_inv/delete_laundry/delete_supply/delete_user/login/save_inv/save_user leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263891.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4792&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4792" target="_blank">CVE-2024-4792</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/sql_action.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263891" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263891" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332533" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Campcodes Online Laundry Management System 1.0. Affected is an unknown function of the file /manage_laundry.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263892.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4793&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4793" target="_blank">CVE-2024-4793</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/sql_manage_laundry.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263892" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263892" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332535" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /manage_receiving.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263893 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4794&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4794" target="_blank">CVE-2024-4794</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/sql_manage_receiving.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263893" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263893" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332536" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability was found in Campcodes Online Laundry Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /manage_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263894 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4795&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4795" target="_blank">CVE-2024-4795</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/sql_manage_user.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263894" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263894" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332537" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as critical. This affects an unknown part of the file /manage_inv.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263895.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4796&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4796" target="_blank">CVE-2024-4796</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/sql_manage_inv.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263895" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263895" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332538" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file manage_user.php of the component HTTP Request Parameter Handler. The manipulation of the argument id leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263938 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4817&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4817" target="_blank">CVE-2024-4817</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/IDOR_manage_user.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263938" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263938" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333055" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability was found in Campcodes Online Laundry Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php. The manipulation of the argument page leads to file inclusion. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263939.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4818&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4818" target="_blank">CVE-2024-4818</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/LFI.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263939" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263939" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333057" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file admin_class.php. The manipulation of the argument type with the input 1 leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263940.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4819&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4819" target="_blank">CVE-2024-4819</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/IDOR.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263940" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263940" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333058" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco AppDynamics<br> </td>
<td>A vulnerability in Cisco AppDynamics Network Visibility Agent could allow an unauthenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the inability to handle unexpected input. An attacker who has local device access could exploit this vulnerability by sending an HTTP request to the targeted service. A successful exploit could allow the attacker to cause a DoS condition by stopping the Network Agent Service on the local device.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20394&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20394" target="_blank">CVE-2024-20394</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-appd-netvisdos-9zNbsJtK" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Network Services Orchestrator<br> </td>
<td>A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of a parameter in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20369&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20369" target="_blank">CVE-2024-20369</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-ordir-MNM8YqzO" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Client<br> </td>
<td>A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate privileges to SYSTEM. This vulnerability is due to a lack of authentication on a specific function. A successful exploit could allow the attacker to execute arbitrary code with SYSTEM privileges on an affected device.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20391&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20391" target="_blank">CVE-2024-20391</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-nam-priv-esc-szu2vYpZ" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Email and Web Manager<br> </td>
<td>A vulnerability in the Cisco Crosswork NSO CLI and the ConfD CLI could allow an authenticated, low-privileged, local attacker to elevate privileges to root on the underlying operating system. The vulnerability is due to an incorrect privilege assignment when specific CLI commands are used. An attacker could exploit this vulnerability by executing an affected CLI command. A successful exploit could allow the attacker to elevate privileges to root on the underlying operating system.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20383&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20383" target="_blank">CVE-2024-20383</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Email<br> </td>
<td>A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20258&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20258" target="_blank">CVE-2024-20258</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Email<br> </td>
<td>A vulnerability in the web-based management API of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to insufficient input validation of some parameters that are passed to the web-based management API of the affected system. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to perform cross-site scripting (XSS) attacks, resulting in the execution of arbitrary script code in the browser of the targeted user, or could allow the attacker to access sensitive, browser-based information.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20392&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20392" target="_blank">CVE-2024-20392</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-http-split-GLrnnOwS" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Email<br> </td>
<td>A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface.r This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20257&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20257" target="_blank">CVE-2024-20257</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>Cisco--Cisco Secure Web Appliance<br> </td>
<td>A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-20256&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-20256" target="_blank">CVE-2024-20256</a><br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-sma-wsa-xss-bgG5WHOD" target="_blank">ykramarz@cisco.com</a></td>
</tr>
<tr>
<td>CodeBard--Fast Custom Social Share by CodeBard<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in CodeBard Fast Custom Social Share by CodeBard.This issue affects Fast Custom Social Share by CodeBard: from n/a through 1.1.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34807&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34807" target="_blank">CVE-2024-34807</a><br><a href="https://patchstack.com/database/vulnerability/fast-custom-social-share-by-codebard/wordpress-fast-custom-social-share-by-codebard-plugin-1-1-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CodePeople--Appointment Hour Booking<br> </td>
<td>Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Appointment Hour Booking allows Removing Important Client Functionality.This issue affects Appointment Hour Booking: from n/a through 1.4.56.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32720&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32720" target="_blank">CVE-2024-32720</a><br><a href="https://patchstack.com/database/vulnerability/appointment-hour-booking/wordpress-appointment-hour-booking-plugin-1-4-56-captcha-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CodePeople--CP Polls<br> </td>
<td>: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP Polls: from n/a through 1.0.71.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24873&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24873" target="_blank">CVE-2024-24873</a><br><a href="https://patchstack.com/database/vulnerability/cp-polls/wordpress-polls-cp-plugin-1-0-71-polls-limitation-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CodePeople--CP Polls<br> </td>
<td>Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CodePeople CP Polls allows Code Injection.This issue affects CP Polls: from n/a through 1.0.71.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24874&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24874" target="_blank">CVE-2024-24874</a><br><a href="https://patchstack.com/database/vulnerability/cp-polls/wordpress-polls-cp-plugin-1-0-71-content-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Codezips--E-Commerce Site<br> </td>
<td>A vulnerability has been found in Codezips E-Commerce Site 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/addproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264460.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4923&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4923" target="_blank">CVE-2024-4923</a><br><a href="https://github.com/polaris0x1/CVE/issues/1" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264460" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264460" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333874" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Codezips--E-Commerce Site<br> </td>
<td>A vulnerability, which was classified as critical, has been found in Codezips E-Commerce Site 1.0. Affected by this issue is some unknown functionality of the file admin/editproduct.php. The manipulation of the argument profilepic leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264746 is the identifier assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5049&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5049" target="_blank">CVE-2024-5049</a><br><a href="https://github.com/polaris0x1/CVE/issues/2" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264746" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264746" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335838" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban--TranslatePress<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban TranslatePress.This issue affects TranslatePress: from n/a through 2.7.5.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34827&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34827" target="_blank">CVE-2024-34827</a><br><a href="https://patchstack.com/database/vulnerability/translatepress-multilingual/wordpress-translate-multilingual-sites-translatepress-plugin-2-7-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Cozmoslabs--Profile Builder<br> </td>
<td>Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31341&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31341" target="_blank">CVE-2024-31341</a><br><a href="https://patchstack.com/database/vulnerability/profile-builder/wordpress-user-profile-builder-plugin-3-11-2-bypass-vulnerability-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Creative Motion--Clearfy Cache<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Clearfy Cache.This issue affects Clearfy Cache: from n/a through 2.2.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34806&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34806" target="_blank">CVE-2024-34806</a><br><a href="https://patchstack.com/database/vulnerability/clearfy/wordpress-clearfy-cache-plugin-2-2-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>CriticalMoments--CMSaasStarter<br> </td>
<td>CMSaaSStarter is a SaaS template/boilerplate built with SvelteKit, Tailwind, and Supabase. Any forks of the CMSaaSStarter template before commit 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 are impacted. The issue is the user JWT Token is not verified on server session. You should take the patch 7904d416d2c72ec75f42fbf51e9e64fa74062ee6 into your fork.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34354&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34354" target="_blank">CVE-2024-34354</a><br><a href="https://github.com/CriticalMoments/CMSaasStarter/commit/7904d416d2c72ec75f42fbf51e9e64fa74062ee6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/CriticalMoments/CMSaasStarter/pull/65" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/CriticalMoments/CMSaasStarter/security/advisories/GHSA-qgcj-9rxf-rw7q" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>Certain MQTT wildcards are not blocked on the CyberPower PowerPanel system, which might result in an attacker obtaining data from throughout the system after gaining access to any device.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31409&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31409" target="_blank">CVE-2024-31409</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>CyberPower--PowerPanel business<br> </td>
<td>The key used to encrypt passwords stored in the database can be found in the CyberPower PowerPanel application code, allowing the passwords to be recovered.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32042&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32042" target="_blank">CVE-2024-32042</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-123-01" target="_blank">ics-cert@hq.dhs.gov</a><br><a href="https://www.cyberpower.com/global/en/product/sku/powerpanel_business_for_windows#downloads" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>Dassault Systmes--3DSwymer<br> </td>
<td>A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5597&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5597" target="_blank">CVE-2023-5597</a><br><a href="https://www.3ds.com/vulnerability/advisories" target="_blank">3DS.Information-Security@3ds.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to denial of service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25965&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:H" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25965" target="_blank">CVE-2024-25965</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an execution with unnecessary privileges vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25967&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25967" target="_blank">CVE-2024-25967</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without limits or throttling vulnerability. A local unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25969&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25969" target="_blank">CVE-2024-25969</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to loss of integrity.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25970&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25970" target="_blank">CVE-2024-25970</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an improper handling of unexpected data type vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25966&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25966" target="_blank">CVE-2024-25966</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Dell--PowerScale OneFS<br> </td>
<td>Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25968&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25968" target="_blank">CVE-2024-25968</a><br><a href="https://www.dell.com/support/kbdoc/en-us/000224860/dsa-2024-163-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" target="_blank">security_alert@emc.com</a></td>
</tr>
<tr>
<td>Easy Digital Downloads--Easy Digital Downloads<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32100&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32100" target="_blank">CVE-2024-32100</a><br><a href="https://patchstack.com/database/vulnerability/easy-digital-downloads/wordpress-easy-digital-downloads-plugin-3-2-11-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Easy Digital Downloads--Easy Digital Downloads<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31113&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31113" target="_blank">CVE-2024-31113</a><br><a href="https://patchstack.com/database/vulnerability/easy-digital-downloads/wordpress-easy-digital-downloads-plugin-3-2-11-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Elegant Themes--Divi Builder<br> </td>
<td>The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the 'title' parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4490&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4490" target="_blank">CVE-2024-4490</a><br><a href="https://www.elegantthemes.com/" target="_blank">security@wordfence.com</a><br><a href="https://www.elegantthemes.com/api/changelog/divi.txt" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/efac70f6-d959-41f7-bdef-d554f1c9133e?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>EnvoThemes--Envo's Elementor Templates &amp; Widgets for WooCommerce<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo's Elementor Templates &amp; Widgets for WooCommerce allows Stored XSS.This issue affects Envo's Elementor Templates &amp; Widgets for WooCommerce: from n/a through 1.4.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35167&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35167" target="_blank">CVE-2024-35167</a><br><a href="https://patchstack.com/database/vulnerability/envo-elementor-for-woocommerce/wordpress-envo-s-elementor-templates-widgets-for-woocommerce-plugin-1-4-8-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Eric Alli--Google Typography<br> </td>
<td>Missing Authorization vulnerability in Eric Alli Google Typography.This issue affects Google Typography: from n/a through 1.1.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33942&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33942" target="_blank">CVE-2024-33942</a><br><a href="https://patchstack.com/database/vulnerability/google-typography/wordpress-google-typography-plugin-1-1-2-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Extend Themes--EmpowerWP<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes EmpowerWP.This issue affects EmpowerWP: from n/a through 1.0.21.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34809&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34809" target="_blank">CVE-2024-34809</a><br><a href="https://patchstack.com/database/vulnerability/empowerwp/wordpress-empowerwp-theme-1-0-21-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Felix Moira--Popup More Popups<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Felix Moira Popup More Popups allows Stored XSS.This issue affects Popup More Popups: from n/a through 2.3.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32800&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32800" target="_blank">CVE-2024-32800</a><br><a href="https://patchstack.com/database/vulnerability/popup-more/wordpress-popup-popup-more-popups-plugin-2-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Flothemes--Flo Forms<br> </td>
<td>Missing Authorization vulnerability in Flothemes Flo Forms.This issue affects Flo Forms: from n/a through 1.0.42.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35174&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35174" target="_blank">CVE-2024-35174</a><br><a href="https://patchstack.com/database/vulnerability/flo-forms/wordpress-flo-forms-plugin-1-0-42-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>FmeAddons--Conditional Checkout Fields for WooCommerce<br> </td>
<td>Missing Authorization vulnerability in FmeAddons Conditional Checkout Fields for WooCommerce.This issue affects Conditional Checkout Fields for WooCommerce: from n/a through 1.2.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-45070&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-45070" target="_blank">CVE-2022-45070</a><br><a href="https://patchstack.com/database/vulnerability/conditional-checkout-fields-for-woocommerce/wordpress-conditional-checkout-fields-for-woocommerce-plugin-1-2-1-broken-authentication-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiADC<br> </td>
<td>An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, version 7.2.3 and below, version 7.1.4 and below, version 7.0.5 and below, version 6.2.6 and below may allow a read-only admin to view data pertaining to other admins.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-50180&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-50180" target="_blank">CVE-2023-50180</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-433" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiNAC<br> </td>
<td>An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 7.2.0 through 7.2.3 may allow a remote authenticated attacker to perform stored and reflected cross site scripting (XSS) attack via crafted HTTP requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31488&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31488" target="_blank">CVE-2024-31488</a><br><a href="https://fortiguard.com/psirt/FG-IR-24-040" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiOS<br> </td>
<td>A double free vulnerability [CWE-415] in Fortinet FortiOS before 7.0.0 may allow a privileged attacker to execute code or commands via crafted HTTP or HTTPs requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-44247&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-44247" target="_blank">CVE-2023-44247</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-195" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiOS<br> </td>
<td>An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker to provoke a denial of service on the administrative interface via crafted HTTP requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-26007&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-26007" target="_blank">CVE-2024-26007</a><br><a href="https://fortiguard.com/psirt/FG-IR-24-017" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiProxy<br> </td>
<td>A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiPAM versions 1.0.0 through 1.0.3, FortiOS versions 7.2.0, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.16 allows attacker to execute unauthorized code or commands via specially crafted commands</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-36640&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-36640" target="_blank">CVE-2023-36640</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-137" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiProxy<br> </td>
<td>A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.5, 7.0.0 through 7.0.11, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6 FortiPAM versions 1.1.0, 1.0.0 through 1.0.3 FortiOS versions 7.4.0, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15 FortiSwitchManager versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.2 allows attacker to execute unauthorized code or commands via specially crafted cli commands and http requests.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45583&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45583" target="_blank">CVE-2023-45583</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-137" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>Fortinet--FortiProxy<br> </td>
<td>An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.12 &amp; FortiProxy SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and before 7.0.13 allows an authenticated VPN user to send (but not receive) packets spoofing the IP of another user via crafted network packets.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45586&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45586" target="_blank">CVE-2023-45586</a><br><a href="https://fortiguard.com/psirt/FG-IR-23-225" target="_blank">psirt@fortinet.com</a></td>
</tr>
<tr>
<td>GE HealthCare--EchoPAC Software Only<br> </td>
<td>Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27108&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27108" target="_blank">CVE-2024-27108</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--EchoPAC Software Only<br> </td>
<td>Vulnerable data in transit in GE HealthCare EchoPAC products</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27106&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27106" target="_blank">CVE-2024-27106</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GE HealthCare--Venue<br> </td>
<td>Path traversal vulnerability in "deleteFiles" function of Common Service Desktop, a GE HealthCare ultrasound device component</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1629&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1629" target="_blank">CVE-2024-1629</a><br><a href="https://securityupdate.gehealthcare.com/" target="_blank">171caf72-b841-4e04-a68e-93493aff2b94</a></td>
</tr>
<tr>
<td>GZTimeWalker--GZCTF<br> </td>
<td>GZ::CTF is a capture the flag platform. Prior to 0.20.1, unprivileged user can perform cross-site scripting attacks on other users by constructing malicious team names. This problem has been fixed in `v0.20.1`.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34699&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34699" target="_blank">CVE-2024-34699</a><br><a href="https://github.com/GZTimeWalker/GZCTF/commit/31e775b65cddf82a567d68dcdc78c1739b746346" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/GZTimeWalker/GZCTF/security/advisories/GHSA-p6rq-5x3x-rmhh" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>German Mesky--GMAce<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in German Mesky GMAce allows Path Traversal.This issue affects GMAce: from n/a through 1.5.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-23872&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-23872" target="_blank">CVE-2023-23872</a><br><a href="https://patchstack.com/database/vulnerability/gmace/wordpress-gmace-plugin-1-5-2-arbitrary-file-download-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>GhozyLab, Inc.--Popup Builder<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GhozyLab, Inc. Popup Builder allows Stored XSS.This issue affects Popup Builder: from n/a through 1.1.29.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34567&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34567" target="_blank">CVE-2024-34567</a><br><a href="https://patchstack.com/database/vulnerability/easy-notify-lite/wordpress-easy-notify-lite-plugin-1-1-29-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6682&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6682" target="_blank">CVE-2023-6682</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/434821" target="_blank">cve@gitlab.com</a><br><a href="https://hackerone.com/reports/2269012" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6688&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6688" target="_blank">CVE-2023-6688</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/434854" target="_blank">cve@gitlab.com</a><br><a href="https://hackerone.com/reports/2270362" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. The pins endpoint is susceptible to DoS through a crafted request.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2454&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2454" target="_blank">CVE-2024-2454</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/450405" target="_blank">cve@gitlab.com</a><br><a href="https://hackerone.com/reports/2408226" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. It was possible for an attacker to cause a denial of service using maliciously crafted markdown content.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2651&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2651" target="_blank">CVE-2024-2651</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/450830" target="_blank">cve@gitlab.com</a><br><a href="https://hackerone.com/reports/2408619" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4597&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4597" target="_blank">CVE-2024-4597</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/438686" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>GitLab--GitLab<br> </td>
<td>An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2 where abusing the API to filter branch and tags could lead to Denial of Service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4539&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4539" target="_blank">CVE-2024-4539</a><br><a href="https://gitlab.com/gitlab-org/gitlab/-/issues/454815" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>Google--Gvisor<br> </td>
<td>A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past commit 6a112c60a257dadac59962e0bc9e9b5aee70b5b6</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-7258&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-7258" target="_blank">CVE-2023-7258</a><br><a href="https://github.com/google/gvisor/commit/6a112c60a257dadac59962e0bc9e9b5aee70b5b6" target="_blank">cve-coordination@google.com</a></td>
</tr>
<tr>
<td>Guido--VS Contact Form<br> </td>
<td>Guessable CAPTCHA vulnerability in Guido VS Contact Form allows Functionality Bypass.This issue affects VS Contact Form: from n/a through 14.7.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30540&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30540" target="_blank">CVE-2024-30540</a><br><a href="https://patchstack.com/database/vulnerability/very-simple-contact-form/wordpress-vs-contact-form-plugin-14-7-sum-captcha-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Gutenify--Gutenify<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gutenify.This issue affects Gutenify: from n/a through 1.4.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35165&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35165" target="_blank">CVE-2024-35165</a><br><a href="https://patchstack.com/database/vulnerability/gutenify/wordpress-gutenify-plugin-1-4-0-sensitive-data-exposure-via-api-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>HCL Software--BigFix Platform<br> </td>
<td>An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23583&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23583" target="_blank">CVE-2024-23583</a><br><a href="https://support.hcltechsw.com/csm?id=kb_article&amp;sysparm_article=KB0113140" target="_blank">psirt@hcl.com</a></td>
</tr>
<tr>
<td>HCL Software--BigFix Platform<br> </td>
<td>Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23554&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23554" target="_blank">CVE-2024-23554</a><br><a href="https://support.hcltechsw.com/csm?id=kb_article&amp;sysparm_article=KB0113140" target="_blank">psirt@hcl.com</a></td>
</tr>
<tr>
<td>HCL Software--BigFix Platform<br> </td>
<td>SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23556&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23556" target="_blank">CVE-2024-23556</a><br><a href="https://support.hcltechsw.com/csm?id=kb_article&amp;sysparm_article=KB0113140" target="_blank">psirt@hcl.com</a></td>
</tr>
<tr>
<td>HCL Software--DRYiCE Lucy<br> </td>
<td>HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnerable to a CORS misconfiguration which could potentially allow unauthorized access to the application resources from any web domain and enable cache poisoning attacks.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-37526&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-37526" target="_blank">CVE-2023-37526</a><br><a href="https://support.hcltechsw.com/csm?id=kb_article&amp;sysparm_article=KB0113032" target="_blank">psirt@hcl.com</a></td>
</tr>
<tr>
<td>Harknell--AWSOM News Announcement<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Harknell AWSOM News Announcement allows Stored XSS.This issue affects AWSOM News Announcement: from n/a through 1.6.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34428&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34428" target="_blank">CVE-2024-34428</a><br><a href="https://patchstack.com/database/vulnerability/awsom-news-announcement/wordpress-awsom-news-announcement-plugin-1-6-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exists in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilites result in the ability to interrupt the normal operation of the affected Access Point.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31478&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31478" target="_blank">CVE-2024-31478</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Unauthenticated Denial of Service (DoS) vulnerabilities exist in the Central Communications service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31479&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31479" target="_blank">CVE-2024-31479</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31480&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31480" target="_blank">CVE-2024-31480</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31481&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31481" target="_blank">CVE-2024-31481</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected Access Point.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31482&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31482" target="_blank">CVE-2024-31482</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hewlett Packard Enterprise (HPE)--Aruba InstantOS and Aruba Access Points running ArubaOS 10<br> </td>
<td>An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31483&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31483" target="_blank">CVE-2024-31483</a><br><a href="https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2024-006.txt" target="_blank">security-alert@hpe.com</a></td>
</tr>
<tr>
<td>Hidden Depth--Sticky banner<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidden Depth Sticky banner allows Stored XSS.This issue affects Sticky banner: from n/a through 1.2.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35170&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35170" target="_blank">CVE-2024-35170</a><br><a href="https://patchstack.com/database/vulnerability/sticky-banner/wordpress-sticky-banner-plugin-1-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Highfivery LLC--Zero Spam<br> </td>
<td>Client-Side Enforcement of Server-Side Security vulnerability in Highfivery LLC Zero Spam allows Removing Important Client Functionality.This issue affects Zero Spam: from n/a through 5.5.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32521&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32521" target="_blank">CVE-2024-32521</a><br><a href="https://patchstack.com/database/vulnerability/zero-spam/wordpress-zero-spam-for-wordpress-plugin-5-5-5-bypass-spam-protection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>The WindowManager module has a vulnerability in permission control. Impact: Successful exploitation of this vulnerability may affect confidentiality.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-52721&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52721" target="_blank">CVE-2023-52721</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32990&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32990" target="_blank">CVE-2024-32990</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32995&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32995" target="_blank">CVE-2024-32995</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32996&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32996" target="_blank">CVE-2024-32996</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32999&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32999" target="_blank">CVE-2024-32999</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4046&amp;vector=CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4046" target="_blank">CVE-2024-4046</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Out-of-bounds access vulnerability in the memory module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32993&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L" target="_blank" title="CVSS V3 Score">5.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32993" target="_blank">CVE-2024-32993</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>NULL pointer access vulnerability in the clock module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32998&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32998" target="_blank">CVE-2024-32998</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-52383&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52383" target="_blank">CVE-2023-52383</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-52384&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52384" target="_blank">CVE-2023-52384</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Race condition vulnerability in the soundtrigger module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-52720&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52720" target="_blank">CVE-2023-52720</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>Huseyin Berberoglu--WP Favorite Posts<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Huseyin Berberoglu WP Favorite Posts.This issue affects WP Favorite Posts: from n/a through 1.6.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34427&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34427" target="_blank">CVE-2024-34427</a><br><a href="https://patchstack.com/database/vulnerability/wp-favorite-posts/wordpress-wp-favorite-posts-plugin-1-6-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>IBM--App Connect Enterprise<br> </td>
<td>IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 285245.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28761&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28761" target="_blank">CVE-2024-28761</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/285245" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150847" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--App Connect Enterprise<br> </td>
<td>IBM App Connect Enterprise 11.0.0.1 through 11.0.0.25 and 12.0.1.0 through 12.0.12.0 dashboard is vulnerable to a denial of service due to improper restrictions of resource allocation. IBM X-Force ID: 285244.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28760&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28760" target="_blank">CVE-2024-28760</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/285244" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150845" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--QRadar SIEM<br> </td>
<td>IBM QRadar SIEM 7.5 could allow a privileged user to configure user management that would disclose unintended sensitive information across tenants. IBM X-Force ID: 284575.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27269&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27269" target="_blank">CVE-2024-27269</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/284575" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150684" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--SDK, Java Technology Edition<br> </td>
<td>The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack in some circumstances due to improper enforcement of the JEP 290 MaxRef and MaxDepth deserialization filters. IBM X-Force ID: 260578.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38264&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38264" target="_blank">CVE-2023-38264</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/260578" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150727" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--Security Guardium<br> </td>
<td>IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that could lead to a denial of service. IBM X-Force ID: 271690.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47717&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47717" target="_blank">CVE-2023-47717</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/271690" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7152469" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--Spectrum Fusion HCI<br> </td>
<td>IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43040&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43040" target="_blank">CVE-2023-43040</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/266807" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7151040" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--TXSeries for Multiplatforms<br> </td>
<td>IBM TXSeries for Multiplatforms 8.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 280191.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22344&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22344" target="_blank">CVE-2024-22344</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/280191" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150667" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--TXSeries for Multiplatforms<br> </td>
<td>IBM TXSeries for Multiplatforms 8.2 transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. IBM X-Force ID: 280192.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22345&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22345" target="_blank">CVE-2024-22345</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/280192" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150667" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--TXSeries for Multiplatforms<br> </td>
<td>IBM TXSeries for Multiplatforms 8.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 280190.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22343&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22343" target="_blank">CVE-2024-22343</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/280190" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150667" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>IBM--UrbanCode Deploy<br> </td>
<td>IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4, and 8.0 through 8.0.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 285654.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28781&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28781" target="_blank">CVE-2024-28781</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/285654" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150747" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>ITPison--OMICARD EDM<br> </td>
<td>ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modify the parameters and conduct Server-Side Request Forgery (SSRF) attacks. This vulnerability enables attackers to probe internal network information.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4894&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4894" target="_blank">CVE-2024-4894</a><br><a href="https://www.twcert.org.tw/en/cp-139-7803-c0f73-2.html" target="_blank">twcert@cert.org.tw</a><br><a href="https://www.twcert.org.tw/tw/cp-132-7802-18f3c-1.html" target="_blank">twcert@cert.org.tw</a></td>
</tr>
<tr>
<td>Imran Sayed--Headless CMS<br> </td>
<td>Missing Authorization vulnerability in Imran Sayed Headless CMS.This issue affects Headless CMS: from n/a through 2.0.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-34186&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-34186" target="_blank">CVE-2023-34186</a><br><a href="https://patchstack.com/database/vulnerability/headless-cms/wordpress-headless-cms-plugin-2-0-3-broken-authentication-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>JFrog--Artifactory<br> </td>
<td>A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim's user email.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2248&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2248" target="_blank">CVE-2024-2248</a><br><a href="https://jfrog.com/help/r/jfrog-release-information/jfrog-security-advisories" target="_blank">reefs@jfrog.com</a></td>
</tr>
<tr>
<td>JetBrains--TeamCity<br> </td>
<td>In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35301&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35301" target="_blank">CVE-2024-35301</a><br><a href="https://www.jetbrains.com/privacy-security/issues-fixed/" target="_blank">cve@jetbrains.com</a></td>
</tr>
<tr>
<td>JetBrains--TeamCity<br> </td>
<td>In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35302&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35302" target="_blank">CVE-2024-35302</a><br><a href="https://www.jetbrains.com/privacy-security/issues-fixed/" target="_blank">cve@jetbrains.com</a></td>
</tr>
<tr>
<td>JetBrains--YouTrack<br> </td>
<td>In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35299&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35299" target="_blank">CVE-2024-35299</a><br><a href="https://www.jetbrains.com/privacy-security/issues-fixed/" target="_blank">cve@jetbrains.com</a></td>
</tr>
<tr>
<td>Justin Silver--Remote Content Shortcode<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Justin Silver Remote Content Shortcode allows PHP Local File Inclusion.This issue affects Remote Content Shortcode: from n/a through 1.5.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45652&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45652" target="_blank">CVE-2023-45652</a><br><a href="https://patchstack.com/database/vulnerability/remote-content-shortcode/wordpress-remote-content-shortcode-plugin-1-5-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Justin Tadlock--Unique<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Unique allows Stored XSS.This issue affects Unique: from n/a through 0.3.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33952&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33952" target="_blank">CVE-2024-33952</a><br><a href="https://patchstack.com/database/vulnerability/unique/wordpress-unique-theme-0-3-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. This affects an unknown part of the file view_each_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263919.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4799&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4799" target="_blank">CVE-2024-4799</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%202.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263919" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263919" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332544" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability has been found in Kashipara College Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file submit_student.php. The manipulation of the argument date_of_birth leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263920.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4800&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4800" target="_blank">CVE-2024-4800</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%203.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263920" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263920" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332545" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability was found in Kashipara College Management System 1.0 and classified as critical. This issue affects some unknown processing of the file submit_new_faculty.php. The manipulation of the argument address leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263921 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4801&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4801" target="_blank">CVE-2024-4801</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%204.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263921" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263921" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332552" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability was found in Kashipara College Management System 1.0. It has been classified as critical. Affected is an unknown function of the file submit_extracurricular_activity.php. The manipulation of the argument activity_datetime leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263922 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4802&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4802" target="_blank">CVE-2024-4802</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%205.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263922" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263922" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332553" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability was found in Kashipara College Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file submit_admin.php. The manipulation of the argument phone leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263923.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4803&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4803" target="_blank">CVE-2024-4803</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%206.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263923" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263923" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332554" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability was found in Kashipara College Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file edit_user.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263924.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4804&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4804" target="_blank">CVE-2024-4804</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%207.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263924" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263924" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332555" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability classified as critical has been found in Kashipara College Management System 1.0. This affects an unknown part of the file edit_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263925 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4805&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4805" target="_blank">CVE-2024-4805</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%208.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263925" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263925" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332556" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability classified as critical was found in Kashipara College Management System 1.0. This vulnerability affects unknown code of the file each_extracurricula_activities.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263926 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4806&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4806" target="_blank">CVE-2024-4806</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%209.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263926" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263926" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332557" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability, which was classified as critical, has been found in Kashipara College Management System 1.0. This issue affects some unknown processing of the file delete_user.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263927.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4807&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4807" target="_blank">CVE-2024-4807</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%2010.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263927" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263927" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332564" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. Affected is an unknown function of the file delete_faculty.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263928.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4808&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4808" target="_blank">CVE-2024-4808</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%2011.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263928" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263928" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332565" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kashipara--College Management System<br> </td>
<td>A vulnerability classified as critical has been found in Kashipara College Management System 1.0. Affected is an unknown function of the file view_students_each_detail.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264438 is the identifier assigned to this vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4905&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4905" target="_blank">CVE-2024-4905</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/College%20Management%20System/College%20Management%20System%20-%20vuln%201.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264438" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264438" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332543" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Kiboko Labs--Arigato Autoresponder and Newsletter<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter.This issue affects Arigato Autoresponder and Newsletter: from n/a through 2.7.2.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34823&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34823" target="_blank">CVE-2024-34823</a><br><a href="https://patchstack.com/database/vulnerability/bft-autoresponder/wordpress-arigato-autoresponder-and-newsletter-plugin-2-7-2-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Kioware--Kioware<br> </td>
<td>KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a user from excessively guessing the number.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3461&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3461" target="_blank">CVE-2024-3461</a><br><a href="https://cert.pl/en/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/04/CVE-2024-3459" target="_blank">cvd@cert.pl</a><br><a href="https://www.kioware.com/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Kubernetes--azure-file-csi-driver<br> </td>
<td>A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe service account tokens. These tokens could then potentially be exchanged with external cloud providers to access secrets stored in cloud vault solutions. Tokens are only logged when TokenRequests is configured in the CSIDriver object and the driver is set to run at log level 2 or greater via the -v flag.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3744&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3744" target="_blank">CVE-2024-3744</a><br><a href="https://github.com/kubernetes/kubernetes/issues/124759" target="_blank">jordan@liggitt.net</a><br><a href="https://groups.google.com/g/kubernetes-security-announce/c/hcgZE2MQo1A/m/Y4C6q-CYAgAJ" target="_blank">jordan@liggitt.net</a></td>
</tr>
<tr>
<td>Linux--Linux kernel<br> </td>
<td>In register_device, the return value of ida_simple_get is unchecked, in witch ida_simple_get will use an invalid index value. To address this issue, index should be checked after ida_simple_get. When the index value is abnormal, a warning message should be printed, the port should be dropped, and the value should be recorded.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4810&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4810" target="_blank">CVE-2024-4810</a><br><a href="https://bugzilla.openanolis.cn/show_bug.cgi?id=9008" target="_blank">security@openanolis.org</a></td>
</tr>
<tr>
<td>LionScripts--IP Blocker Lite<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in LionScripts IP Blocker Lite allows Functionality Bypass.This issue affects IP Blocker Lite: from n/a through 11.1.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30479&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30479" target="_blank">CVE-2024-30479</a><br><a href="https://patchstack.com/database/vulnerability/ip-address-blocker/wordpress-lionscripts-ip-blocker-lite-plugin-11-1-1-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>LizardByte--Sunshine<br> </td>
<td>Sunshine is a self-hosted game stream host for Moonlight. Users who ran Sunshine versions 0.17.0 through 0.22.2 as a service on Windows may be impacted when terminating the service if an attacked placed a file named `C:\Program.exe`, `C:\Program.bat`, or `C:\Program.cmd` on the user's computer. This attack vector isn't exploitable unless the user has manually loosened ACLs on the system drive. If the user's system locale is not English, then the name of the executable will likely vary. Version 0.23.0 contains a patch for the issue. Some workarounds are available. One may identify and block potentially malicious software executed path interception by using application control tools, like Windows Defender Application Control, AppLocker, or Software Restriction Policies where appropriate. Alternatively, ensure that proper permissions and directory access control are set to deny users the ability to write files to the top-level directory `C:`. Require that all executables be placed in write-protected directories.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31226&amp;vector=CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31226" target="_blank">CVE-2024-31226</a><br><a href="https://github.com/LizardByte/Sunshine/commit/93e622342c4f3e9b34f5f265039b6775b8e33a7a" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/LizardByte/Sunshine/pull/2379" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/LizardByte/Sunshine/security/advisories/GHSA-r3rw-mx4q-7vfp" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Matt van Andel--Adventure Journal<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt van Andel Adventure Journal allows Stored XSS.This issue affects Adventure Journal: from n/a through 1.7.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33953&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33953" target="_blank">CVE-2024-33953</a><br><a href="https://patchstack.com/database/vulnerability/adventure-journal/wordpress-adventure-journal-theme-1-7-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Metagauss--EventPrime<br> </td>
<td>Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 2.8.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-33321&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-33321" target="_blank">CVE-2023-33321</a><br><a href="https://patchstack.com/database/vulnerability/eventprime-event-calendar-management/wordpress-eventprime-plugin-2-8-6-sensitive-data-exposure?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Metagauss--ProfileGrid<br> </td>
<td>Improper Restriction of Excessive Authentication Attempts vulnerability in Metagauss ProfileGrid allows Removing Important Client Functionality.This issue affects ProfileGrid : from n/a through 5.8.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32774&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32774" target="_blank">CVE-2024-32774</a><br><a href="https://patchstack.com/database/vulnerability/profilegrid-user-profiles-groups-and-communities/wordpress-profilegrid-plugin-5-8-2-group-members-limit-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Microchip--SAME70<br> </td>
<td>A voltage glitch during the startup of EEFC NVM controllers on Microchip SAM E70/S70/V70/V71 microcontrollers allows access to the memory bus via the debug interface even if the security bit is set.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4760&amp;vector=CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4760" target="_blank">CVE-2024-4760</a><br><a href="https://www.0x01team.com/hw_security/bypassing-microchip-atmel-sam-e70-s70-v70-v71-security/" target="_blank">dc3f6da9-85b5-4a73-84a2-2ec90b40fca5</a></td>
</tr>
<tr>
<td>Microsoft--.NET 7.0<br> </td>
<td>Visual Studio Denial of Service Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30046&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30046" target="_blank">CVE-2024-30046</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30046" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--.NET 8.0<br> </td>
<td>.NET and Visual Studio Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30045&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30045" target="_blank">CVE-2024-30045</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30045" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Azure Migrate<br> </td>
<td>Azure Migrate Cross-Site Scripting Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30053&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30053" target="_blank">CVE-2024-30053</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30053" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Microsoft Bing Search for iOS<br> </td>
<td>Microsoft Bing Search Spoofing Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30041&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30041" target="_blank">CVE-2024-30041</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30041" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Microsoft Edge (Chromium-based)<br> </td>
<td>Microsoft Edge (Chromium-based) Spoofing Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30055&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30055" target="_blank">CVE-2024-30055</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30055" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Microsoft Intune Mobile Application Management<br> </td>
<td>Microsoft Intune for Android Mobile Application Management Tampering Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30059&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30059" target="_blank">CVE-2024-30059</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30059" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Microsoft SharePoint Enterprise Server 2016<br> </td>
<td>Microsoft SharePoint Server Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30043&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30043" target="_blank">CVE-2024-30043</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30043" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--PowerBI-client JS SDK<br> </td>
<td>Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30054&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30054" target="_blank">CVE-2024-30054</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30054" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29997&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29997" target="_blank">CVE-2024-29997</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29997" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29998&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29998" target="_blank">CVE-2024-29998</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29998" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-29999&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29999" target="_blank">CVE-2024-29999</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29999" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30000&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30000" target="_blank">CVE-2024-30000</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30000" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30001&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30001" target="_blank">CVE-2024-30001</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30001" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30002&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30002" target="_blank">CVE-2024-30002</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30002" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30003&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30003" target="_blank">CVE-2024-30003</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30003" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30004&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30004" target="_blank">CVE-2024-30004</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30004" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30005&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30005" target="_blank">CVE-2024-30005</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30005" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30012&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30012" target="_blank">CVE-2024-30012</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30012" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mobile Broadband Driver Remote Code Execution Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30021&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30021" target="_blank">CVE-2024-30021</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30021" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows DWM Core Library Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30008&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30008" target="_blank">CVE-2024-30008</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30008" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Cryptographic Services Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30016&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30016" target="_blank">CVE-2024-30016</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30016" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30034&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30034" target="_blank">CVE-2024-30034</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30034" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Remote Access Connection Manager Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30039&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30039" target="_blank">CVE-2024-30039</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30039" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows 10 Version 1809<br> </td>
<td>Windows Mark of the Web Security Feature Bypass Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30050&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30050" target="_blank">CVE-2024-30050</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30050" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2019<br> </td>
<td>Windows Hyper-V Denial of Service Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30011&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30011" target="_blank">CVE-2024-30011</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30011" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2019<br> </td>
<td>DHCP Server Service Denial of Service Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30019&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30019" target="_blank">CVE-2024-30019</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30019" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>Microsoft--Windows Server 2019<br> </td>
<td>Windows Deployment Services Information Disclosure Vulnerability</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30036&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30036" target="_blank">CVE-2024-30036</a><br><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30036" target="_blank">secure@microsoft.com</a></td>
</tr>
<tr>
<td>MongoDB Inc--MongoDB Server<br> </td>
<td>An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that exceeds certain memory sizes. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.16 and MongoDB Server v6.0 versions prior to and including 6.0.5.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3374&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3374" target="_blank">CVE-2024-3374</a><br><a href="https://jira.mongodb.org/browse/SERVER-75601" target="_blank">cna@mongodb.com</a></td>
</tr>
<tr>
<td>N/A--N/A<br> </td>
<td>The 'WordPress RSS Aggregator' WordPress Plugin, versions &lt; 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the  'notice_id'  GET parameter.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4860&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4860" target="_blank">CVE-2024-4860</a><br><a href="https://www.tenable.com/security/research/tra-2024-16" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>Nathan Vonnahme--Configure Login Timeout<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nathan Vonnahme Configure Login Timeout allows Stored XSS.This issue affects Configure Login Timeout: from n/a through 1.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34419&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34419" target="_blank">CVE-2024-34419</a><br><a href="https://patchstack.com/database/vulnerability/configure-login-timeout/wordpress-configure-login-timeout-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Ninja Team--Filebird<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Filebird: from n/a through 5.6.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35166&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35166" target="_blank">CVE-2024-35166</a><br><a href="https://patchstack.com/database/vulnerability/filebird/wordpress-filebird-wordpress-media-library-folders-file-manager-plugin-5-6-3-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>OCDI--One Click Demo Import<br> </td>
<td>Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: from n/a through 3.2.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34433&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34433" target="_blank">CVE-2024-34433</a><br><a href="https://patchstack.com/database/vulnerability/one-click-demo-import/wordpress-one-click-demo-import-plugin-3-2-0-php-object-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>OceanicJS--Oceanic<br> </td>
<td>Oceanic is a NodeJS library for interfacing with Discord. Prior to version 1.10.4, input to functions such as `Client.rest.channels.removeBan` is not url-encoded, resulting in specially crafted input such as `../../../channels/{id}` being normalized into the url `/api/v10/channels/{id}`, and deleting a channel rather than removing a ban. Version 1.10.4 fixes this issue. Some workarounds are available. One may sanitize user input, ensuring strings are valid for the purpose they are being used for. One may also encode input with `encodeURIComponent` before providing it to the library.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34712&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34712" target="_blank">CVE-2024-34712</a><br><a href="https://github.com/OceanicJS/Oceanic/commit/8bf8ee8373b8c565fbdbf70a609aba4fbc1a1ffe" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/OceanicJS/Oceanic/security/advisories/GHSA-5h5v-hw44-f6gg" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Path Traversal found in OpenTextâ„¢ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3484&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3484" target="_blank">CVE-2024-3484</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Server Side Request Forgery vulnerability has been discovered in OpenTextâ„¢ iManager 3.2.6.0200. This could lead to senstive information disclosure.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3485&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3485" target="_blank">CVE-2024-3485</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>File Upload vulnerability in unauthenticated session found in OpenTextâ„¢ iManager 3.2.6.0200. The vulnerability could allow ant attacker to upload a file without authentication.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3488&amp;vector=CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3488" target="_blank">CVE-2024-3488</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Server Side Request Forgery vulnerability has been discovered in OpenTextâ„¢ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3970&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3970" target="_blank">CVE-2024-3970</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>Orchestrated--Corona Virus (COVID-19) Banner &amp; Live Data<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Orchestrated Corona Virus (COVID-19) Banner &amp; Live Data allows Stored XSS.This issue affects Corona Virus (COVID-19) Banner &amp; Live Data: from n/a through 1.8.0.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34429&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34429" target="_blank">CVE-2024-34429</a><br><a href="https://patchstack.com/database/vulnerability/corona-virus-covid-19-banner/wordpress-simple-website-banner-plugin-1-8-0-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PHOENIX CONTACT--CHARX SEC-3000<br> </td>
<td>A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28135&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28135" target="_blank">CVE-2024-28135</a><br><a href="https://cert.vde.com/en/advisories/VDE-2024-019" target="_blank">info@cert.vde.com</a></td>
</tr>
<tr>
<td>PHPGurukul--Online Course Registration System<br> </td>
<td>A vulnerability classified as critical was found in PHPGurukul Online Course Registration System 3.1. Affected by this vulnerability is an unknown functionality of the file /pincode-verification.php. The manipulation of the argument pincode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264925 was assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5066&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5066" target="_blank">CVE-2024-5066</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Online%20Course%20Registration%20System/Online%20Course%20Registration%20System%20-%20SQL%20Injection%20-%204.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264925" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264925" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336240" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>PaperCut--PaperCut NG, PaperCut MF<br> </td>
<td>An arbitrary file deletion vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This vulnerability requires local login/console access to the PaperCut NG/MF server (eg: member of a domain admin group).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3037&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3037" target="_blank">CVE-2024-3037</a><br><a href="https://www.papercut.com/kb/Main/security-bulletin-may-2024/" target="_blank">eb41dac7-0af8-4f84-9f6d-0272772514f4</a></td>
</tr>
<tr>
<td>PaperCut--PaperCut NG, PaperCut MF<br> </td>
<td>An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This vulnerability requires local login/console access to the PaperCut NG/MF server (eg: member of a domain admin group).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4712&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4712" target="_blank">CVE-2024-4712</a><br><a href="https://www.papercut.com/kb/Main/security-bulletin-may-2024/" target="_blank">eb41dac7-0af8-4f84-9f6d-0272772514f4</a></td>
</tr>
<tr>
<td>Phil Baylog--QuickieBar<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phil Baylog QuickieBar allows Stored XSS.This issue affects QuickieBar: from n/a through 1.8.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34425&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34425" target="_blank">CVE-2024-34425</a><br><a href="https://patchstack.com/database/vulnerability/quickiebar/wordpress-quickiebar-plugin-1-8-4-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PluginEver--Serial Numbers for WooCommerce License Manager<br> </td>
<td>Missing Authorization vulnerability in PluginEver Serial Numbers for WooCommerce - License Manager.This issue affects Serial Numbers for WooCommerce - License Manager: from n/a through 1.7.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35173&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35173" target="_blank">CVE-2024-35173</a><br><a href="https://patchstack.com/database/vulnerability/wc-serial-numbers/wordpress-wc-serial-numbers-plugin-1-7-2-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>PrestaShop--PrestaShop<br> </td>
<td>PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-office in anonymous mode, by supplying a random secure_key parameter in the url. This issue is patched in version 8.1.6. No known workarounds are available.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34717&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34717" target="_blank">CVE-2024-34717</a><br><a href="https://github.com/PrestaShop/PrestaShop/releases/tag/8.1.6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-7pjr-2rgh-fc5g" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Progress Software Corporation--WhatsUp Gold<br> </td>
<td>In WhatsUp Gold versions released before 2023.1.2 , an SSRF vulnerability exists in Whatsup Gold's Issue exists in the HTTP Monitoring functionality.  Due to the lack of proper authorization, any authenticated user can access the HTTP monitoring functionality, what leads to the Server Side Request Forgery.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4562&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4562" target="_blank">CVE-2024-4562</a><br><a href="https://community.progress.com/s/article/Announcing-WhatsUp-Gold-v2023-1-2" target="_blank">security@progress.com</a><br><a href="https://www.progress.com/network-monitoring" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Progress Software Corporation--WhatsUp Gold<br> </td>
<td>In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker to send arbitrary HTTP requests on behalf of the vulnerable server.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4561&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4561" target="_blank">CVE-2024-4561</a><br><a href="https://community.progress.com/s/article/Announcing-WhatsUp-Gold-v2023-1-2" target="_blank">security@progress.com</a><br><a href="https://www.progress.com/network-monitoring" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Progress Software--Telerik Report Server<br> </td>
<td>An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4357&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4357" target="_blank">CVE-2024-4357</a><br><a href="https://docs.telerik.com/report-server/knowledge-base/xxe-vulnerability-cve-2024-4357" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Progress Software--Telerik Report Server<br> </td>
<td>In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via a trust boundary violation vulnerability.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4837&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4837" target="_blank">CVE-2024-4837</a><br><a href="https://docs.telerik.com/report-server/knowledge-base/information-exposure-cve-2024-4837" target="_blank">security@progress.com</a></td>
</tr>
<tr>
<td>Proofpoint--Enterprise Protection<br> </td>
<td>The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains a Server-Side Request Forgery vulnerability that allows an authenticated user to relay HTTP requests from the Protection server to otherwise private network addresses.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0862&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0862" target="_blank">CVE-2024-0862</a><br><a href="https://www.proofpoint.com/us/security/security-advisories/pfpt-sa-2024-0001" target="_blank">security@proofpoint.com</a></td>
</tr>
<tr>
<td>QODE Interactive--Qi Addons For Elementor<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QODE Interactive Qi Addons For Elementor allows PHP Local File Inclusion.This issue affects Qi Addons For Elementor: from n/a through 1.6.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47679&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47679" target="_blank">CVE-2023-47679</a><br><a href="https://patchstack.com/database/vulnerability/qi-addons-for-elementor/wordpress-qi-addons-for-elementor-plugin-1-6-3-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>RadiusTheme--ShopBuilder Elementor WooCommerce Builder Addons<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in RadiusTheme ShopBuilder - Elementor WooCommerce Builder Addons.This issue affects ShopBuilder - Elementor WooCommerce Builder Addons: from n/a through 2.1.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34812&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34812" target="_blank">CVE-2024-34812</a><br><a href="https://patchstack.com/database/vulnerability/shopbuilder/wordpress-shopbuilder-plugin-2-1-8-sensitive-data-exposure-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>RafflePress--Giveaways and Contests<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in RafflePress Giveaways and Contests allows Functionality Bypass.This issue affects Giveaways and Contests: from n/a through 1.12.7.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32827&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32827" target="_blank">CVE-2024-32827</a><br><a href="https://patchstack.com/database/vulnerability/rafflepress/wordpress-giveaways-and-contests-by-rafflepress-plugin-1-12-7-ip-restriction-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Rashed Latif--TT Custom Post Type Creator<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rashed Latif TT Custom Post Type Creator allows Stored XSS.This issue affects TT Custom Post Type Creator: from n/a through 1.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34430&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34430" target="_blank">CVE-2024-34430</a><br><a href="https://patchstack.com/database/vulnerability/tt-custom-post-type-creator/wordpress-tt-custom-post-type-creator-plugin-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Red Hat--Red Hat Advanced Cluster Management for Kubernetes 2<br> </td>
<td>A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire cluster.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5042&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N" target="_blank" title="CVSS V3 Score">6.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5042" target="_blank">CVE-2024-5042</a><br><a href="https://access.redhat.com/security/cve/CVE-2024-5042" target="_blank">secalert@redhat.com</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2280921" target="_blank">secalert@redhat.com</a><br><a href="https://github.com/advisories/GHSA-2rhx-qhxp-5jpw" target="_blank">secalert@redhat.com</a></td>
</tr>
<tr>
<td>Red Hat--Red Hat Enterprise Linux 6<br> </td>
<td>A flaw was found in the QEMU Virtio PCI Bindings (hw/virtio/virtio-pci.c). An improper release and use of the irqfd for vector 0 during the boot process leads to a guest triggerable crash via vhost_net_stop(). This flaw allows a malicious guest to crash the QEMU process on the host.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4693&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4693" target="_blank">CVE-2024-4693</a><br><a href="https://access.redhat.com/security/cve/CVE-2024-4693" target="_blank">secalert@redhat.com</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2279965" target="_blank">secalert@redhat.com</a></td>
</tr>
<tr>
<td>Red Hat--Red Hat OpenStack Platform 16.2<br> </td>
<td>An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, which can expose sensitive information to anyone with access to the logs.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4840&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4840" target="_blank">CVE-2024-4840</a><br><a href="https://access.redhat.com/security/cve/CVE-2024-4840" target="_blank">secalert@redhat.com</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2280249" target="_blank">secalert@redhat.com</a></td>
</tr>
<tr>
<td>Red Hat--Red Hat Satellite 6<br> </td>
<td>A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. When the key changes, the Satellite still connects it because it uses "-o StrictHostKeyChecking=no". This flaw can lead to a man-in-the-middle attack (MITM), denial of service, leaking of secrets the remote execution job contains, or other issues that may arise from the attacker's ability to forge an SSH key. This issue does not directly allow unauthorized remote execution on the Satellite, although it can leak secrets that may lead to it.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4871&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4871" target="_blank">CVE-2024-4871</a><br><a href="https://access.redhat.com/security/cve/CVE-2024-4871" target="_blank">secalert@redhat.com</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2278627" target="_blank">secalert@redhat.com</a></td>
</tr>
<tr>
<td>Revmakx--WPCal.io Easy Meeting Scheduler<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io - Easy Meeting Scheduler.This issue affects WPCal.Io - Easy Meeting Scheduler: from n/a through 0.9.5.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34816&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34816" target="_blank">CVE-2024-34816</a><br><a href="https://patchstack.com/database/vulnerability/wpcal/wordpress-wpcal-io-plugin-0-9-5-8-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Ruijie--RG-UAC<br> </td>
<td>A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240506. Affected is an unknown function of the file /view/networkConfig/physicalInterface/interface_commit.php. The manipulation of the argument name leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-263934 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4813&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4813" target="_blank">CVE-2024-4813</a><br><a href="https://github.com/h0e4a0r1t/I_L-HxK-pF-uZ1-/blob/main/Ruijie%20RG-UAC%20Unified%20Internet%20Behavior%20Management%20Audit%20System%20Backend%20RCE%20Vulnerability-physicalInterface%3Ainterface_commit.php.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263934" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263934" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.330020" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Ruijie--RG-UAC<br> </td>
<td>A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240506. Affected by this vulnerability is an unknown functionality of the file /view/networkConfig/RouteConfig/StaticRoute/static_route_edit_commit.php. The manipulation of the argument oldipmask/oldgateway leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263935. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4814&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4814" target="_blank">CVE-2024-4814</a><br><a href="https://github.com/h0e4a0r1t/I_L-HxK-pF-uZ1-/blob/main/Ruijie%20RG-UAC%20Unified%20Internet%20Behavior%20Management%20Audit%20System%20Backend%20RCE%20Vulnerability-StaticRoute%3Astatic_route_edit_commit.php.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263935" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263935" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.330052" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Ruijie--RG-UAC<br> </td>
<td>A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240506. Affected by this issue is some unknown functionality of the file /view/bugSolve/viewData/detail.php. The manipulation of the argument filename leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263936. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4815&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4815" target="_blank">CVE-2024-4815</a><br><a href="https://github.com/h0e4a0r1t/I_L-HxK-pF-uZ1-/blob/main/Ruijie%20RG-UAC%20Unified%20Internet%20Behavior%20Management%20Audit%20System%20Backend%20RCE%20Vulnerability-view_bugSolve_viewData_detail.php.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263936" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263936" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.329966" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Ruijie--RG-UAC<br> </td>
<td>A vulnerability, which was classified as critical, was found in Ruijie RG-UAC up to 20240506. This affects an unknown part of the file /view/networkConfig/GRE/gre_add_commit.php. The manipulation of the argument name/remote/local/IP leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263937 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4816&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4816" target="_blank">CVE-2024-4816</a><br><a href="https://github.com/h0e4a0r1t/I_L-HxK-pF-uZ1-/blob/main/Ruijie%20RG-UAC%20Unified%20Internet%20Behavior%20Management%20Audit%20System%20Backend%20RCE%20Vulnerability-gre_add_commit.php.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263937" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263937" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.329953" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP BusinessObjects Business Intelligence Platform (Webservices)<br> </td>
<td>SAP Business Objects Business Intelligence Platform is vulnerable to Insecure Storage as dynamic web pages are getting cached even after logging out. On successful exploitation, the attacker can see the sensitive information through cache and can open the pages causing limited impact on Confidentiality, Integrity and Availability of the application.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33004&amp;vector=CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33004" target="_blank">CVE-2024-33004</a><br><a href="https://me.sap.com/notes/3449093" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP Enable Now<br> </td>
<td>SAP Enable Now Manager does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker with the role 'Learner' could gain access to other user's data in manager which will lead to a high impact to the confidentiality of the application.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32730&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32730" target="_blank">CVE-2024-32730</a><br><a href="https://me.sap.com/notes/3441944" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP Global Label Management (GLM)<br> </td>
<td>SAP Global Label Management is vulnerable to SQL injection. On exploitation the attacker can use specially crafted inputs to modify database commands resulting in the retrieval of additional information persisted by the system. This could lead to low impact on Confidentiality and Integrity of the application.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33009&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33009" target="_blank">CVE-2024-33009</a><br><a href="https://me.sap.com/notes/1938764" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP My Travel Requests <br> </td>
<td>SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can upload a malicious attachment to a business trip request which will lead to a low impact on the confidentiality, integrity and availability of the application. </td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32731&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32731" target="_blank">CVE-2024-32731</a><br><a href="https://me.sap.com/notes/3447467" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP NetWeaver Application Server ABAP and ABAP Platform <br> </td>
<td>Due to missing input validation and output encoding of untrusted data, SAP NetWeaver Application Server ABAP and ABAP Platform allows an unauthenticated attacker to inject malicious JavaScript code into the dynamically crafted web page. On successful exploitation the attacker can access or modify sensitive information with no impact on availability of the application</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32733&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32733" target="_blank">CVE-2024-32733</a><br><a href="https://me.sap.com/notes/3450286" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP NetWeaver Application server for ABAP and ABAP Platform<br> </td>
<td>SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker can control code that is executed within a user's browser, which could result in modification, deletion of data, including accessing or deleting files, or stealing session cookies which an attacker could use to hijack a user's session. Hence, this could have impact on Confidentiality, Integrity and Availability of the system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34687&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34687" target="_blank">CVE-2024-34687</a><br><a href="https://me.sap.com/notes/3448445" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP Replication Server <br> </td>
<td>SAP Replication Server allows an attacker to use gateway for executing some commands to RSSD. This could result in crashing the Replication Server due to memory corruption with high impact on Availability of the system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33008&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33008" target="_blank">CVE-2024-33008</a><br><a href="https://me.sap.com/notes/3349468" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)<br> </td>
<td>Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can enable/disable the sharing rule of other users affecting the integrity of the application. Confidentiality and Availability are not affected.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4138&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4138" target="_blank">CVE-2024-4138</a><br><a href="https://me.sap.com/notes/3434666" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)<br> </td>
<td>Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can delete rules of other users affecting the integrity of the application. Confidentiality and Availability are not affected.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4139&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4139" target="_blank">CVE-2024-4139</a><br><a href="https://me.sap.com/notes/3434666" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP S/4HANA (Document Service Handler for DPS)<br> </td>
<td>Document Service handler (obsolete) in Data Provisioning Service does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability with low impact on Confidentiality and Integrity of the application.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33002&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33002" target="_blank">CVE-2024-33002</a><br><a href="https://me.sap.com/notes/3460772" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SKT Themes--SKT Addons for Elementor<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes SKT Addons for Elementor allows Stored XSS.This issue affects SKT Addons for Elementor: from n/a through 1.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34436&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34436" target="_blank">CVE-2024-34436</a><br><a href="https://patchstack.com/database/vulnerability/skt-addons-for-elementor/wordpress-skt-addons-for-elementor-plugin-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SKT Themes--SKT Addons for Elementor<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes SKT Addons for Elementor allows Stored XSS.This issue affects SKT Addons for Elementor: from n/a through 1.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34445&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34445" target="_blank">CVE-2024-34445</a><br><a href="https://patchstack.com/database/vulnerability/skt-addons-for-elementor/wordpress-skt-addons-for-elementor-plugin-1-8-cross-site-scripting-xss-vulnerability-2?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SailPoint--Identity Security Cloud<br> </td>
<td>An improper access control was identified in the Identity Security Cloud (ISC) message server API that allowed an authenticated user to exfiltrate job processing metadata (opaque messageIDs, work queue depth and counts) for other tenants.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3317&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3317" target="_blank">CVE-2024-3317</a><br><a href="https://www.sailpoint.com/security-advisories/" target="_blank">psirt@sailpoint.com</a></td>
</tr>
<tr>
<td>SailPoint--Identity Security Cloud<br> </td>
<td>A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authenticated administrator to set arbitrary connector attributes, including the "file" attribute, which in turn allowed the user to access files uploaded for other sources.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3318&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.2</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3318" target="_blank">CVE-2024-3318</a><br><a href="https://www.sailpoint.com/security-advisories/" target="_blank">psirt@sailpoint.com</a></td>
</tr>
<tr>
<td>SakuraIsayeki--WOWS-Karma<br> </td>
<td>WOWS Karma is a reputation system for Wargaming's World of Warships. A user is able to click multiple times on "create" on a post creation prompt before the modal closes, which triggers sending several post creation API requests at once. Due to timing, sending multiple posts simultaneously requests bypasses the cooldown validation, however are not refreshing a user's metrics more than once, due to concurrent karma updates. This issue is fixed in 0.17.4.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34695&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34695" target="_blank">CVE-2024-34695</a><br><a href="https://github.com/SakuraIsayeki/WOWS-Karma/commit/3210b516fa3551e30fe760c915f7656d9046e69a" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/SakuraIsayeki/WOWS-Karma/commit/6cb825976f28c68d79172aeda00e955bf5853de2" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/SakuraIsayeki/WOWS-Karma/security/advisories/GHSA-v6cc-v976-mj8g" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Salon Booking System--Salon booking system<br> </td>
<td>Improper Privilege Management vulnerability in Salon Booking System Salon booking system allows Privilege Escalation.This issue affects Salon booking system: from n/a through 8.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-48319&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-48319" target="_blank">CVE-2023-48319</a><br><a href="https://patchstack.com/database/vulnerability/salon-booking-system/wordpress-salon-booking-system-plugin-8-7-editor-privilege-escalation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Samsung Open Source--Escargot<br> </td>
<td>Improper Input Validation vulnerability in Samsung Open Source escargot JavaScript engine allows Overflow Buffers. However, it occurs in the test code and does not include in the release. This issue affects escargot: 4.0.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32669&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32669" target="_blank">CVE-2024-32669</a><br><a href="https://github.com/Samsung/escargot/pull/1326" target="_blank">PSIRT@samsung.com</a></td>
</tr>
<tr>
<td>Samsung Open Source--Escargot<br> </td>
<td>A Segmentation Fault issue discovered in Samsung Open Source Escargot JavaScript engine allows remote attackers to cause a denial of service via crafted input. This issue affects Escargot: 4.0.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32672&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32672" target="_blank">CVE-2024-32672</a><br><a href="https://github.com/Samsung/escargot/pull/1322" target="_blank">PSIRT@samsung.com</a></td>
</tr>
<tr>
<td>Samuel Marshall--JCH Optimize<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samuel Marshall JCH Optimize.This issue affects JCH Optimize: from n/a through 4.2.0.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34808&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34808" target="_blank">CVE-2024-34808</a><br><a href="https://patchstack.com/database/vulnerability/jch-optimize/wordpress-jch-optimize-plugin-4-2-0-path-traversal-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ShortPixel--ShortPixel Adaptive Images<br> </td>
<td>Server-Side Request Forgery (SSRF) vulnerability in ShortPixel ShortPixel Adaptive Images.This issue affects ShortPixel Adaptive Images: from n/a through 3.8.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35172&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35172" target="_blank">CVE-2024-35172</a><br><a href="https://patchstack.com/database/vulnerability/shortpixel-adaptive-images/wordpress-shortpixel-adaptive-images-plugin-3-8-3-server-side-request-forgery-ssrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ShortPixel--ShortPixel Adaptive Images<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in ShortPixel ShortPixel Adaptive Images.This issue affects ShortPixel Adaptive Images: from n/a through 3.8.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4689&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4689" target="_blank">CVE-2024-4689</a><br><a href="https://patchstack.com/database/vulnerability/shortpixel-adaptive-images/wordpress-shortpixel-adaptive-images-plugin-3-8-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SiAdmin--SiAdmin<br> </td>
<td>Vulnerability in SiAdmin 1.1 that allows XSS via the /show.php query parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and thereby steal their cookie session credentials.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4993&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4993" target="_blank">CVE-2024-4993</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-siadmin" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Siemens--OPUPI0 AMQP/MQTT<br> </td>
<td>A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions &lt; V5.30). The affected devices stores MQTT client passwords without sufficient protection on the devices. An attacker with remote shell access or physical access could retrieve the credentials leading to confidentiality loss.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31486&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31486" target="_blank">CVE-2024-31486</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-871704.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--Polarion ALM<br> </td>
<td>A vulnerability has been identified in Polarion ALM (All versions &lt; V2404.0). The Apache Lucene based query engine in the affected application lacks proper access controls. This could allow an authenticated user to query items beyond the user's allowed projects.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33647&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33647" target="_blank">CVE-2024-33647</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-925850.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). Downloading files overwrites files with the same name in the installation directory of the affected systems. The filename for the target file can be specified, thus arbitrary files can be overwritten by an attacker with the required privileges.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27946&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27946" target="_blank">CVE-2024-27946</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--RUGGEDCOM CROSSBOW<br> </td>
<td>A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions &lt; V5.5). The affected systems could allow log messages to be forwarded to a specific client under certain circumstances. An attacker could leverage this vulnerability to forward log messages to a specific compromised client.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27947&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27947" target="_blank">CVE-2024-27947</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-916916.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--S7-PCT<br> </td>
<td>A vulnerability has been identified in S7-PCT (All versions), Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions), SIMATIC BATCH V9.1 (All versions), SIMATIC NET PC Software (All versions), SIMATIC PCS 7 V9.1 (All versions), SIMATIC PDM V9.2 (All versions), SIMATIC Route Control V9.1 (All versions), SIMATIC STEP 7 V5 (All versions), SIMATIC WinCC OA V3.17 (All versions), SIMATIC WinCC OA V3.18 (All versions &lt; V3.18 P025), SIMATIC WinCC OA V3.19 (All versions &lt; V3.19 P010), SIMATIC WinCC Runtime Advanced (All versions), SIMATIC WinCC Runtime Professional V16 (All versions), SIMATIC WinCC Runtime Professional V17 (All versions), SIMATIC WinCC Runtime Professional V18 (All versions), SIMATIC WinCC Runtime Professional V19 (All versions), SIMATIC WinCC Unified PC Runtime (All versions), SIMATIC WinCC V7.4 (All versions), SIMATIC WinCC V7.5 (All versions), SIMATIC WinCC V8.0 (All versions), SINAMICS Startdrive (All versions &lt; V19 SP1), SINUMERIK ONE virtual (All versions &lt; V6.23), SINUMERIK PLC Programming Tool (All versions), TIA Portal Cloud Connector (All versions &lt; V2.0), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions &lt; V19 Update 2). The affected applications contain an out of bounds read vulnerability. This could allow an attacker to cause a Blue Screen of Death (BSOD) crash of the underlying Windows kernel.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46280&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46280" target="_blank">CVE-2023-46280</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-962515.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). The "DBTest" tool of SIMATIC RTLS Locating Manager does not properly enforce access restriction. This could allow an authenticated local attacker to extract sensitive information from memory.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30208&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30208" target="_blank">CVE-2024-30208</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected components do not properly authenticate heartbeat messages. This could allow an unauthenticated remote attacker to affected the availability of secondary RTLS systems configured using a TeeRevProxy service and potentially cause loss of data generated during the time the attack is ongoing.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33494&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33494" target="_blank">CVE-2024-33494</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). The affected application does not properly limit the size of specific logs. This could allow an unauthenticated remote attacker to exhaust system resources by creating a great number of log entries which could potentially lead to a denial of service condition. A successful exploitation requires the attacker to have access to specific SIMATIC RTLS Locating Manager Clients in the deployment.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33495&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33495" target="_blank">CVE-2024-33495</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33496&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33496" target="_blank">CVE-2024-33496</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected SIMATIC RTLS Locating Manager Track Viewer Client do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33497&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33497" target="_blank">CVE-2024-33497</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected applications do not properly release memory that is allocated when handling specifically crafted incoming packets. This could allow an unauthenticated remote attacker to cause a denial of service condition by crashing the service when it runs out of memory. The service is restarted automatically after a short time.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33498&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33498" target="_blank">CVE-2024-33498</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>SourceCodester--Best Courier Management System<br> </td>
<td>A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file view_parcel.php. The manipulation of the argument id leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264480.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4945&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4945" target="_blank">CVE-2024-4945</a><br><a href="https://github.com/CveSecLook/cve/issues/28" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264480" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264480" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333960" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Employee and Visitor Gate Pass Logging System<br> </td>
<td>A vulnerability classified as critical has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is an unknown function of the file /employee_gatepass/classes/Users.php?f=ssave. The manipulation of the argument img leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264456.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4921&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4921" target="_blank">CVE-2024-4921</a><br><a href="https://github.com/I-Schnee-I/cev/blob/main/upload.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264456" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264456" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333662" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Gas Agency Management System<br> </td>
<td>A vulnerability has been found in SourceCodester Gas Agency Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file edituser.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264748.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5051&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5051" target="_blank">CVE-2024-5051</a><br><a href="https://github.com/HuoMingZ/aoligei/blob/main/Gas.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264748" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264748" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336010" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Interactive Map with Marker<br> </td>
<td>A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete-mark.php. The manipulation of the argument mark leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264535.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4967&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4967" target="_blank">CVE-2024-4967</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Interactive%20Map%20App/Interactive%20Map%20App%20-%20SQL%20Injection.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264535" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264535" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335190" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Art Gallery Management System<br> </td>
<td>A vulnerability was found in SourceCodester Online Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file admin/adminHome.php. The manipulation of the argument sliderpic leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264481 was assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4946&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4946" target="_blank">CVE-2024-4946</a><br><a href="https://github.com/CveSecLook/cve/issues/29" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264481" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264481" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.334215" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Birth Certificate Management System<br> </td>
<td>A vulnerability was found in SourceCodester Online Birth Certificate Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin. The manipulation leads to files or directories accessible. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264742 is the identifier assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5045&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5045" target="_blank">CVE-2024-5045</a><br><a href="https://github.com/HuoMingZ/aoligei/blob/main/yuzu.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264742" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264742" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335384" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Computer and Laptop Store<br> </td>
<td>A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown functionality of the file /admin/maintenance/manage_brand.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263918 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4798&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4798" target="_blank">CVE-2024-4798</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/sql5.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263918" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263918" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332784" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Online Computer and Laptop Store<br> </td>
<td>A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/SystemSettings.php?f=update_settings. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263941 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4820&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4820" target="_blank">CVE-2024-4820</a><br><a href="https://github.com/jxm68868/cve/blob/main/upload.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263941" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263941" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333272" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Open Source Clinic Management System<br> </td>
<td>A vulnerability has been found in SourceCodester Open Source Clinic Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file setting.php. The manipulation of the argument logo leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263929 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4809&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4809" target="_blank">CVE-2024-4809</a><br><a href="https://github.com/CveSecLook/cve/issues/26" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263929" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263929" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332581" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--School Intramurals Student Attendance Management System<br> </td>
<td>A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /intrams_sams/manage_course.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264461 was assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4925&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4925" target="_blank">CVE-2024-4925</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/sql6.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264461" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264461" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333875" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--School Intramurals Student Attendance Management System<br> </td>
<td>A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /intrams_sams/manage_student.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264462 is the identifier assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4926&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4926" target="_blank">CVE-2024-4926</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/sql7.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264462" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264462" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333879" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /simple-online-bidding-system/admin/ajax.php?action=save_product. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264463.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4927&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4927" target="_blank">CVE-2024-4927</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/upload2.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264463" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264463" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333891" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /simple-online-bidding-system/admin/ajax.php?action=delete_category. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264464.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4928&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4928" target="_blank">CVE-2024-4928</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/sql8.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264464" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264464" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333893" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability classified as critical was found in SourceCodester Simple Online Bidding System 1.0. This vulnerability affects unknown code of the file /simple-online-bidding-system/index.php?page=view_prod. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264466 is the identifier assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4930&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4930" target="_blank">CVE-2024-4930</a><br><a href="https://github.com/rockersiyuan/CVE/blob/main/SourceCodester%20Simple%20Online%20Bidding%20System%20Sql%20Inject-1.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264466" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264466" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335343" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability, which was classified as critical, has been found in SourceCodester Simple Online Bidding System 1.0. This issue affects some unknown processing of the file /simple-online-bidding-system/admin/index.php?page=view_udet. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264467.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4931&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4931" target="_blank">CVE-2024-4931</a><br><a href="https://github.com/rockersiyuan/CVE/blob/main/SourceCodester%20Simple%20Online%20Bidding%20System%20Sql%20Inject-2.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264467" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264467" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335365" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability, which was classified as critical, was found in SourceCodester Simple Online Bidding System 1.0. Affected is an unknown function of the file /simple-online-bidding-system/admin/index.php?page=manage_user. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264468.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4932&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4932" target="_blank">CVE-2024-4932</a><br><a href="https://github.com/rockersiyuan/CVE/blob/main/SourceCodester%20Simple%20Online%20Bidding%20System%20Sql%20Inject-3.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264468" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264468" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335366" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability has been found in SourceCodester Simple Online Bidding System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /simple-online-bidding-system/admin/index.php?page=manage_product. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264469 was assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4933&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4933" target="_blank">CVE-2024-4933</a><br><a href="https://github.com/rockersiyuan/CVE/blob/main/SourceCodester%20Simple%20Online%20Bidding%20System%20Sql%20Inject-4.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264469" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264469" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335367" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Bidding System<br> </td>
<td>A vulnerability classified as problematic has been found in SourceCodester Simple Online Bidding System 1.0. This affects an unknown part of the file /simple-online-bidding-system/admin/ajax.php?action=save_user. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264465 was assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4929&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4929" target="_blank">CVE-2024-4929</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/csrf.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264465" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264465" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333894" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Online Mens Salon Management System<br> </td>
<td>A vulnerability, which was classified as critical, has been found in SourceCodester Simple Online Mens Salon Management System 1.0. Affected by this issue is some unknown functionality of the file view_service.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-264926 is the identifier assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5069&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5069" target="_blank">CVE-2024-5069</a><br><a href="https://github.com/menxin996/Cvehub/blob/main/Men&amp;apos;s%20Salon%20Management%20System%20%20view_service.php%20has%20Sqlinjection.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264926" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264926" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.336842" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Sparkle WP--Editorialmag<br> </td>
<td>Missing Authorization vulnerability in Sparkle WP Editorialmag editorialmag.This issue affects Editorialmag: from n/a through 1.1.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-32129&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-32129" target="_blank">CVE-2023-32129</a><br><a href="https://patchstack.com/database/vulnerability/editorialmag/wordpress-editorialmag-theme-1-1-9-authenticated-arbitrary-plugin-activation?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Stefano Lissa &amp; The Newsletter Team--Newsletter<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in Stefano Lissa &amp; The Newsletter Team Newsletter allows Functionality Bypass.This issue affects Newsletter: from n/a through 8.2.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30522&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30522" target="_blank">CVE-2024-30522</a><br><a href="https://patchstack.com/database/vulnerability/newsletter/wordpress-newsletter-plugin-8-2-0-ip-blacklist-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Strategy11 Form Builder Team--Formidable Forms<br> </td>
<td>Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affects Formidable Forms: from n/a through 6.7.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-23522&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23522" target="_blank">CVE-2024-23522</a><br><a href="https://patchstack.com/database/vulnerability/formidable/wordpress-formidable-forms-plugin-6-7-content-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>StylemixThemes--Cost Calculator Builder PRO<br> </td>
<td>Cost Calculator Builder Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.1.72, via the send_demo_webhook() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4789&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4789" target="_blank">CVE-2024-4789</a><br><a href="https://stylemixthemes.com/cost-calculator-plugin/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c6840350-7ff4-4ec2-bf2b-94ce6f782537?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Supsystic--Pricing Table by Supsystic<br> </td>
<td>Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Supsystic Pricing Table by Supsystic allows Code Injection.This issue affects Pricing Table by Supsystic: from n/a through 1.9.12.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32790&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32790" target="_blank">CVE-2024-32790</a><br><a href="https://patchstack.com/database/vulnerability/pricing-table-by-supsystic/wordpress-pricing-table-by-supsystic-plugin-1-9-12-content-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Swift Ideas--Swift Framework<br> </td>
<td>The Swift Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sf_edit_directory_item() function in all versions up to, and including, 2.7.31. This makes it possible for unauthenticated attackers to update arbitrary posts with arbitrary content. Unfortunately, we did not receive a response from the vendor to send over the vulnerability details.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3915&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3915" target="_blank">CVE-2024-3915</a><br><a href="https://swiftideas.com/swift-framework/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/855055d5-362e-4a92-9e9d-97eab328dcc3?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Swift Ideas--Swift Framework<br> </td>
<td>The Swift Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 2.7.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Unfortunately, we did not receive a response from the vendor to send over the vulnerability details.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3916&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3916" target="_blank">CVE-2024-3916</a><br><a href="https://swiftideas.com/swift-framework/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/57103f8e-0874-4e56-8571-254607ada21c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>Sylius--Sylius<br> </td>
<td>Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript code in the Admin panel. In order to perform an XSS attack input a script into Name field in which of the resources: Taxons, Products, Product Options or Product Variants. The code will be executed while using an autocomplete field with one of the listed entities in the Admin Panel. Also for the taxons in the category tree on the product form.The issue is fixed in versions: 1.12.16, 1.13.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34349&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34349" target="_blank">CVE-2024-34349</a><br><a href="https://github.com/Sylius/Sylius/commit/ba4b66da5af88cdb1bba6174de8bdf42f4853e12" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/Sylius/Sylius/security/advisories/GHSA-v2f9-rv6w-vw8r" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Synaptics--Synaptics Fingerprint Driver<br> </td>
<td>Missing lock check in SynHsaService may create a use-after-free condition which causes abnormal termination of the service, resulting in denial of service for the Synaptics Hardware Support App.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5447&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5447" target="_blank">CVE-2023-5447</a><br><a href="https://www.synaptics.com/sites/default/files/2023-10/fingerprint-driver-HSAService-security-brief-2023-10-13.pdf" target="_blank">PSIRT@synaptics.com</a></td>
</tr>
<tr>
<td>TIBCO--Hawk<br> </td>
<td>Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3182&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3182" target="_blank">CVE-2024-3182</a><br><a href="https://community.tibco.com/advisories/tibco-security-advisory-may-14-2024-tibco-hawk-cve-2024-3182-r213/" target="_blank">security@tibco.com</a></td>
</tr>
<tr>
<td>TYPO3--typo3<br> </td>
<td>TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the form manager backend module is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to the form module. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1 fix the problem described.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34356&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34356" target="_blank">CVE-2024-34356</a><br><a href="https://github.com/TYPO3/typo3/commit/2832e2f51f929aeddb5de7d667538a33ceda8156" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/d0393a879a32fb4e3569acad6bdb5cda776be1e5" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/e95a1224719efafb9cab2d85964f240fd0356e64" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/security/advisories/GHSA-v6mw-h7w6-59w3" target="_blank">security-advisories@github.com</a><br><a href="https://typo3.org/security/advisory/typo3-core-sa-2024-008" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>TYPO3--typo3<br> </td>
<td>TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, failing to properly encode user-controlled values in file entities, the `ShowImageController` (`_eID tx_cms_showpic_`) is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to file entities. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34357&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34357" target="_blank">CVE-2024-34357</a><br><a href="https://github.com/TYPO3/typo3/commit/376474904f6b9a54dc1b785a2e45277cbd13b0d7" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/b31d05d1da3eeaeead2d19eb43b1c3f9c88e15ee" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/d774642381354d3bf5095a5a26e18acd2767f0b1" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/security/advisories/GHSA-hw6c-6gwq-3m3m" target="_blank">security-advisories@github.com</a><br><a href="https://typo3.org/security/advisory/typo3-core-sa-2024-009" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>TYPO3--typo3<br> </td>
<td>TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the `ShowImageController` (`_eID tx_cms_showpic_`) lacks a cryptographic HMAC-signature on the `frame` HTTP query parameter (e.g. `/index.php?eID=tx_cms_showpic?file=3&amp;...&amp;frame=12345`). This allows adversaries to instruct the system to produce an arbitrary number of thumbnail images on the server side. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34358&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34358" target="_blank">CVE-2024-34358</a><br><a href="https://github.com/TYPO3/typo3/commit/05c95fed869a1a6dcca06c7077b83b6ea866ff14" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/1e70ebf736935413b0531004839362b4fb0755a5" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/commit/df7909b6a1cf0f12a42994d0cc3376b607746142" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/security/advisories/GHSA-36g8-62qv-5957" target="_blank">security-advisories@github.com</a><br><a href="https://typo3.org/security/advisory/typo3-core-sa-2024-010" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Tech9logy Creators--WPCS ( WordPress Custom Search )<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tech9logy Creators WPCS ( WordPress Custom Search ) allows Stored XSS.This issue affects WPCS ( WordPress Custom Search ): from n/a through 1.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34418&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34418" target="_blank">CVE-2024-34418</a><br><a href="https://patchstack.com/database/vulnerability/wpcs-wp-custom-search/wordpress-wpcs-wordpress-custom-search-plugin-1-1-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>The Events Calendar--BookIt<br> </td>
<td>Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-24715&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24715" target="_blank">CVE-2024-24715</a><br><a href="https://patchstack.com/database/vulnerability/bookit/wordpress-wordpress-bookit-plugin-plugin-2-4-0-price-bypass-vulnerability-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Theme Freesia--Freesia Empire<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Freesia Empire allows Stored XSS.This issue affects Freesia Empire: from n/a through 1.4.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33955&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33955" target="_blank">CVE-2024-33955</a><br><a href="https://patchstack.com/database/vulnerability/freesia-empire/wordpress-freesia-empire-theme-1-4-1-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThemeFuse--Unyson<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in ThemeFuse Unyson.This issue affects Unyson: from n/a through 2.7.29.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34814&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34814" target="_blank">CVE-2024-34814</a><br><a href="https://patchstack.com/database/vulnerability/unyson/wordpress-unyson-plugin-2-7-29-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThemeLocation--Custom WooCommerce Checkout Fields Editor<br> </td>
<td>Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33956&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33956" target="_blank">CVE-2024-33956</a><br><a href="https://patchstack.com/database/vulnerability/add-fields-to-checkout-page-woocommerce/wordpress-custom-woocommerce-checkout-fields-editor-plugin-1-3-0-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThemeNectar--Salient Shortcodes<br> </td>
<td>The Salient Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'icon' shortcode in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3811&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3811" target="_blank">CVE-2024-3811</a><br><a href="https://themeforest.net/item/salient-responsive-multipurpose-theme/4363266" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/70682a2d-16f6-4d7e-bf69-f0f3999f03de?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>ThimPress--Thim Elementor Kit<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Thim Elementor Kit allows Stored XSS.This issue affects Thim Elementor Kit: from n/a through 1.1.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34415&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34415" target="_blank">CVE-2024-34415</a><br><a href="https://patchstack.com/database/vulnerability/thim-elementor-kit/wordpress-thim-elementor-kit-plugin-1-1-8-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ThroughTek--Kalay SDK<br> </td>
<td>ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6323&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6323" target="_blank">CVE-2023-6323</a><br><a href="https://bitdefender.com/blog/labs/notes-on-throughtek-kalay-vulnerabilities-and-their-impact/" target="_blank">cve-requests@bitdefender.com</a></td>
</tr>
<tr>
<td>Toidicode.com (thanhtaivtt)--Viet Nam Affiliate<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Toidicode.Com (thanhtaivtt) Viet Nam Affiliate allows Stored XSS.This issue affects Viet Nam Affiliate: from n/a through 1.0.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34417&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34417" target="_blank">CVE-2024-34417</a><br><a href="https://patchstack.com/database/vulnerability/viet-nam-affiliate/wordpress-viet-nam-affiliate-plugin-1-0-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Tongda--OA<br> </td>
<td>A vulnerability was found in Tongda OA 2017. It has been declared as critical. This vulnerability affects unknown code of the file /general/meeting/manage/delete.php. The manipulation of the argument M_ID_STR leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264436. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4903&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4903" target="_blank">CVE-2024-4903</a><br><a href="https://github.com/Hefei-Coffee/cve/blob/main/sql3.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264436" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264436" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.330632" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Trellix--ePolicy Orchestrator<br> </td>
<td>ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow a least privileged user to manipulate the client task and client task assignments, hence escalating his/her privilege.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4843&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4843" target="_blank">CVE-2024-4843</a><br><a href="https://thrive.trellix.com/s/article/000013505" target="_blank">trellixpsirt@trellix.com</a></td>
</tr>
<tr>
<td>UkrSolution--Barcode Scanner with Inventory &amp; Order Manager<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in UkrSolution Barcode Scanner with Inventory &amp; Order Manager.This issue affects Barcode Scanner with Inventory &amp; Order Manager: from n/a through 1.5.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34556&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34556" target="_blank">CVE-2024-34556</a><br><a href="https://patchstack.com/database/vulnerability/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/wordpress-barcode-scanner-with-inventory-order-manager-plugin-1-5-4-sensitive-data-exposure-via-exported-file-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>UkrSolution--Barcode Scanner with Inventory &amp; Order Manager<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in UkrSolution Barcode Scanner with Inventory &amp; Order Manager.This issue affects Barcode Scanner with Inventory &amp; Order Manager: from n/a through 1.5.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34557&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34557" target="_blank">CVE-2024-34557</a><br><a href="https://patchstack.com/database/vulnerability/barcode-scanner-lite-pos-to-manage-products-inventory-and-orders/wordpress-barcode-scanner-with-inventory-order-manager-plugin-1-5-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Uniform Server Zero--Uniform Server Zero<br> </td>
<td>vulnerability in Uniform Server Zero, version 10.2.5, consisting of an XSS through the /us_extra/phpinfo.php page. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and partially take over their session details.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5052&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5052" target="_blank">CVE-2023-5052</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-uniform-server-zero" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>Valiano--Unite Gallery Lite<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Valiano Unite Gallery Lite allows PHP Local File Inclusion.This issue affects Unite Gallery Lite: from n/a through 1.7.59.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-33310&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L" target="_blank" title="CVSS V3 Score">6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-33310" target="_blank">CVE-2023-33310</a><br><a href="https://patchstack.com/database/vulnerability/unite-gallery-lite/wordpress-unite-gallery-lite-plugin-1-7-59-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>ValvePress--WordPress Automatic Plugin<br> </td>
<td>The WordPress Automatic Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'autoplay' parameter in all versions up to, and including, 3.94.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4849&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4849" target="_blank">CVE-2024-4849</a><br><a href="https://codecanyon.net/item/wordpress-automatic-plugin/1904470" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4be58bfa-d489-45f5-9169-db8bab718175?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>VeronaLabs--WP SMS<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS allows Stored XSS.This issue affects WP SMS: from n/a through 6.5.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34811&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34811" target="_blank">CVE-2024-34811</a><br><a href="https://patchstack.com/database/vulnerability/wp-sms/wordpress-wp-sms-plugin-6-5-1-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Visualmodo--Borderless Widgets, Elements, Templates and Toolkit for Elementor &amp; Gutenberg<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Visualmodo Borderless - Widgets, Elements, Templates and Toolkit for Elementor &amp; Gutenberg allows Stored XSS.This issue affects Borderless - Widgets, Elements, Templates and Toolkit for Elementor &amp; Gutenberg: from n/a through 1.5.3.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34757&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34757" target="_blank">CVE-2024-34757</a><br><a href="https://patchstack.com/database/vulnerability/borderless/wordpress-borderless-widgets-elements-templates-and-toolkit-for-elementor-gutenberg-plugin-1-5-3-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>W3 Eden Inc.--Download Manager<br> </td>
<td>Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affects Download Manager: from n/a through 3.2.82.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32131&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32131" target="_blank">CVE-2024-32131</a><br><a href="https://patchstack.com/database/vulnerability/download-manager/wordpress-download-manager-plugin-3-2-82-file-password-lock-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 disks (/admin/DeviceS3). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3787&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3787" target="_blank">CVE-2024-3787</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through License (/admin/CDPUsers). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3788&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3788" target="_blank">CVE-2024-3788</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Uncontrolled resource consumption vulnerability in White Bear Solutions WBSAirback, version 21.02.04. This vulnerability could allow an attacker to send multiple command injection payloads to influence the amount of resources consumed.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3789&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3789" target="_blank">CVE-2024-3789</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemUsers, login / description fields, passwd1/ passwd2 parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3790&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3790" target="_blank">CVE-2024-3790</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/SystemConfiguration, name / free memory limit fields , type / password parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3791&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3791" target="_blank">CVE-2024-3791</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/DeviceReplication, execution range field, all parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3792&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3792" target="_blank">CVE-2024-3792</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/CloudAccounts, account name / user password / server fields, all parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3793&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3793" target="_blank">CVE-2024-3793</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/AdvancedSystem, description field, all parameters. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3794&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3794" target="_blank">CVE-2024-3794</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupTemplate, name / description fields. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3795&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3795" target="_blank">CVE-2024-3795</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WBSAirback--White Bear Solutions<br> </td>
<td>Vulnerability in WBSAirback 21.02.04, which consists of a stored Cross-Site Scripting (XSS) through /admin/BackupSchedule, description field. Exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3796&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3796" target="_blank">CVE-2024-3796</a><br><a href="https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-wbsairback-white-bear-solutions" target="_blank">cve-coordination@incibe.es</a></td>
</tr>
<tr>
<td>WP Club Manager--WP Club Manager<br> </td>
<td>Missing Authorization vulnerability in WP Club Manager.This issue affects WP Club Manager: from n/a through 2.2.11.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32719&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32719" target="_blank">CVE-2024-32719</a><br><a href="https://patchstack.com/database/vulnerability/wp-club-manager/wordpress-wp-club-manager-plugin-2-2-11-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Happy Coders--Comments Like Dislike<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in WP Happy Coders Comments Like Dislike allows Functionality Bypass.This issue affects Comments Like Dislike: from n/a through 1.2.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25906&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25906" target="_blank">CVE-2024-25906</a><br><a href="https://patchstack.com/database/vulnerability/comments-like-dislike/wordpress-comments-like-dislike-plugin-1-2-1-ip-restriction-bypass-vulnerability-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WP Royal--Royal Elementor Addons<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in WP Royal Royal Elementor Addons allows Functionality Bypass.This issue affects Royal Elementor Addons: from n/a through 1.3.93.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32786&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32786" target="_blank">CVE-2024-32786</a><br><a href="https://patchstack.com/database/vulnerability/royal-elementor-addons/wordpress-royal-elementor-addons-and-templates-plugin-1-3-93-ip-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPBlockart--Magazine Blocks<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPBlockart Magazine Blocks allows Stored XSS.This issue affects Magazine Blocks: from n/a through 1.3.6.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34760&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34760" target="_blank">CVE-2024-34760</a><br><a href="https://patchstack.com/database/vulnerability/magazine-blocks/wordpress-magazine-blocks-plugin-1-3-6-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPDeveloper--SchedulePress<br> </td>
<td>Missing Authorization vulnerability in WPDeveloper SchedulePress.This issue affects SchedulePress: from n/a through 5.0.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32717&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32717" target="_blank">CVE-2024-32717</a><br><a href="https://patchstack.com/database/vulnerability/wp-scheduled-posts/wordpress-schedulepress-plugin-5-0-8-broken-access-control-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPMU DEV--Defender Security<br> </td>
<td>Insecure Storage of Sensitive Information vulnerability in WPMU DEV Defender Security allows : Screen Temporary Files for Sensitive Information.This issue affects Defender Security: from n/a through 3.3.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2022-44581&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-44581" target="_blank">CVE-2022-44581</a><br><a href="https://patchstack.com/database/vulnerability/defender-security/wordpress-defender-security-plugin-3-3-2-broken-authentication-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WPMU DEV--Defender Security<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in WPMU DEV Defender Security allows Functionality Bypass.This issue affects Defender Security: from n/a through 4.4.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-25595&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25595" target="_blank">CVE-2024-25595</a><br><a href="https://patchstack.com/database/vulnerability/defender-security/wordpress-defender-security-plugin-4-4-1-ip-restriction-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Wangshen--SecGate 3600<br> </td>
<td>A vulnerability, which was classified as critical, was found in Wangshen SecGate 3600 up to 20240516. This affects an unknown part of the file /?g=log_import_save. The manipulation of the argument reqfile leads to unrestricted upload. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-264747.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5050&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5050" target="_blank">CVE-2024-5050</a><br><a href="https://github.com/h0e4a0r1t/h0e4a0r1t.github.io/blob/master/2024/s%40%23NGfP%7B4%5Et(%7C%5Dd9/Wangshen%20SecGata%203600%20Firewall%20log_import_save%20arbitrary%20file%20upload%20vulnerability.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264747" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264747" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335968" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Warfare Plugins--Social Warfare<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in Warfare Plugins Social Warfare.This issue affects Social Warfare: from n/a through 4.4.5.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34825&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34825" target="_blank">CVE-2024-34825</a><br><a href="https://patchstack.com/database/vulnerability/social-warfare/wordpress-social-warfare-plugin-4-4-5-1-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Web-Settler--Landing Page Builder Free Landing Page Templates<br> </td>
<td>Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Web-Settler Landing Page Builder - Free Landing Page Templates allows Path Traversal.This issue affects Landing Page Builder - Free Landing Page Templates: from n/a through 3.1.9.9.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-24379&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-24379" target="_blank">CVE-2023-24379</a><br><a href="https://patchstack.com/database/vulnerability/ultimate-landing-page/wordpress-landing-page-builder-free-landing-page-templates-plugin-3-1-9-8-local-file-inclusion-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>WebToffee--Order Export &amp; Order Import for WooCommerce<br> </td>
<td>Deserialization of Untrusted Data vulnerability in WebToffee Order Export &amp; Order Import for WooCommerce.This issue affects Order Export &amp; Order Import for WooCommerce: from n/a through 2.4.9.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34751&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34751" target="_blank">CVE-2024-34751</a><br><a href="https://patchstack.com/database/vulnerability/order-import-export-for-woocommerce/wordpress-order-export-order-import-for-woocommerce-plugin-2-4-9-php-object-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Webvitaly--iFrame<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webvitaly iFrame allows Stored XSS.This issue affects iFrame: from n/a through 5.0.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34805&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34805" target="_blank">CVE-2024-34805</a><br><a href="https://patchstack.com/database/vulnerability/iframe/wordpress-iframe-plugin-5-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Wireshark Foundation--Wireshark<br> </td>
<td>MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4854&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4854" target="_blank">CVE-2024-4854</a><br><a href="https://gitlab.com/wireshark/wireshark/-/issues/19726" target="_blank">cve@gitlab.com</a><br><a href="https://gitlab.com/wireshark/wireshark/-/merge_requests/15047" target="_blank">cve@gitlab.com</a><br><a href="https://gitlab.com/wireshark/wireshark/-/merge_requests/15499" target="_blank">cve@gitlab.com</a><br><a href="https://www.wireshark.org/security/wnpa-sec-2024-07.html" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>WordPlus--BP Better Messages<br> </td>
<td>Missing Authorization vulnerability in WordPlus BP Better Messages allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BP Better Messages: from n/a through 2.4.32.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32802&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32802" target="_blank">CVE-2024-32802</a><br><a href="https://patchstack.com/database/vulnerability/bp-better-messages/wordpress-better-messages-plugin-2-4-32-broken-authentication-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Wpmet--Wp Ultimate Review<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.3.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21746&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21746" target="_blank">CVE-2024-21746</a><br><a href="https://patchstack.com/database/vulnerability/wp-ultimate-review/wordpress-wp-ultimate-review-plugin-2-2-5-ip-limit-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Wpmet--Wp Ultimate Review<br> </td>
<td>Client-Side Enforcement of Server-Side Security vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.2.5.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32685&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32685" target="_blank">CVE-2024-32685</a><br><a href="https://patchstack.com/database/vulnerability/wp-ultimate-review/wordpress-wp-ultimate-review-plugin-2-2-5-review-score-manipulation-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Zoom Video Communications, Inc.--Zoom Workplace VDI App for Windows<br> </td>
<td>Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27244&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27244" target="_blank">CVE-2024-27244</a><br><a href="https://www.zoom.com/en/trust/security-bulletin/zsb-24015/" target="_blank">security@zoom.us</a></td>
</tr>
<tr>
<td>Zoom Video Communications, Inc.--see references<br> </td>
<td>Buffer overflow in some Zoom Workplace Apps and SDK's may allow an authenticated user to conduct a denial of service via network access.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-27243&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27243" target="_blank">CVE-2024-27243</a><br><a href="https://www.zoom.com/en/trust/security-bulletin/zsb-24014/" target="_blank">security@zoom.us</a></td>
</tr>
<tr>
<td>abuhayat--HTML5 Audio Player- Best WordPress Audio Player Plugin<br> </td>
<td>The HTML5 Audio Player- Best WordPress Audio Player Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.2.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4398&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4398" target="_blank">CVE-2024-4398</a><br><a href="https://plugins.trac.wordpress.org/browser/html5-audio-player/trunk/inc/Elementor/Widgets/Simple.php#L237" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/html5-audio-player/trunk/inc/elementor-widgets/fusion-audio-player.php#L275" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/html5-audio-player/trunk/inc/elementor-widgets/playlist.php#L541" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/html5-audio-player/trunk/inc/elementor-widgets/stamp-audio-player.php#L286" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ca646202-b9e2-4272-b0e2-d39cd748fb8e?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>aio-libs--aiosmtpd<br> </td>
<td>aiosmptd is a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on aiosmtpd accept extra unencrypted commands after STARTTLS, treating them as if they came from inside the encrypted connection. This could be exploited by a man-in-the-middle attack. Version 1.4.6 contains a patch for the issue.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34083&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34083" target="_blank">CVE-2024-34083</a><br><a href="https://github.com/aio-libs/aiosmtpd/commit/b3a4a2c6ecfd228856a20d637dc383541fcdbfda" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/aio-libs/aiosmtpd/security/advisories/GHSA-wgjv-9j3q-jhg8" target="_blank">security-advisories@github.com</a><br><a href="https://nostarttls.secvuln.info/" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>argoproj--argo-cd<br> </td>
<td>Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. There is a Denial of Service (DoS) vulnerability via OOM using jq in ignoreDifferences. This vulnerability has been patched in version(s) 2.10.7, 2.9.12 and 2.8.16.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32476&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32476" target="_blank">CVE-2024-32476</a><br><a href="https://github.com/argoproj/argo-cd/commit/7893979a1e78d59cedd0ba790ded24e30bb40657" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/argoproj/argo-cd/commit/9e5cc5a26ff0920a01816231d59fdb5eae032b5a" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/argoproj/argo-cd/commit/e2df7315fb7d96652186bf7435773a27be330cac" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/argoproj/argo-cd/security/advisories/GHSA-9m6p-x4h2-6frq" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>asterisk--asterisk<br> </td>
<td>Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as PJSIP Endpoint of local asterisk server. This vulnerability is fixed in 18.23.1, 20.8.1, and 21.3.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35190&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35190" target="_blank">CVE-2024-35190</a><br><a href="https://github.com/asterisk/asterisk/commit/85241bd22936cc15760fd1f65d16c98be7aeaf6d" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/asterisk/asterisk/pull/600" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/asterisk/asterisk/pull/602" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/asterisk/asterisk/security/advisories/GHSA-qqxj-v78h-hrf9" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>athemes--Sydney Toolbox<br> </td>
<td>The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget in all versions up to, and including, 1.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4473&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4473" target="_blank">CVE-2024-4473</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082233/sydney-toolbox" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/60f16abd-951b-48a0-a363-0221f7e0957d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>automattic--Jetpack WP Security, Backup, Speed, &amp; Growth<br> </td>
<td>The Jetpack - WP Security, Backup, Speed, &amp; Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpvideo shortcode in all versions up to, and including, 13.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4392&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4392" target="_blank">CVE-2024-4392</a><br><a href="https://plugins.trac.wordpress.org/browser/jetpack/tags/13.3.1/modules/videopress/class.videopress-player.php#L335" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/11dceac7-7ff8-4384-9046-919c38947c32?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>avimegladon--Custom Post Type Attachment<br> </td>
<td>The Custom Post Type Attachment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pdf_attachment' shortcode in all versions up to, and including, 3.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4546&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4546" target="_blank">CVE-2024-4546</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087121/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f6ba2907-36f4-4c4d-9e25-d13d32e28690?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>bdthemes--Prime Slider Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider)<br> </td>
<td>The Prime Slider - Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the General widget in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4339&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4339" target="_blank">CVE-2024-4339</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3080132%40bdthemes-prime-slider-lite%2Ftrunk&amp;old=3079066%40bdthemes-prime-slider-lite%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6eba6056-e087-4347-ad36-96501ceb4cdd?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>blakeblackshear--frigate<br> </td>
<td>Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Below 0.13.2 Release, when uploading a file or retrieving the filename, a user may intentionally use a large Unicode filename which would lead to a application-level denial of service. This is due to no limitation set on the length of the filename and the costy use of the Unicode normalization with the form NFKD under the hood of `secure_filename()`.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32874&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32874" target="_blank">CVE-2024-32874</a><br><a href="https://github.com/blakeblackshear/frigate/commit/cc851555e4029647986dccc8b8ecf54afee31442" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/blakeblackshear/frigate/security/advisories/GHSA-w4h6-9wrp-v5jq" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>blocksera--Image Hover Effects Elementor Addon<br> </td>
<td>The Image Hover Effects - Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Hover Effects Widget in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1166&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1166" target="_blank">CVE-2024-1166</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3068751%40image-hover-effects-addon-for-elementor&amp;new=3068751%40image-hover-effects-addon-for-elementor&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4d72a57f-9acc-43e4-af81-024bc6e0d3fd?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>boldgrid--Post and Page Builder by BoldGrid Visual Drag and Drop Editor<br> </td>
<td>The Post and Page Builder by BoldGrid - Visual Drag and Drop Editor plguin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions up to, and including, 1.26.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4400&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4400" target="_blank">CVE-2024-4400</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087230/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9bb6683a-b8e6-4776-880f-5b48966fc5c6?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>brainstormforce--Elementor Header &amp; Footer Builder<br> </td>
<td>The Elementor Header &amp; Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hfe_svg_mime_types' function in versions up to, and including, 1.6.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4634&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4634" target="_blank">CVE-2024-4634</a><br><a href="https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/1.6.28/inc/widgets-manager/class-widgets-loader.php#L156" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086402/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f44bb823-bbf3-413b-82b5-a351609270bf?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>brainstormforce--Elementor Header &amp; Footer Builder<br> </td>
<td>The Elementor Header &amp; Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.6.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary HTML in pages that will be shown whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2619&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2619" target="_blank">CVE-2024-2619</a><br><a href="https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/1.6.25/admin/class-hfe-admin.php#L220" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/header-footer-elementor/tags/1.6.25/admin/class-hfe-admin.php#L74" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3070659%40header-footer-elementor%2Ftrunk&amp;old=3053177%40header-footer-elementor%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/689eb95b-2f72-4aa4-9f21-6ae186346061?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>brainstormforce--Starter Templates Elementor, WordPress &amp; Beaver Builder Templates<br> </td>
<td>The Starter Templates - Elementor, WordPress &amp; Beaver Builder Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_upload_mimes' function in versions up to, and including, 4.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4630&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4630" target="_blank">CVE-2024-4630</a><br><a href="https://plugins.trac.wordpress.org/browser/astra-sites/tags/4.2.0/inc/importers/wxr-importer/class-astra-wxr-importer.php#L416" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084334/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/25edb9e8-65ea-41d1-a95f-09be110ec1d2?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>brainstormforce--Starter Templates Elementor, WordPress &amp; Beaver Builder Templates<br> </td>
<td>The Starter Templates - Elementor, WordPress &amp; Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.6 via the ai_api_request(). This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1467&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1467" target="_blank">CVE-2024-1467</a><br><a href="https://plugins.trac.wordpress.org/changeset/3074863/astra-sites/tags/4.1.7/inc/classes/class-astra-sites-importer.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3074863/astra-sites/tags/4.1.7/inc/classes/class-astra-sites.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cf5075f9-9658-4a09-bd38-34a72f6560f4?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>britner--Gutenberg Blocks with AI by Kadence WP Page Builder Features<br> </td>
<td>The Gutenberg Blocks with AI by Kadence WP - Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the typer effect in the advanced heading widget in all versions up to, and including, 3.2.37 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4208&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4208" target="_blank">CVE-2024-4208</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3084683%40kadence-blocks&amp;new=3084683%40kadence-blocks&amp;sfp_email=&amp;sfph_mail=#file2" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/7ea2bb8c-cc8b-49de-9c8e-2c8c0569f4ac?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>britner--Gutenberg Blocks with AI by Kadence WP Page Builder Features<br> </td>
<td>The Gutenberg Blocks with AI by Kadence WP - Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown timer in all versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4209&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4209" target="_blank">CVE-2024-4209</a><br><a href="https://plugins.trac.wordpress.org/browser/kadence-blocks/trunk/includes/blocks/class-kadence-blocks-countdown-block.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083616/kadence-blocks/trunk/dist/blocks-countdown.js" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cff2e5be-0de0-4e62-a881-6156760b7d99?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>britner--Gutenberg Blocks with AI by Kadence WP Page Builder Features<br> </td>
<td>The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the plugin's blocks in all versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4481&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4481" target="_blank">CVE-2024-4481</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083616/kadence-blocks/trunk/includes/blocks/class-kadence-blocks-advanced-heading-block.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ad0e4292-d890-499b-b70a-ed638d5b8ee9?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>britner--Gutenberg Blocks with AI by Kadence WP Page Builder Features<br> </td>
<td>The Gutenberg Blocks by Kadence Blocks - Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Testimonial', 'Progress Bar', 'Lottie Animations', 'Row Layout', 'Google Maps', and 'Advanced Gallery' blocks in all versions up to, and including, 3.2.37 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3189&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3189" target="_blank">CVE-2024-3189</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083616/kadence-blocks/trunk/includes/blocks/class-kadence-blocks-lottie-block.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3076712%40kadence-blocks&amp;new=3076712%40kadence-blocks&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3084683%40kadence-blocks&amp;new=3084683%40kadence-blocks&amp;sfp_email=&amp;sfph_mail=#file2" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/766b0bde-c555-40c1-b174-20045bd89c11?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>buddypress--BuddyPress<br> </td>
<td>The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_name' parameter in versions up to, and including, 12.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3974&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3974" target="_blank">CVE-2024-3974</a><br><a href="https://plugins.trac.wordpress.org/browser/buddypress/trunk/bp-members/bp-members-admin.php#L145" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/buddypress/trunk/bp-members/bp-members-blocks.php#L347" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3079691/buddypress" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3657384e-025a-44ad-8b7e-1a2fea17dcc3?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>carazo--Import and export users and customers<br> </td>
<td>The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user agent header in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4656&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4656" target="_blank">CVE-2024-4656</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3085346%40import-users-from-csv-with-meta%2Ftrunk&amp;old=3078277%40import-users-from-csv-with-meta%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/af742451-b2d6-445a-9a10-e950490f6c7c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>carazo--Import and export users and customers<br> </td>
<td>The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.6.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4734&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4734" target="_blank">CVE-2024-4734</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3085346%40import-users-from-csv-with-meta%2Ftrunk&amp;old=3078277%40import-users-from-csv-with-meta%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0dca168f-a383-42fc-91ba-d78a5d7e6724?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>code-projects--Budget Management<br> </td>
<td>A vulnerability classified as critical was found in code-projects Budget Management 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument edit leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264745 was assigned to this vulnerability.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5048&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5048" target="_blank">CVE-2024-5048</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Budget%20Management%20App/Budget%20Management%20App%20-%20SQL%20Injection%20-%201.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264745" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264745" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335666" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>code-projects--Simple Chat System<br> </td>
<td>A vulnerability classified as critical has been found in code-projects Simple Chat System 1.0. This affects an unknown part of the file /login.php. The manipulation of the argument email/password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264537 was assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4972&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4972" target="_blank">CVE-2024-4972</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Simple%20Chat%20App/Simple%20Chat%20App%20-%20SQL%20Injection%20-%201.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264537" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264537" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335199" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>code-projects--Simple Chat System<br> </td>
<td>A vulnerability classified as critical was found in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the file /register.php. The manipulation of the argument name/number/address leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-264538 is the identifier assigned to this vulnerability.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4973&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4973" target="_blank">CVE-2024-4973</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Simple%20Chat%20App/Simple%20Chat%20App%20-%20SQL%20Injection%20-%202.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264538" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264538" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335200" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>codename065--Sliding Widgets<br> </td>
<td>Missing Authorization vulnerability in codename065 Sliding Widgets allows Cross-Site Scripting (XSS).This issue affects Sliding Widgets: from n/a through 1.5.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33938&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33938" target="_blank">CVE-2024-33938</a><br><a href="https://patchstack.com/database/vulnerability/sliding-widgets/wordpress-sliding-widgets-plugin-1-5-0-broken-access-control-to-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>codewoogeek--Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro<br> </td>
<td>The The Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.3.1. This is due to the plugin for WordPress allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4038&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4038" target="_blank">CVE-2024-4038</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3080830%40back-in-stock-notifier-for-woocommerce&amp;new=3080830%40back-in-stock-notifier-for-woocommerce&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d7f59489-9bff-4d22-8f99-6ea52d702ecf?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>creativethemeshq--Blocksy Companion<br> </td>
<td>The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG uploads in versions up to, and including, 2.0.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4487&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4487" target="_blank">CVE-2024-4487</a><br><a href="https://plugins.trac.wordpress.org/browser/blocksy-companion/tags/2.0.45/framework/features/svg.php#L20" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084198/#file18" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5208529c-4ac3-42a4-82d0-7f4d2e486236?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>creativethemeshq--Blocksy<br> </td>
<td>The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tagName' parameter in versions up to, and including, 2.0.42 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4158&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4158" target="_blank">CVE-2024-4158</a><br><a href="https://themes.trac.wordpress.org/changeset/226440/blocksy" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22d1ccf3-ac1a-4dfc-81c3-b8eb88795bc1?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>croixhaug--Appointment Booking Calendar Simply Schedule Appointments Booking Plugin<br> </td>
<td>The Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter in versions up to, and including, 1.6.7.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4288&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4288" target="_blank">CVE-2024-4288</a><br><a href="https://plugins.trac.wordpress.org/browser/simply-schedule-appointments/trunk/includes/class-shortcodes.php#L677" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087297/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/84262b4a-a662-4aaf-9eae-f5cca8f6cd06?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>daext--Soccer Engine Soccer Plugin for WordPress<br> </td>
<td>The Soccer Engine - Soccer Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to missing or incorrect nonce validation when saving match and team settings. This makes it possible for unauthenticated attackers to change plugin settings as well as teams, players, etc. via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4312&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4312" target="_blank">CVE-2024-4312</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3081944%40soccer-engine-lite%2Ftrunk&amp;old=3066918%40soccer-engine-lite%2Ftrunk" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/57e84624-98ab-495b-b985-908302527b3a?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>davidanderson--Testimonial Slider<br> </td>
<td>The Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'testimonialcategory' shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4193&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4193" target="_blank">CVE-2024-4193</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3080579%40testimonial-slider&amp;new=3080579%40testimonial-slider&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cd7ed687-4049-4957-86e9-b2f59621c747?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>deTheme--DethemeKit For Elementor<br> </td>
<td>Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in deTheme DethemeKit For Elementor allows Stored XSS.This issue affects DethemeKit For Elementor: from n/a through 2.1.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34575&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34575" target="_blank">CVE-2024-34575</a><br><a href="https://patchstack.com/database/vulnerability/dethemekit-for-elementor/wordpress-dethemekit-for-elementor-plugin-2-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>detheme--DethemeKit For Elementor<br> </td>
<td>The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4374&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4374" target="_blank">CVE-2024-4374</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3088000%40dethemekit-for-elementor&amp;new=3088000%40dethemekit-for-elementor&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bcd9384c-5af3-4544-8179-c2f5550dd152?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>devitemsllc--HT Mega Absolute Addons For Elementor<br> </td>
<td>The HT Mega - Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gallery Justify Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3989&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3989" target="_blank">CVE-2024-3989</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3074490%40ht-mega-for-elementor&amp;new=3074490%40ht-mega-for-elementor&amp;sfp_email=&amp;sfph_mail=#file3" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/03fba6bb-ff30-42bb-936b-93c009a7e3f7?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>devitemsllc--HT Mega Absolute Addons For Elementor<br> </td>
<td>The HT Mega - Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip &amp; Popover Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3990&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3990" target="_blank">CVE-2024-3990</a><br><a href="https://plugins.trac.wordpress.org/browser/ht-mega-for-elementor/tags/2.5.0/includes/widgets/htmega_tooltip.php#L620" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3074490%40ht-mega-for-elementor&amp;new=3074490%40ht-mega-for-elementor&amp;sfp_email=&amp;sfph_mail=#file4" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3074490%40ht-mega-for-elementor&amp;new=3074490%40ht-mega-for-elementor&amp;sfp_email=&amp;sfph_mail=#file5" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/98e74a23-b586-4d6a-b1ab-78838b0eed61?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>devitemsllc--ShopLentor WooCommerce Builder for Elementor &amp; Gutenberg +12 Modules All in One Solution (formerly WooLentor)<br> </td>
<td>The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to view all products purchased in the past week, along with the users that purchased them.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6327&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6327" target="_blank">CVE-2023-6327</a><br><a href="https://plugins.trac.wordpress.org/browser/woolentor-addons/tags/2.7.4/includes/modules/sales-notification/class.sale_notification.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3080097/woolentor-addons/trunk/includes/modules/sales-notification/class.sale_notification.php?contextall=1&amp;old=3061864&amp;old_path=%2Fwoolentor-addons%2Ftrunk%2Fincludes%2Fmodules%2Fsales-notification%2Fclass.sale_notification.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/263324cb-31b7-40ad-ad7d-4582e128cd75?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>directus--directus<br> </td>
<td>Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.0, session tokens function like the other JWT tokens where they are not actually invalidated when logging out. The `directus_session` gets destroyed and the cookie gets deleted but if the cookie value is captured, it will still work for the entire expiry time which is set to 1 day by default. Making it effectively a long lived unrevokable stateless token instead of the stateful session token it was meant to be. This vulnerability is fixed in 10.11.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34709&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34709" target="_blank">CVE-2024-34709</a><br><a href="https://github.com/directus/directus/commit/a6172f8a6a0f31a6bf4305a090de172ebfb63bcf" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/directus/directus/security/advisories/GHSA-g65h-35f3-x2w3" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>directus--directus<br> </td>
<td>Directus is a real-time API and App dashboard for managing SQL database content. A user with permission to view any collection using redacted hashed fields can get access the raw stored version using the `alias` functionality on the API. Normally, these redacted fields will return `**********` however if we change the request to `?alias[workaround]=redacted` we can instead retrieve the plain text value for the field. This can be avoided by removing permission to view the sensitive fields entirely from users or roles that should not be able to see them. This vulnerability is fixed in 10.11.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34708&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34708" target="_blank">CVE-2024-34708</a><br><a href="https://github.com/directus/directus/commit/e70a90c267bea695afce6545174c2b77517d617b" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/directus/directus/security/advisories/GHSA-p8v3-m643-4xqx" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>divSpot--DS Site Message<br> </td>
<td>Cross-Site Request Forgery (CSRF) vulnerability in divSpot DS Site Message.This issue affects DS Site Message: from n/a through 1.14.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34439&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34439" target="_blank">CVE-2024-34439</a><br><a href="https://patchstack.com/database/vulnerability/ds-site-message/wordpress-ds-site-message-plugin-1-14-4-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>envothemes--Envo Extra<br> </td>
<td>The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 1.8.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4385&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4385" target="_blank">CVE-2024-4385</a><br><a href="https://plugins.trac.wordpress.org/browser/envo-extra/trunk/lib/elementor/widgets/button/button.php#L679" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/envo-extra/trunk/lib/elementor/widgets/counter/counter.php#L754" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/envo-extra/trunk/lib/elementor/widgets/icon-box/icon-box.php#L909" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/envo-extra/trunk/lib/elementor/widgets/team/team.php#L1189" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/envo-extra/trunk/lib/elementor/widgets/testimonial/testimonial.php#L899" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3080715/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/83d78ff7-bd59-431e-b579-156e23ede053?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>fluxcd--source-controller<br> </td>
<td>The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. The source-controller implements the source.toolkit.fluxcd.io API and is a core component of the GitOps toolkit. Prior to version 1.2.5, when source-controller was configured to use an Azure SAS token when connecting to Azure Blob Storage, the token was logged along with the Azure URL when the controller encountered a connection error. An attacker with access to the source-controller logs could use the token to gain access to the Azure Blob Storage until the token expires. This vulnerability was fixed in source-controller v1.2.5. There is no workaround for this vulnerability except for using a different auth mechanism such as Azure Workload Identity.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31216&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31216" target="_blank">CVE-2024-31216</a><br><a href="https://github.com/fluxcd/source-controller/commit/915d1a072a4f37dd460ba33079dc094aa6e72fa9" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/fluxcd/source-controller/pull/1430" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/fluxcd/source-controller/security/advisories/GHSA-v554-xwgw-hc3w" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>frappe--frappe<br> </td>
<td>Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external URls. This behaviour can be used by malicious actors for phishing. This vulnerability is fixed in 15.26.0 and 14.74.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34074&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34074" target="_blank">CVE-2024-34074</a><br><a href="https://github.com/frappe/frappe/commit/65b3c42635038cdff17d3109be6c373bac004829" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/frappe/frappe/pull/26304" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/frappe/frappe/security/advisories/GHSA-7g27-q225-j894" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>freescout-helpdesk--freescout<br> </td>
<td>FreeScout is a free, self-hosted help desk and shared mailbox. Versions of FreeScout prior to 1.8.139 contain a Prototype Pollution vulnerability in the `/public/js/main.js` source file. The Prototype Pollution arises because the `getQueryParam` Function recursively merges an object containing user-controllable properties into an existing object (For URL Query Parameters Parsing), without first sanitizing the keys. This can allow an attacker to inject a property with a key `__proto__`, along with arbitrarily nested properties. The merge operation assigns the nested properties to the `params` object's prototype instead of the target object itself. As a result, the attacker can pollute the prototype with properties containing harmful values, which are then inherited by user-defined objects and subsequently used by the application dangerously. The vulnerability lets an attacker control properties of objects that would otherwise be inaccessible. If the application subsequently handles an attacker-controlled property in an unsafe way, this can potentially be chained with other vulnerabilities like DOM-based XSS, Open Redirection, Cookie Manipulation, Link Manipulation, HTML Injection, etc. Version 1.8.139 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34698&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">4.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34698" target="_blank">CVE-2024-34698</a><br><a href="https://github.com/freescout-helpdesk/freescout/commit/2614514bc6d6c4ad563202a1c9cae5a97b195cc5" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/freescout-helpdesk/freescout/security/advisories/GHSA-rx6j-4c33-9h3r" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>giuliopanda--ADFO Custom data in admin dashboard<br> </td>
<td>The ADFO - Custom data in admin dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dbp_id' parameter in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4104&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4104" target="_blank">CVE-2024-4104</a><br><a href="https://plugins.trac.wordpress.org/browser/admin-form/trunk/admin/class-af-list-admin.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3081090%40admin-form&amp;new=3081090%40admin-form&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e61110fc-cc2d-4207-97b6-b21459334216?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>giuliopanda--ADFO Custom data in admin dashboard<br> </td>
<td>The ADFO - Custom data in admin dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.0. This is due to missing or incorrect nonce validation on several functions hooked via the controller() function. This makes it possible for unauthenticated attackers to edit the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4103&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4103" target="_blank">CVE-2024-4103</a><br><a href="https://plugins.trac.wordpress.org/changeset/3081090/admin-form/trunk/admin/class-af-list-admin.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/8d797238-f8f3-44d7-8c16-bee23ce12ae0?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>https://elementor.com/--Elementor Website Builder Pro<br> </td>
<td>The Elementor Website Builder - More than Just a Page Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in versions up to, and including, 3.21.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4107&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4107" target="_blank">CVE-2024-4107</a><br><a href="https://doc.clickup.com/9011113249/d/h/8chnb91-5091/3951e6f2afbd388" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0d5d47bd-4f05-4dc7-84c1-f7bc1196ee16?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>iePlexus--Featured Content Gallery<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iePlexus Featured Content Gallery allows Stored XSS.This issue affects Featured Content Gallery: from n/a through 3.2.0.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34424&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34424" target="_blank">CVE-2024-34424</a><br><a href="https://patchstack.com/database/vulnerability/featured-content-gallery/wordpress-featured-content-gallery-plugin-3-2-0-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>iqonicdesign--Graphina Elementor Charts and Graphs<br> </td>
<td>The Graphina - Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4574&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4574" target="_blank">CVE-2024-4574</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/area/widget/area_chart.php#L457" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/bubble/widget/bubble_chart.php#L685" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/candle/widget/candle_chart.php#L517" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/column/widget/column_chart.php#L531" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/distributed_column/widget/Distributed_Column_chart.php#L464" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/donut/widget/donut_chart.php#L325" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/heatmap/widget/heatmap_chart.php#L448" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/line/widget/line_chart.php#L426" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/pie/widget/pie_chart.php#L279" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/polar/widget/polar_chart.php#L413" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/radar/widget/radar_chart.php#L546" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/radial/widget/radial_chart.php#L417" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/scatter/widget/scatter_chart.php#L419" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/charts/timeline/widget/timeline_chart.php#L462" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/area/widget/area_google_chart.php#L570" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/bar/widget/bar_google_chart.php#L524" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/column/widget/column_google_chart.php#L536" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/donut/widget/donut_google_chart.php#L384" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/line/widget/line_google_chart.php#L578" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/trunk/elementor/google_charts/pie/widget/pie_google_chart.php#L391" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1febe2d8-d354-4c78-a611-c1bb0937e53d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>ithemelandco--Bulk Posts Editing For WordPress<br> </td>
<td>The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 4.2.3. This makes it possible for authenticated attackers, with subscriber access and higher, to invoke their corresponding functions. This may lead to post creation and duplication, post content retrieval, post taxonomy manipulation.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4199&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4199" target="_blank">CVE-2024-4199</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3085134%40ithemeland-bulk-posts-editing-lite%2Ftrunk&amp;old=2946926%40ithemeland-bulk-posts-editing-lite%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/683131a0-eec3-4251-b322-5c2088855687?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>ithemelandco--Bulk Posts Editing For WordPress<br> </td>
<td>The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.3. This is due to missing or incorrect nonce validation on the plugin's AJAX actions.. This makes it possible for unauthenticated attackers to create and duplicate posts, retrieve post content, and modify post taxonomy among other things via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4204&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4204" target="_blank">CVE-2024-4204</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3085134%40ithemeland-bulk-posts-editing-lite%2Ftrunk&amp;old=2946926%40ithemeland-bulk-posts-editing-lite%2Ftrunk&amp;sfp_email=&amp;sfph_mail=#file51" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/34b39462-32c5-4f7d-b54f-d95f40b6ed92?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>justinbusa--Beaver Builder WordPress Page Builder<br> </td>
<td>The Beaver Builder - WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_target parameter in all versions up to, and including, 2.8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3923&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3923" target="_blank">CVE-2024-3923</a><br><a href="https://plugins.trac.wordpress.org/browser/beaver-builder-lite-version/tags/2.8.0.7/modules/button/includes/frontend.php#L14" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3078825%40beaver-builder-lite-version%2Ftrunk&amp;old=3062187%40beaver-builder-lite-version%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/99960ff7-62e1-4c44-ae8e-ebda3e075781?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>justinbusa--Beaver Builder WordPress Page Builder<br> </td>
<td>The Beaver Builder - WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the photo widget crop attribute in all versions up to, and including, 2.8.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4430&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4430" target="_blank">CVE-2024-4430</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3083534%40beaver-builder-lite-version%2Ftrunk&amp;old=3078825%40beaver-builder-lite-version%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cd6ed285-f215-44d3-9db9-9b2bfffee60a?source=cve" target="_blank">security@wordfence.com</a><br><a href="https://www.wpbeaverbuilder.com/change-logs/?utm_medium=bb-lite&amp;utm_source=repo-readme&amp;utm_campaign=repo-changelog-page" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>kraftplugins--Mega Elements Addons for Elementor<br> </td>
<td>The Mega Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4702&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4702" target="_blank">CVE-2024-4702</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085457/mega-elements-addons-for-elementor" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3808ca2a-e78e-4118-890b-c22a71f8e855?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>levelfourstorefront--Shopping Cart &amp; eCommerce Store<br> </td>
<td>The Shopping Cart &amp; eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functionality. This makes it possible for unauthenticated attackers to extract sensitive data including order details such as payment details, addresses and other PII.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4213&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4213" target="_blank">CVE-2024-4213</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084202/wp-easycart/trunk/admin/inc/wp_easycart_admin.php?old=3068711&amp;old_path=wp-easycart%2Ftrunk%2Fadmin%2Finc%2Fwp_easycart_admin.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/93daab72-1243-4a05-91d3-9254a1aac727?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>litonice13--Master Addons Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor<br> </td>
<td>The Master Addons - Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the title_html_tag attribute in all versions up to, and including, 2.0.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3134&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3134" target="_blank">CVE-2024-3134</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3087193%40master-addons%2Ftrunk&amp;old=3078134%40master-addons%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6106c972-5475-4c19-8630-3a01edc616ad?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>litonice13--Master Addons Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor<br> </td>
<td>The Master Addons - Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 2.0.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4580&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4580" target="_blank">CVE-2024-4580</a><br><a href="https://plugins.trac.wordpress.org/browser/master-addons/trunk/addons/ma-image-hover-effects/ma-image-hover-effects.php#L1546" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/master-addons/trunk/addons/ma-tabs/ma-tabs.php#L1068" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087193/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e3e3ac84-dd82-42b0-80b9-c876731170d5?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>mantisbt--mantisbt<br> </td>
<td>MantisBT (Mantis Bug Tracker) is an open source issue tracker. Improper escaping of a custom field's name allows an attacker to inject HTML and, if CSP settings permit, achieve execution of arbitrary JavaScript when resolving or closing issues (`bug_change_status_page.php`) belonging to a project linking said custom field, viewing issues (`view_all_bug_page.php`) when the custom field is displayed as a column, or printing issues (`print_all_bug_page.php`) when the custom field is displayed as a column. Version 2.26.2 contains a patch for the issue. As a workaround, ensure Custom Field Names do not contain HTML tags.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34081&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34081" target="_blank">CVE-2024-34081</a><br><a href="https://github.com/mantisbt/mantisbt/commit/447a521aae0f82f791b8116a14a20e276df739be" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/mantisbt/mantisbt/security/advisories/GHSA-wgx7-jp56-65mq" target="_blank">security-advisories@github.com</a><br><a href="https://mantisbt.org/bugs/view.php?id=34432" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>mantisbt--mantisbt<br> </td>
<td>MantisBT (Mantis Bug Tracker) is an open source issue tracker. If an issue references a note that belongs to another issue that the user doesn't have access to, then it gets hyperlinked. Clicking on the link gives an access denied error as expected, yet some information remains available via the link, link label, and tooltip. This can result in disclosure of the existence of the note, the note author name, the note creation timestamp, and the issue id the note belongs to. Version 2.26.2 contains a patch for the issue. No known workarounds are available.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34080&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34080" target="_blank">CVE-2024-34080</a><br><a href="https://github.com/mantisbt/mantisbt/commit/0a50562369d823689c9b946066d1e49d3c2df226" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/mantisbt/mantisbt/pull/2000" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/mantisbt/mantisbt/security/advisories/GHSA-99jc-wqmr-ff2q" target="_blank">security-advisories@github.com</a><br><a href="https://mantisbt.org/bugs/view.php?id=34434" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>matrix-org--matrix-sdk-crypto<br> </td>
<td>The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Matrix, the server-side `key backup` stores encrypted copies of Matrix message keys. This facilitates key sharing between a user's devices and provides a redundant copy in case all devices are lost. The key backup uses asymmetric cryptography, with each server-side key backup assigned a unique public-private key pair. Due to a logic bug introduced in commit 71136e44c03c79f80d6d1a2446673bc4d53a2067, matrix-sdk-crypto version 0.7.0 will sometimes log the private part of the backup key pair to Rust debug logs (using the `tracing` crate). This issue has been resolved in matrix-sdk-crypto version 0.7.1. No known workarounds are available.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34353&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34353" target="_blank">CVE-2024-34353</a><br><a href="https://crates.io/crates/matrix-sdk-crypto/0.7.1" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/matrix-org/matrix-rust-sdk/commit/71136e44c03c79f80d6d1a2446673bc4d53a2067" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/matrix-org/matrix-rust-sdk/commit/fa10bbb5dd0f9120a51aa1854cec752e25790bb0" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/matrix-org/matrix-rust-sdk/releases/tag/matrix-sdk-crypto-0.7.1" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/matrix-org/matrix-rust-sdk/security/advisories/GHSA-9ggc-845v-gcgv" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>matter-labs--era-compiler-solidity<br> </td>
<td>era-compiler-solidity is the ZKsync compiler for Solidity. The problem occurred during instruction selection in the `DAGCombine` phase while visiting the XOR operation. The issue arises when attempting to fold the expression `!(x cc y)` into `(x !cc y)`. To perform this transformation, the second operand of XOR should be a constant representing the true value. However, it was incorrectly assumed that -1 represents the true value, when in fact, 1 is the correct representation, so this transformation for this case should be skipped. This vulnerability is fixed in 1.4.1.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34704&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34704" target="_blank">CVE-2024-34704</a><br><a href="https://github.com/matter-labs/era-compiler-solidity/security/advisories/GHSA-22pj-7cvw-r3gc" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>mgibbs189--Custom Field Suite<br> </td>
<td>The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' parameter in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3068&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3068" target="_blank">CVE-2024-3068</a><br><a href="https://plugins.trac.wordpress.org/browser/custom-field-suite/trunk/templates/field_html.php?order=date&amp;desc=1#L46" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3080330%40custom-field-suite%2Ftrunk&amp;old=3042177%40custom-field-suite%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/0ab546cc-b099-4d26-bf42-785952fcfd8c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>mihdan--Mihdan: Yandex Turbo Feed<br> </td>
<td>The Mihdan: Yandex Turbo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.6.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4411&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4411" target="_blank">CVE-2024-4411</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3081039%40mihdan-yandex-turbo-feed%2Ftrunk&amp;old=3005548%40mihdan-yandex-turbo-feed%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6ecf99ef-f879-426f-8a05-129be77f1157?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>miraheze--CreateWiki<br> </td>
<td>CreateWiki is Miraheze's MediaWiki extension for requesting &amp; creating wikis. It is possible for users to be considered as the requester of a specific wiki request if their local user ID on any wiki in a wiki farm matches the local ID of the requester at the wiki where the wiki request was made. This allows them to go to that request entry's on Special:RequestWikiQueue on the wiki where their local user ID matches and take any actions that the wiki requester is allowed to take from there. Commit 02e0f298f8d35155c39aa74193cb7b867432c5b8 fixes the issue. Important note about the fix: This vulnerability has been fixed by disabling access to the REST API and special pages outside of the wiki configured as the "global wiki" in `$wgCreateWikiGlobalWiki` in a user's MediaWiki settings. As a workaround, it is possible to disable the special pages outside of one's own global wiki by doing something similar to `miraheze/mw-config` commit e5664995fbb8644f9a80b450b4326194f20f9ddc that is adapted to one's own setup. As for the REST API, before the fix, there wasn't any REST endpoint that allowed one to make writes. Regardless, it is possible to also disable it outside of the global wiki by using `$wgCreateWikiDisableRESTAPI` and `$wgConf` in the configuration for one's own wiki farm..</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34701&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34701" target="_blank">CVE-2024-34701</a><br><a href="https://github.com/miraheze/CreateWiki/commit/02e0f298f8d35155c39aa74193cb7b867432c5b8" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/miraheze/CreateWiki/security/advisories/GHSA-89fx-77w7-rc64" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/miraheze/mw-config/commit/1798e53901a202b62edab32f8bcd5c6b9e574191" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/miraheze/mw-config/commit/e5664995fbb8644f9a80b450b4326194f20f9ddc" target="_blank">security-advisories@github.com</a><br><a href="https://issue-tracker.miraheze.org/T12011" target="_blank">security-advisories@github.com</a><br><a href="https://issue-tracker.miraheze.org/T12102" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>monetizemore--Advanced Ads  Ad Manager &amp; AdSense<br> </td>
<td>The Advanced Ads - Ad Manager &amp; AdSense plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Ad widget in all versions up to, and including, 1.52.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3952&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3952" target="_blank">CVE-2024-3952</a><br><a href="https://plugins.trac.wordpress.org/browser/advanced-ads/tags/1.52.1/modules/gutenberg/includes/class-gutenberg.php#L224" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3081914%40advanced-ads&amp;new=3081914%40advanced-ads&amp;sfp_email=&amp;sfph_mail=#file4" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4ea634b5-72db-428c-96b4-15ef6025ab1d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>mra13--Simple Membership<br> </td>
<td>The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4383&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4383" target="_blank">CVE-2024-4383</a><br><a href="https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.4.3/classes/shortcode-related/class.swpm-shortcodes-handler.php#L228" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3081024/simple-membership/trunk/classes/shortcode-related/class.swpm-shortcodes-handler.php?old=3010737&amp;old_path=%2Fsimple-membership%2Ftrunk%2Fclasses%2Fshortcode-related%2Fclass.swpm-shortcodes-handler.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/56fdbf80-8ea2-412a-b166-b7c27de88e70?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>n/a--DedeCMS<br> </td>
<td>A vulnerability classified as problematic has been found in DedeCMS 5.7.114. This affects an unknown part of the file /sys_verifies.php?action=view. The manipulation of the argument filename with the input ../../../../../etc/passwd leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263889 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4790&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4790" target="_blank">CVE-2024-4790</a><br><a href="https://github.com/gatsby2003/DedeCms/blob/main/Directory_traversal_arbitrary_file_read.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263889" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263889" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.329483" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>n/a--Emlog Pro<br> </td>
<td>A vulnerability was found in Emlog Pro 2.3.4 and classified as critical. Affected by this issue is some unknown functionality of the file admin/setting.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264740. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5043&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5043" target="_blank">CVE-2024-5043</a><br><a href="https://github.com/ssteveez/emlog/blob/main/emlog%20pro%20version%202.3.4%20Admin%20side%20can%20upload%20arbitrary%20files%20and%20getshell.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264740" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264740" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331854" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>n/a--Endurance Gaming Mode software installers<br> </td>
<td>Incorrect default permissions in some Endurance Gaming Mode software installers before version 1.3.937.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-42433&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-42433" target="_blank">CVE-2023-42433</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00965.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Advisor software<br> </td>
<td>Uncontrolled search path in some Intel(R) Advisor software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21772&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21772" target="_blank">CVE-2024-21772</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01047.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) BIOS PPAM firmware<br> </td>
<td>Improper conditions check in some Intel(R) BIOS PPAM firmware may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-28383&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-28383" target="_blank">CVE-2023-28383</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00814.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) CST software<br> </td>
<td>Uncontrolled search path for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-40155&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40155" target="_blank">CVE-2023-40155</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01021.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) CST software<br> </td>
<td>Improper access control for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-39433&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-39433" target="_blank">CVE-2023-39433</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01021.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) CST software<br> </td>
<td>Null pointer dereference for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41082&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41082" target="_blank">CVE-2023-41082</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01021.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) CST<br> </td>
<td>Improper access control in some Intel(R) CST before version 2.1.10300 may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43487&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43487" target="_blank">CVE-2023-43487</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01021.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Chipset Device Software<br> </td>
<td>Uncontrolled search path for some Intel(R) Chipset Device Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21814&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21814" target="_blank">CVE-2024-21814</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01032.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Computing Improvement Program software<br> </td>
<td>Uncontrolled search path for some Intel(R) Computing Improvement Program software before version 2.4.0.10654 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21843&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21843" target="_blank">CVE-2024-21843</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01059.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Core(TM) Ultra Processors<br> </td>
<td>Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-46103&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46103" target="_blank">CVE-2023-46103</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01052.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) DLB driver software<br> </td>
<td>Improper input validation for some Intel(R) DLB driver software before version 8.5.0 may allow an authenticated user to potentially denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22015&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22015" target="_blank">CVE-2024-22015</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00996.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) DSA and Intel(R) IAA for some Intel(R) 4th or 5th generation Xeon(R) processors<br> </td>
<td>Hardware logic with insecure de-synchronization in Intel(R) DSA and Intel(R) IAA for some Intel(R) 4th or 5th generation Xeon(R) processors may allow an authorized user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21823&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21823" target="_blank">CVE-2024-21823</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01084.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) DSA software uninstallers<br> </td>
<td>Uncontrolled search path in some Intel(R) DSA software uninstallers before version 23.4.39.10 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45743&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45743" target="_blank">CVE-2023-45743</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01031.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Data Center GPU Max Series 1100 and 1550 products<br> </td>
<td>Improper conditions check in the Intel(R) Data Center GPU Max Series 1100 and 1550 products may allow an privileged user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47165&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47165" target="_blank">CVE-2023-47165</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01041.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Distribution for GDB software<br> </td>
<td>Uncontrolled search path for some Intel(R) Distribution for GDB software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21841&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21841" target="_blank">CVE-2024-21841</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01042.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Ethernet Controller Administrative Tools software<br> </td>
<td>Improper access control in some Intel(R) Ethernet Controller Administrative Tools software before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21828&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21828" target="_blank">CVE-2024-21828</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01056.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) FPGA products<br> </td>
<td>Out of bounds write in firmware for some Intel(R) FPGA products before version 2.9.0 may allow escalation of privilege and information disclosure.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-49614&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-49614" target="_blank">CVE-2023-49614</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01050.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) FPGA products<br> </td>
<td>Improper input validation in firmware for some Intel(R) FPGA products before version 2.9.1 may allow denial of service.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22390&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22390" target="_blank">CVE-2024-22390</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01050.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA Framework software<br> </td>
<td>Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-35192&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-35192" target="_blank">CVE-2023-35192</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA Framework software<br> </td>
<td>Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21861&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21861" target="_blank">CVE-2024-21861</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01067.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA software<br> </td>
<td>Uncontrolled search path in some Intel(R) GPA software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41961&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41961" target="_blank">CVE-2023-41961</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00831.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) GPA software<br> </td>
<td>Uncontrolled search path in some Intel(R) GPA software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21788&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21788" target="_blank">CVE-2024-21788</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01067.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Graphics Windows DCH driver software<br> </td>
<td>Uncontrolled search path in Intel(R) Graphics Command Center Service bundled in some Intel(R) Graphics Windows DCH driver software before versions 31.0.101.3790/31.0.101.2114 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43751&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43751" target="_blank">CVE-2023-43751</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00937.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Inspector software<br> </td>
<td>Uncontrolled search path in some Intel(R) Inspector software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22379&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22379" target="_blank">CVE-2024-22379</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01043.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Media SDK software<br> </td>
<td>Improper input validation in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-48368&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-48368" target="_blank">CVE-2023-48368</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Media SDK<br> </td>
<td>Improper buffer restrictions in Intel(R) Media SDK all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45221&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">4.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45221" target="_blank">CVE-2023-45221</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Neural Compressor software<br> </td>
<td>Time-of-check Time-of-use race condition in Intel(R) Neural Compressor software before version 2.5.0 may allow an authenticated user to potentially enable information disclosure via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21792&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21792" target="_blank">CVE-2024-21792</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01109.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) PCM software<br> </td>
<td>Uncontrolled search path in some Intel(R) PCM software before version 202311 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21818&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21818" target="_blank">CVE-2024-21818</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01035.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) PROSet/Wireless WiFi software for Windows<br> </td>
<td>Race condition for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-40536&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40536" target="_blank">CVE-2023-40536</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) PROSet/Wireless WiFi software for linux<br> </td>
<td>Improper input validation for some Intel(R) PROSet/Wireless WiFi software for linux before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47210&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47210" target="_blank">CVE-2023-47210</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) PROSet/Wireless WiFi software<br> </td>
<td>Improper input validation for some Intel(R) PROSet/Wireless WiFi software before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38417&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38417" target="_blank">CVE-2023-38417</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>Insecure inherited permissions in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45736&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45736" target="_blank">CVE-2023-45736</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windows<br> </td>
<td>NULL pointer dereference in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-41234&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-41234" target="_blank">CVE-2023-41234</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for Windwos<br> </td>
<td>Improper initialization in some Intel(R) Power Gadget software for Windwos all versions may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45315&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45315" target="_blank">CVE-2023-45315</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for macOS<br> </td>
<td>Incomplete cleanup in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45846&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45846" target="_blank">CVE-2023-45846</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Processor Diagnostic Tool software<br> </td>
<td>Uncontrolled search path in some Intel(R) Processor Diagnostic Tool software before version 4.1.9.41 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21831&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21831" target="_blank">CVE-2024-21831</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01069.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Processor Identification Utility software<br> </td>
<td>Uncontrolled search path in some Intel(R) Processor Identification Utility software before versions 6.10.34.1129, 7.1.6 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21774&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21774" target="_blank">CVE-2024-21774</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01054.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Quartus(R) Prime Lite Edition Design software<br> </td>
<td>Improper conditions check for some Intel(R) Quartus(R) Prime Lite Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21809&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21809" target="_blank">CVE-2024-21809</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01055.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Quartus(R) Prime Lite Edition Design software<br> </td>
<td>Uncontrolled search path in some Intel(R) Quartus(R) Prime Lite Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21837&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21837" target="_blank">CVE-2024-21837</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01055.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Quartus(R) Prime Pro Edition Design software<br> </td>
<td>Uncontrolled search path in some Intel(R) Quartus(R) Prime Pro Edition Design software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21777&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21777" target="_blank">CVE-2024-21777</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01055.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Quartus(R) Prime Standard Edition Design software<br> </td>
<td>Uncontrolled search path in some Intel(R) Quartus(R) Prime Standard Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21862&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21862" target="_blank">CVE-2024-21862</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01055.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) TDX module software<br> </td>
<td>Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47855&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47855" target="_blank">CVE-2023-47855</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01036.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) VTune(TM) Profiler software<br> </td>
<td>Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45320&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45320" target="_blank">CVE-2023-45320</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01034.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Wireless Bluetooth products for Windows<br> </td>
<td>Improper access control for some Intel(R) Wireless Bluetooth products for Windows before version 23.20 may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47859&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47859" target="_blank">CVE-2023-47859</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Wireless Bluetooth(R) products for Windows<br> </td>
<td>Improper conditions check for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.20 may allow a privileged user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45845&amp;vector=CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45845" target="_blank">CVE-2023-45845</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01039.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) XTU software<br> </td>
<td>Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-21835&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-21835" target="_blank">CVE-2024-21835</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01066.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Libva software maintained by Intel(R)<br> </td>
<td>Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-39929&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-39929" target="_blank">CVE-2023-39929</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01012.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--UEFI firmware for some Intel(R) Server Board S2600BP products<br> </td>
<td>Improper input validation of EpsdSrMgmtConfig in UEFI firmware for some Intel(R) Server Board S2600BP products may allow a privileged user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-22662&amp;vector=CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:H" target="_blank" title="CVSS V3 Score">5.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-22662" target="_blank">CVE-2023-22662</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01080.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31952&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31952" target="_blank">CVE-2024-31952</a><br><a href="https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31952/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-31953&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31953" target="_blank">CVE-2024-31953</a><br><a href="https://semiconductor.samsung.com/support/quality-support/product-security-updates/cve-2024-31953/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28759&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28759" target="_blank">CVE-2024-28759</a><br><a href="https://support2.windriver.com/index.php?page=cve&amp;on=view&amp;id=CVE-2024-28759" target="_blank">cve@mitre.org</a><br><a href="https://windriver.com/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--onboard video driver software for Intel(R) Server Boards based on Intel(R) 62X Chipset<br> </td>
<td>Incorrect default permissions in some onboard video driver software before version 1.14 for Intel(R) Server Boards based on Intel(R) 62X Chipset may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-42668&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" target="_blank" title="CVSS V3 Score">6.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-42668" target="_blank">CVE-2023-42668</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00962.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>nalam-1--Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )<br> </td>
<td>The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text effect widget in all versions up to, and including, 1.1.37 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2923&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2923" target="_blank">CVE-2024-2923</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3078558%40magical-addons-for-elementor&amp;new=3078558%40magical-addons-for-elementor&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/733f5ded-e8cb-4895-b938-889cea32f027?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>nko--Visual Portfolio, Photo Gallery &amp; Post Grid<br> </td>
<td>The Visual Portfolio, Photo Gallery &amp; Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title_tag' parameter in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4363&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4363" target="_blank">CVE-2024-4363</a><br><a href="https://plugins.trac.wordpress.org/browser/visual-portfolio/trunk/templates/items-list/item-parts/title.php#L22" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/visual-portfolio/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ab5e09d8-6fa3-4a5b-bee1-6648df4f4b3b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>nocodb--nocodb<br> </td>
<td>NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with create access could conduct a SQL Injection attack on MySQL DB using unescaped `table_name`. This vulnerability may result in leakage of sensitive data in the database. Version 0.202.10 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-50718&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-50718" target="_blank">CVE-2023-50718</a><br><a href="https://github.com/nocodb/nocodb/security/advisories/GHSA-8fxg-mr34-jqr8" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>nocodb--nocodb<br> </td>
<td>NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with malicious content. If user tries to open that file in browser malicious scripts can be executed leading stored cross-site scripting attack. This allows remote attacker to execute JavaScript code in the context of the user accessing the vector. An attacker could have used this vulnerability to execute requests in the name of a logged-in user or potentially collect information about the attacked user by displaying a malicious form. Version 0.202.10 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-50717&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-50717" target="_blank">CVE-2023-50717</a><br><a href="https://github.com/nocodb/nocodb/security/advisories/GHSA-qg73-g3cf-vhhh" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>nvidia--ChatRTX<br> </td>
<td>NVIDIA ChatRTX for Windows contains a vulnerability in the ChatRTX UI and backend, where a user can cause a clear-text transmission of sensitive information issue by data sniffing. A successful exploit of this vulnerability might lead to information disclosure.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0098&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0098" target="_blank">CVE-2024-0098</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5533" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>nvidia--NVIDIA Triton Inference Server<br> </td>
<td>NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a user can corrupt system files. A successful exploit of this vulnerability might lead to denial of service and data tampering.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0100&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0100" target="_blank">CVE-2024-0100</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5535" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>nvidia--NVIDIA Triton Inference Server<br> </td>
<td>NVIDIA Triton Inference Server for Linux contains a vulnerability in shared memory APIs, where a user can cause an improper memory access issue by a network API. A successful exploit of this vulnerability might lead to denial of service and data tampering.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0088&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0088" target="_blank">CVE-2024-0088</a><br><a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5535" target="_blank">psirt@nvidia.com</a></td>
</tr>
<tr>
<td>optimole--Image Optimization by Optimole Lazy Load, CDN, Convert WebP &amp; AVIF<br> </td>
<td>The Image Optimization by Optimole - Lazy Load, CDN, Convert WebP &amp; AVIF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allow_meme_types' function in versions up to, and including, 3.12.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4636&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4636" target="_blank">CVE-2024-4636</a><br><a href="https://plugins.trac.wordpress.org/browser/optimole-wp/tags/3.12.10/inc/admin.php#L1828" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086306/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/be88566d-fc84-442d-bb34-834ad9f4465b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>paperless-ngx--paperless-ngx<br> </td>
<td>Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote user authentication allows API access even if API access is explicitly disabled. Version 2.8.6 contains a patchc for the issue.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35184&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35184" target="_blank">CVE-2024-35184</a><br><a href="https://github.com/paperless-ngx/paperless-ngx/commit/ed05b40ba461641b1b59b0a92f51f3f6a66ce180" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/paperless-ngx/paperless-ngx/pull/6739" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/paperless-ngx/paperless-ngx/releases/tag/v2.8.6" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/paperless-ngx/paperless-ngx/security/advisories/GHSA-72w4-hxqq-c256" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>phpbits--Forty Four 404 Plugin for WordPress<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpbits Forty Four - 404 Plugin for WordPress allows Stored XSS.This issue affects Forty Four - 404 Plugin for WordPress: from n/a through 1.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34423&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34423" target="_blank">CVE-2024-34423</a><br><a href="https://patchstack.com/database/vulnerability/forty-four/wordpress-forty-four-404-plugin-for-wordpress-plugin-1-4-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>piotnetdotcom--Piotnet Addons For Elementor<br> </td>
<td>The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.4.26 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4432&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4432" target="_blank">CVE-2024-4432</a><br><a href="https://plugins.trac.wordpress.org/browser/piotnet-addons-for-elementor/trunk/widgets/pafe-before-after-image-comparison-slider.php#L195" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/piotnet-addons-for-elementor/trunk/widgets/pafe-table.php#L195" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087322/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4f65a7df-acb5-4b5b-8867-986ce9930e3f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>posimyththemes--The Plus Addons for Elementor Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce<br> </td>
<td>The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attributes in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor access or higher to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-34373 is likely a duplicate of this issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0445&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0445" target="_blank">CVE-2024-0445</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.3.4/modules/widgets/tp_flip_box.php#L2323" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.3.4/modules/widgets/tp_info_box.php#L2928" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.3.4/modules/widgets/tp_pricing_table.php#L2942" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.5.0/modules/widgets/tp_flip_box.php#L2388" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.5.0/modules/widgets/tp_info_box.php#L2997" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.5.0/modules/widgets/tp_pricing_table.php#L2960" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a412e682-869a-46ba-a2d0-d84ed542adc9?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>posimyththemes--The Plus Addons for Elementor Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce<br> </td>
<td>The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate widget in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2785&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2785" target="_blank">CVE-2024-2785</a><br><a href="https://plugins.trac.wordpress.org/browser/the-plus-addons-for-elementor-page-builder/tags/5.5.0/modules/widgets/tp_age_gate.php?annotate=blame#L2389" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3076733%40the-plus-addons-for-elementor-page-builder&amp;new=3076733%40the-plus-addons-for-elementor-page-builder&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/d0117436-7a2a-42f3-8c05-75dfddfb9d09?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>prasunsen--Hostel<br> </td>
<td>The Hostel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5.3. This is due to missing or incorrect nonce validation when managing rooms. This makes it possible for unauthenticated attackers to create and delete rooms via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4314&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4314" target="_blank">CVE-2024-4314</a><br><a href="https://plugins.trac.wordpress.org/changeset/3079755/hostel/trunk?contextall=1&amp;old=3070681&amp;old_path=%2Fhostel%2Ftrunk" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/6a8c5d9b-4535-4edb-a92e-a9b83a0d22c3?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>pt-guy--Content Views Post Grid &amp; Filter, Recent Posts, Category Posts, &amp; More (Gutenberg Blocks and Shortcode)<br> </td>
<td>The Content Views - Post Grid &amp; Filter, Recent Posts, Category Posts, &amp; More (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pagingType' parameter in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4446&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4446" target="_blank">CVE-2024-4446</a><br><a href="https://plugins.trac.wordpress.org/browser/content-views-query-and-display-post-page/tags/3.7.1/includes/html.php#L803" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/65504747-7f1b-43f9-be4d-48b9547e7c45?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>pure-chat--Pure Chat Live Chat Plugin &amp; More!<br> </td>
<td>The Pure Chat - Live Chat Plugin &amp; More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the purechatwid and purechatwname parameter in all versions up to, and including, 2.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3595&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3595" target="_blank">CVE-2024-3595</a><br><a href="https://wordpress.org/plugins/pure-chat/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5d03c798-dc77-407c-8674-d0bd2f1ada8c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>rankmath--Rank Math SEO with AI Best SEO Tools<br> </td>
<td>The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'textAlign' parameter in versions up to, and including, 1.0.217 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4335&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4335" target="_blank">CVE-2024-4335</a><br><a href="https://plugins.trac.wordpress.org/browser/seo-by-rank-math/tags/1.0.217/includes/modules/schema/blocks/class-block.php#L64" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3080259/#file26" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/96eba67c-58e7-4eea-84d4-9b3bb275b42d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>rankmath--Rank Math SEO with AI Best SEO Tools<br> </td>
<td>The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in versions up to, and including, 1.0.218 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4617&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4617" target="_blank">CVE-2024-4617</a><br><a href="https://plugins.trac.wordpress.org/browser/seo-by-rank-math/trunk/includes/modules/schema/blocks/class-block-faq.php#L183" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084351/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/474fdbcb-fe3c-4a79-a847-363f81b300c2?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>realmag777--WordPress Meta Data and Taxonomies Filter (MDTF)<br> </td>
<td>Incorrect Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Inclusion, Functionality Misuse.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34434&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34434" target="_blank">CVE-2024-34434</a><br><a href="https://patchstack.com/database/vulnerability/wp-meta-data-filter-and-taxonomy-filter/wordpress-mdtf-meta-data-and-taxonomies-filter-plugin-1-3-3-2-arbitrary-shortcode-execution-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>redbitcz--SimpleShop<br> </td>
<td>The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capability check on the maybe_disconnect_simpleshop function in all versions up to, and including, 2.10.2. This makes it possible for unauthenticated attackers to disconnect the SimpleShop.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1229&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1229" target="_blank">CVE-2024-1229</a><br><a href="https://plugins.trac.wordpress.org/browser/simpleshop-cz/trunk/src/Settings.php?rev=3019145#L341" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3080151%40simpleshop-cz&amp;new=3080151%40simpleshop-cz&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4dc39c47-3b99-4e43-b25d-a025f3d228b5?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>redbitcz--SimpleShop<br> </td>
<td>The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.0. This is due to missing or incorrect nonce validation on the maybe_disconnect_simpleshop function. This makes it possible for unauthenticated attackers to disconnect the site from simpleshop via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1230&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1230" target="_blank">CVE-2024-1230</a><br><a href="https://github.com/redbitcz/simpleshop-wp-plugin/commit/8b04c95bb29036658e6a5b1ef735440646e3199b" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/simpleshop-cz/trunk/src/Settings.php?rev=3019145#L341" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9870db7f-0c8e-44a4-aa0f-13709d773756?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>reviewx--ReviewX Multi-criteria Rating &amp; Reviews for WooCommerce<br> </td>
<td>The ReviewX - Multi-criteria Rating &amp; Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.27. This makes it possible for authenticated attackers, with subscriber access and above, to delete attachments.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3609&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3609" target="_blank">CVE-2024-3609</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3086273%40reviewx%2Ftrunk&amp;old=3054184%40reviewx%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f8152adf-1ca9-4a19-b539-39e257ab94c8?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>ruby--rexml<br> </td>
<td>REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a denial of service vulnerability when it parses an XML that has many `&lt;`s in an attribute value. Those who need to parse untrusted XMLs may be impacted to this vulnerability. The REXML gem 3.2.7 or later include the patch to fix this vulnerability. As a workaround, don't parse untrusted XMLs.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35176&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35176" target="_blank">CVE-2024-35176</a><br><a href="https://github.com/ruby/rexml/commit/4325835f92f3f142ebd91a3fdba4e1f1ab7f1cfb" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/ruby/rexml/security/advisories/GHSA-vg3r-rm7w-2xgh" target="_blank">security-advisories@github.com</a><br><a href="https://www.ruby-lang.org/en/news/2024/05/16/dos-rexml-cve-2024-35176" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>sbouey--Falang multilanguage for WordPress<br> </td>
<td>The Falang multilanguage for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.3.49 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4417&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4417" target="_blank">CVE-2024-4417</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3082466%40falang%2Ftrunk&amp;old=3059173%40falang%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b62949fd-d73f-4c42-82c7-c29986bca1da?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>sc0ttkclark--Pods Custom Content Types and Fields<br> </td>
<td>The Pods - Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pod Form widget in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3956&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3956" target="_blank">CVE-2024-3956</a><br><a href="https://plugins.trac.wordpress.org/browser/pods/tags/3.2.1/ui/front/form.php#L105" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083418/pods/tags/3.1.4.1/includes/data.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083418/pods/tags/3.1.4.1/ui/front/form.php" target="_blank">security@wordfence.com</a><br><a href="https://pods.io/2024/05/08/pods-3-2-1-1-security-release/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/a0707c92-96e9-444a-8a13-52d49c9e3f5c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>shaonsina--Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets &amp; Elementor Templates)<br> </td>
<td>The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets &amp; Elementor Templates) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via several parameters in versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4333&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4333" target="_blank">CVE-2024-4333</a><br><a href="https://plugins.trac.wordpress.org/browser/sina-extension-for-elementor/trunk/assets/js/jquery.countdown.min.js" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/sina-extension-for-elementor/trunk/assets/js/typed.min.js" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085825/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f616df94-7839-49db-baa5-88f8f1de208f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>shaonsina--Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets &amp; Elementor Templates)<br> </td>
<td>The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets &amp; Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sina Particle Layer widget in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4373&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4373" target="_blank">CVE-2024-4373</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3085825%40sina-extension-for-elementor&amp;new=3085825%40sina-extension-for-elementor&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/eee04b1d-188a-4b92-a6f3-dfa843ca20d7?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>smartersite--WP Compress Image Optimizer [All-In-One]<br> </td>
<td>The WP Compress - Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the several functions in versions up to, and including, 6.20.01. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to edit plugin settings, including storing cross-site scripting, in multisite environments.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4445&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4445" target="_blank">CVE-2024-4445</a><br><a href="https://plugins.trac.wordpress.org/browser/wp-compress-image-optimizer/trunk/classes/mu.class.php?rev=2946135" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082085/#file655" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/830f53a4-da3b-4a95-99f1-c4a4c8e6944c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>smartersite--WP Compress Image Optimizer [All-In-One]<br> </td>
<td>The WP Compress - Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.20.01. This is due to insufficient validation on the redirect url supplied via the 'css' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-6812&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-6812" target="_blank">CVE-2023-6812</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082085/wp-compress-image-optimizer/trunk/fixCss.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cbbf9fbb-74fd-42eb-a781-2a720fe56b13?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>smartypants--SP Project &amp; Document Manager<br> </td>
<td>The SP Project &amp; Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdm_save_category AJAX action in all versions up to, and including, 4.70. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary folder name that do not belong to them.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-1693&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-1693" target="_blank">CVE-2024-1693</a><br><a href="https://plugins.trac.wordpress.org/browser/sp-client-document-manager/trunk/classes/ajax.php#L786" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/1951ad6c-17b5-44ae-85e2-376b99df742e?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>solidus--solidus<br> </td>
<td>Solidus &lt;= 4.3.4 is affected by a Stored Cross-Site Scripting vulnerability in the order tracking URL.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4859&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N" target="_blank" title="CVSS V3 Score">5.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4859" target="_blank">CVE-2024-4859</a><br><a href="https://www.tenable.com/security/research/tra-2024-15" target="_blank">vulnreport@tenable.com</a></td>
</tr>
<tr>
<td>squelch--Squelch Tabs and Accordions Shortcodes<br> </td>
<td>The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.4.7. This is due to missing or incorrect nonce validation when saving plugin settings. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4463&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4463" target="_blank">CVE-2024-4463</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3082482%40squelch-tabs-and-accordions-shortcodes%2Ftrunk&amp;old=3067680%40squelch-tabs-and-accordions-shortcodes%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/cd9490f2-ad52-477e-ae3b-be49984e8189?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>stacklok--minder<br> </td>
<td>Minder is a software supply chain security platform. Prior to version 0.0.49, the Minder REST ingester is vulnerable to a denial of service attack via an attacker-controlled REST endpoint that can crash the Minder server. The REST ingester allows users to interact with REST endpoints to fetch data for rule evaluation. When fetching data with the REST ingester, Minder sends a request to an endpoint and will use the data from the body of the response as the data to evaluate against a certain rule. If the response is sufficiently large, it can drain memory on the machine and crash the Minder server. The attacker can control the remote REST endpoints that Minder sends requests to, and they can configure the remote REST endpoints to return responses with large bodies. They would then instruct Minder to send a request to their configured endpoint that would return the large response which would crash the Minder server. Version 0.0.49 fixes this issue.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35185&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35185" target="_blank">CVE-2024-35185</a><br><a href="https://github.com/stacklok/minder/commit/065049336aac0621ee00a0bb2211f8051d47c14b" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/stacklok/minder/security/advisories/GHSA-fjw8-3gp8-4cvx" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>stalwartlabs--mail-server<br> </td>
<td>Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, when using `RUN_AS_USER`, the specified user (and therefore, web interface admins) can read arbitrary files as root. This issue affects admins who have set up to run stalwart with `RUN_AS_USER` who handed out admin credentials to the mail server but expect these to only grant access according to the `RUN_AS_USER` and are attacked where the attackers managed to achieve Arbitrary Code Execution using another vulnerability. Version 0.8.0 contains a patch for the issue.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35179&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">6.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35179" target="_blank">CVE-2024-35179</a><br><a href="https://github.com/stalwartlabs/mail-server/security/advisories/GHSA-5pfx-j27j-4c6h" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>stellar--stellar-core<br> </td>
<td>Stellar-core is a reference implementation for the peer-to-peer agent that manages the Stellar network. Prior to 20.4.0, core nodes could be randomly crashed due to a race condition with a 3rd party library. The likelihood of affecting the network is low since crashed nodes come back up online right away. Code fix mitigation is part of Stellar-core v20.4.0 release</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32985&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32985" target="_blank">CVE-2024-32985</a><br><a href="https://github.com/stellar/stellar-core/security/advisories/GHSA-mgx8-frjx-x33m" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>swte--Swift Performance Lite<br> </td>
<td>The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_handler() function in all versions up to, and including, 2.3.6.18. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve and modify settings.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3722&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3722" target="_blank">CVE-2024-3722</a><br><a href="https://plugins.trac.wordpress.org/browser/swift-performance-lite/trunk/includes/setup/setup.php#L97" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/58b7736a-e3e0-4ecd-9adf-284568b02ef7?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>talspotim--Comments Evolved for WordPress<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in talspotim Comments Evolved for WordPress allows Stored XSS.This issue affects Comments Evolved for WordPress: from n/a through 1.6.3.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34420&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34420" target="_blank">CVE-2024-34420</a><br><a href="https://patchstack.com/database/vulnerability/gplus-comments/wordpress-comments-evolved-for-wordpress-plugin-1-6-3-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>techjewel--Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder<br> </td>
<td>The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag &amp; Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in all versions up to, and including, 5.1.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with access to the Fluent Forms settings, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This can be chained with CVE-2024-2771 for a low-privileged user to inject malicious web scripts.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2772&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2772" target="_blank">CVE-2024-2772</a><br><a href="https://plugins.trac.wordpress.org/changeset/3073857" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2ccba77c-fb90-4906-b0fe-77607ec5df1f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>tg123--sshpiper<br> </td>
<td>sshpiper is a reverse proxy for sshd. Starting in version 1.0.50 and prior to version 1.3.0, the way the proxy protocol listener is implemented in sshpiper can allow an attacker to forge their connecting address. Commit 2ddd69876a1e1119059debc59fe869cb4e754430 added the proxy protocol listener as the only listener in sshpiper, with no option to toggle this functionality off. This means that any connection that sshpiper is directly (or in some cases indirectly) exposed to can use proxy protocol to forge its source address. Any users of sshpiper who need logs from it for whitelisting/rate limiting/security investigations could have them become much less useful if an attacker is sending a spoofed source address. Version 1.3.0 contains a patch for the issue.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35175&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35175" target="_blank">CVE-2024-35175</a><br><a href="https://github.com/tg123/sshpiper/commit/2ddd69876a1e1119059debc59fe869cb4e754430" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/tg123/sshpiper/commit/70fb830dca26bea7ced772ce5d834a3e88ae7f53" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/tg123/sshpiper/security/advisories/GHSA-4w53-6jvp-gg52" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>thehappymonster--Happy Addons for Elementor<br> </td>
<td>The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4391&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4391" target="_blank">CVE-2024-4391</a><br><a href="https://plugins.trac.wordpress.org/browser/happy-elementor-addons/trunk/widgets/event-calendar/widget.php#L1811" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083138/happy-elementor-addons/trunk/widgets/event-calendar/widget.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e75f7e1a-f3bb-4b24-bf04-b83d0e572551?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thehappymonster--Happy Addons for Elementor<br> </td>
<td>The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Group widget in all versions up to, and including, 3.10.7 due to insufficient input sanitization and output escaping on user supplied 'tooltip_position' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4478&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4478" target="_blank">CVE-2024-4478</a><br><a href="https://plugins.trac.wordpress.org/browser/happy-elementor-addons/tags/3.10.7/widgets/image-stack-group/widget.php#L611" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083138/#file584" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/happy-elementor-addons/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c7243f40-5cca-475a-bb27-44fab965bb0e?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thehappymonster--Happy Addons for Elementor<br> </td>
<td>The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_id' parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4865&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4865" target="_blank">CVE-2024-4865</a><br><a href="https://plugins.trac.wordpress.org/browser/happy-elementor-addons/trunk/widgets/skills/widget.php#L359" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087575/happy-elementor-addons/trunk/widgets/skills/widget.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2fdf2020-ad80-44c3-89b6-fc2ba067cd33?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thehappymonster--Happy Addons for Elementor<br> </td>
<td>The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_id' parameter in all versions up to, and including, 3.10.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5088&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5088" target="_blank">CVE-2024-5088</a><br><a href="https://plugins.trac.wordpress.org/browser/happy-elementor-addons/trunk/widgets/skills/widget.php#L360" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087575/happy-elementor-addons/trunk/widgets/skills/widget.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/203ab09f-7344-4cab-86bf-0c1ec545d78f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themeisle--Menu Icons by ThemeIsle<br> </td>
<td>The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'add_mime_type' function in versions up to, and including, 0.13.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4635&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4635" target="_blank">CVE-2024-4635</a><br><a href="https://plugins.trac.wordpress.org/browser/menu-icons/tags/0.13.13/vendor/codeinwp/icon-picker/includes/types/svg.php#L69" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086753/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/90284576-6570-4e4c-8eb3-743bc402ea1b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themelooks--Enter Addons Ultimate Template Builder for Elementor<br> </td>
<td>The Enter Addons - Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animation Title widget's img tag in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3680&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3680" target="_blank">CVE-2024-3680</a><br><a href="https://wordpress.org/plugins/enteraddons/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/29cc82cb-f3fd-4de5-9731-7ceb1212b0f9?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themelooks--Enter Addons Ultimate Template Builder for Elementor<br> </td>
<td>The Enter Addons - Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3831&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3831" target="_blank">CVE-2024-3831</a><br><a href="https://wordpress.org/plugins/enteraddons/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/62a4dd6a-f970-483e-b1a8-d57f604b7b66?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themeum--Tutor LMS eLearning and online course solution<br> </td>
<td>The Tutor LMS - eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference to Arbitrary Course Deletion in versions up to, and including, 2.7.0 via the 'tutor_course_delete' function due to missing validation on a user controlled key. This can allow authenticated attackers, with Instructor-level permissions and above, to delete any course.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4279&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4279" target="_blank">CVE-2024-4279</a><br><a href="https://plugins.trac.wordpress.org/browser/tutor/trunk/classes/Course_List.php#L357" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3086489/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/45d04643-e43a-4732-91bf-e4af7b622e33?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>themifyme--Themify Shortcodes<br> </td>
<td>The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themify_button shortcode in all versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4567&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4567" target="_blank">CVE-2024-4567</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082885/themify-shortcodes" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c63ff9d7-6a14-4186-8550-4e5c50855e7f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thimpress--LearnPress WordPress LMS Plugin<br> </td>
<td>The LearnPress - WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_html' parameter in all versions up to, and including, 4.2.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4277&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4277" target="_blank">CVE-2024-4277</a><br><a href="https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.6.5/inc/ExternalPlugin/Elementor/Widgets/Instructor/ListInstructorsElementor.php?order=date#L96" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/46693edf-bcc6-4af8-9f26-5ede865f4694?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thimpress--LearnPress WordPress LMS Plugin<br> </td>
<td>The LearnPress - WordPress LMS Plugin plugin for WordPress is vulnerable to bypass to user registration in versions up to, and including, 4.2.6.5. This is due to missing checks in the 'create_account' function in the checkout. This makes it possible for unauthenticated attackers to register as the default role on the site, even if registration is disabled.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4444&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4444" target="_blank">CVE-2024-4444</a><br><a href="https://inky-knuckle-2c2.notion.site/Improper-Authentication-in-checkout-leads-privilege-escalation-of-unauthenticated-to-create-accoun-09da24a043884219a891dd1a0fc01af6" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/learnpress/tags/4.2.6.5/inc/class-lp-checkout.php#L79" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082204/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c9e1410f-10c9-4654-8b61-cfcdde696da7?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>thimpress--Thim Elementor Kit<br> </td>
<td>The Thim Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4329&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4329" target="_blank">CVE-2024-4329</a><br><a href="https://plugins.trac.wordpress.org/browser/thim-elementor-kit/tags/1.1.9.1/inc/elementor/widgets/global/search-form.php#L819" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3275c47d-caf5-49e6-8aa2-20a6d8106f26?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>tigroumeow--Gallery Block (Meow Gallery)<br> </td>
<td>The Gallery Block (Meow Gallery) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_atts' parameter in versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4386&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4386" target="_blank">CVE-2024-4386</a><br><a href="https://plugins.trac.wordpress.org/browser/meow-gallery/trunk/classes/core.php#L273" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082976/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/477b41a5-b2ff-4b94-9622-824146a0e2ed?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>timstrifler--Exclusive Addons for Elementor<br> </td>
<td>The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Member widget in all versions up to, and including, 2.6.9.6 due to insufficient input sanitization and output escaping on user supplied 'url' attribute. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4618&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4618" target="_blank">CVE-2024-4618</a><br><a href="https://plugins.trac.wordpress.org/browser/exclusive-addons-for-elementor/tags/2.6.9.6/elements/team-member/team-member.php#L1696" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083582/#file4" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/exclusive-addons-for-elementor/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2e82478c-e476-4cdf-ab72-f578331058e2?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>trinhtuantai--Viet Affiliate Link<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in trinhtuantai Viet Affiliate Link allows Stored XSS.This issue affects Viet Affiliate Link: from n/a through 1.2.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34422&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">5.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34422" target="_blank">CVE-2024-34422</a><br><a href="https://patchstack.com/database/vulnerability/viet-affiliate-link/wordpress-viet-affiliate-link-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>uapp--Testimonial Carousel For Elementor<br> </td>
<td>The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'show_line_text ' and 'slide_button_hover_animation' parameters in versions up to, and including, 10.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4698&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4698" target="_blank">CVE-2024-4698</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel-blog.php#L1076" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel-bottom.php#L1478" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel-centered.php#L1619" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel-gallery-coverflow.php#L1876" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel-logo.php#L1715" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/testimonials-carousel-elementor/trunk/widgets/testimonials-carousel/class-testimonialscarousel.php#L1847" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087862/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4542b0f8-c9ee-4992-b737-e5f727c7b5b0?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>unitecms--Unlimited Elements For Elementor (Free Widgets, Addons, Templates)<br> </td>
<td>The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_connect_error' parameter in all versions up to, and including, 1.5.102 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3547&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3547" target="_blank">CVE-2024-3547</a><br><a href="https://plugins.trac.wordpress.org/changeset/3071404/unlimited-elements-for-elementor/trunk/inc_php/unitecreator_settings_output.class.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f629fc93-84ce-4c33-b1c0-3a3194aac477?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>upwerd--Visual Footer Credit Remover<br> </td>
<td>The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'selector' parameter in all versions up to, and including, 2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-2846&amp;vector=CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2846" target="_blank">CVE-2024-2846</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3081401%40visual-footer-credit-remover&amp;new=3081401%40visual-footer-credit-remover&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/9fcb65a0-4218-4728-9c29-0d1a03f438a6?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>videousermanuals--White Label CMS<br> </td>
<td>The White Label CMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_plugin function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to reset plugin settings.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4280&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4280" target="_blank">CVE-2024-4280</a><br><a href="https://plugins.trac.wordpress.org/changeset/3082887/white-label-cms" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/13a206ea-0890-4535-9da7-54a7a45f0452?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>villatheme--Orders Tracking for WooCommerce<br> </td>
<td>The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.10. This is due to the plugin allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. A partial patch was released in 1.2.10, and a complete patch was released in 1.2.11.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4039&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4039" target="_blank">CVE-2024-4039</a><br><a href="https://plugins.trac.wordpress.org/browser/woo-orders-tracking/trunk/includes/frontend/frontend.php#L55" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3083652%40woo-orders-tracking&amp;new=3083652%40woo-orders-tracking&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/991ab188-869c-4875-80f3-940000a1717b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>visualmodo--Borderless Widgets, Elements, Templates and Toolkit for Elementor &amp; Gutenberg<br> </td>
<td>The Borderless - Widgets, Elements, Templates and Toolkit for Elementor &amp; Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4666&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4666" target="_blank">CVE-2024-4666</a><br><a href="https://plugins.trac.wordpress.org/browser/borderless/trunk/modules/elementor/widgets/circular-progress-bar.php#L427" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/borderless/trunk/modules/elementor/widgets/progress-bar.php#L412" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/borderless/trunk/modules/elementor/widgets/semi-circular-progress-bar.php#L403" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/borderless/trunk/modules/elementor/widgets/team-member.php#L1101" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/borderless/trunk/modules/elementor/widgets/testimonial.php#L905" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085856/" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/borderless/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/b6840637-9b0f-4f3d-bb73-9e4527a5f326?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>weForms--weForms<br> </td>
<td>Client-Side Enforcement of Server-Side Security vulnerability in weForms allows Removing Important Client Functionality.This issue affects weForms: from n/a through 1.6.20.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32512&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32512" target="_blank">CVE-2024-32512</a><br><a href="https://patchstack.com/database/vulnerability/weforms/wordpress-weforms-plugin-1-6-20-form-submission-restriction-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>webdevmattcrom--GiveWP Donation Plugin and Fundraising Platform<br> </td>
<td>The GiveWP - Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode when used with a legacy form in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3714&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3714" target="_blank">CVE-2024-3714</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083390/give/tags/3.11.0/includes/class-give-donate-form.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/dd8f5cfa-3431-4617-b2cd-d5a8ce4530f4?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>webtechideas--WTI Like Post<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in webtechideas WTI Like Post allows Functionality Bypass.This issue affects WTI Like Post: from n/a through 1.4.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33917&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33917" target="_blank">CVE-2024-33917</a><br><a href="https://patchstack.com/database/vulnerability/wti-like-post/wordpress-wti-like-post-plugin-1-4-6-ip-restriction-bypass-vulnerability-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>wolfi-dev--wolfictl<br> </td>
<td>wolfictl is a command line tool for working with Wolfi. A git authentication issue in versions prior to 0.16.10 allows a local user's GitHub token to be sent to remote servers other than `github.com`. Most git-dependent functionality in wolfictl relies on its own `git` package, which contains centralized logic for implementing interactions with git repositories. Some of this functionality requires authentication in order to access private repositories. A central function `GetGitAuth` looks for a GitHub token in the environment variable `GITHUB_TOKEN` and returns it as an HTTP basic auth object to be used with the `github.com/go-git/go-git/v5` library. Most callers (direct or indirect) of `GetGitAuth` use the token to authenticate to github.com only; however, in some cases callers were passing this authentication without checking that the remote git repository was hosted on github.com. This behavior has existed in one form or another since commit 0d06e1578300327c212dda26a5ab31d09352b9d0 - committed January 25, 2023. This impacts anyone who ran the `wolfictl check update` commands with a Melange configuration that included a `git-checkout` directive step that referenced a git repository not hosted on github.com. This also impacts anyone who ran `wolfictl update &lt;url&gt;` with a remote URL outside of github.com. Additionally, these subcommands must have run with the `GITHUB_TOKEN` environment variable set to a valid GitHub token. Users should upgrade to version 0.16.10 to receive a patch.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35183&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N" target="_blank" title="CVSS V3 Score">4.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35183" target="_blank">CVE-2024-35183</a><br><a href="https://github.com/wolfi-dev/wolfictl/blob/488b53823350caa706de3f01ec0eded9350c7da7/pkg/update/update.go#L143" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/wolfi-dev/wolfictl/blob/4dd6c95abb4bc0f9306350a8601057bd7a92bded/pkg/update/deps/cleanup.go#L49" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/wolfi-dev/wolfictl/blob/6d99909f7b1aa23f732d84dad054b02a61f530e6/pkg/git/git.go#L22" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/wolfi-dev/wolfictl/commit/0d06e1578300327c212dda26a5ab31d09352b9d0" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/wolfi-dev/wolfictl/commit/403e93569f46766b4e26e06cf9cd0cae5ee0c2a2" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/wolfi-dev/wolfictl/security/advisories/GHSA-8fg7-hp93-qhvr" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>wpdevteam--EmbedPress Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps &amp; Embed Any Documents in Gutenberg &amp; Elementor<br> </td>
<td>The EmbedPress - Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps &amp; Embed Any Documents in Gutenberg &amp; Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all versions up to, and including, 3.9.16 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4316&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4316" target="_blank">CVE-2024-4316</a><br><a href="https://plugins.trac.wordpress.org/browser/embedpress/trunk/EmbedPress/Elementor/Widgets/Embedpress_Elementor.php#L3076" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/2af03168-9344-4db0-9b69-2ad1fdb6d472?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpdevteam--Essential Addons for Elementor Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders<br> </td>
<td>The Essential Addons for Elementor - Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Interactive Circle widget in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4275&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4275" target="_blank">CVE-2024-4275</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083162/essential-addons-for-elementor-lite/tags/5.9.20/includes/Elements/Interactive_Circle.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/91f50b65-f001-4c73-bfe3-1aed3fc10d26?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpdevteam--Essential Addons for Elementor Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders<br> </td>
<td>The Essential Addons for Elementor - Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Dual Color Header', 'Event Calendar', &amp; 'Advanced Data Table' widgets in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4448&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4448" target="_blank">CVE-2024-4448</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083162/essential-addons-for-elementor-lite/tags/5.9.20/includes/Elements/Advanced_Data_Table.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083162/essential-addons-for-elementor-lite/tags/5.9.20/includes/Elements/Dual_Color_Header.php" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3083162/essential-addons-for-elementor-lite/tags/5.9.20/includes/Elements/Event_Calendar.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/21e12c72-7898-4896-9852-ebb10e5f9a3b?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpdevteam--Essential Addons for Elementor Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders<br> </td>
<td>The Essential Addons for Elementor - Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Fancy Text', 'Filter Gallery', 'Sticky Video', 'Content Ticker', 'Woo Product Gallery', &amp; 'Twitter Feed' widgets in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4449&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4449" target="_blank">CVE-2024-4449</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;old=3083162%40essential-addons-for-elementor-lite&amp;new=3083162%40essential-addons-for-elementor-lite&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/57ed6c7e-ca8d-476d-adce-905b2cd2eda8?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpdevteam--Essential Addons for Elementor Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders<br> </td>
<td>The Essential Addons for Elementor - Best Elementor Templates, Widgets, Kits &amp; WooCommerce Builders plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eael_ext_toc_title_tag' parameter in versions up to, and including, 5.9.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4624&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4624" target="_blank">CVE-2024-4624</a><br><a href="https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/tags/5.9.19/includes/Traits/Elements.php#L550" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085420/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/bedad627-0ccb-41c1-be8d-753f57be618f?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpdevteam--Essential Blocks Page Builder Gutenberg Blocks, Patterns &amp; Templates<br> </td>
<td>The Essential Blocks - Page Builder Gutenberg Blocks, Patterns &amp; Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tagName' parameter in versions up to, and including, 4.5.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-18</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4891&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4891" target="_blank">CVE-2024-4891</a><br><a href="https://plugins.trac.wordpress.org/browser/essential-blocks/trunk/blocks/AdvancedHeading.php#L115" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3087677/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e1bcebb3-920b-40cc-aa5c-24a1f729b28d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpexpertsio--Password Protected Ultimate Plugin to Password Protect Your WordPress Content with Ease<br> </td>
<td>The Password Protected - Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.6 via the API. This makes it possible for authenticated attackers, with subscriber access or higher, to extract post titles and content, thus bypassing the plugin's password protection.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0437&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0437" target="_blank">CVE-2024-0437</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3034934%40password-protected%2Ftrunk&amp;old=3005632%40password-protected%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/f3045ebf-70af-4124-9116-42c07f64a3bf?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpjoli--Joli FAQ SEO WordPress FAQ Plugin<br> </td>
<td>The Joli FAQ SEO - WordPress FAQ Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing or incorrect nonce validation when saving settings. This makes it possible for unauthenticated attackers to change the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4082&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">4.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4082" target="_blank">CVE-2024-4082</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3081648%40joli-faq-seo%2Ftrunk&amp;old=3076380%40joli-faq-seo%2Ftrunk&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c45b6163-7ebf-4f18-afd6-735d02d9170d?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpkube--Simple Basic Contact Form<br> </td>
<td>The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 20240502. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on the functionality of other plugins installed in the environment.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4144&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4144" target="_blank">CVE-2024-4144</a><br><a href="https://plugins.trac.wordpress.org/browser/simple-basic-contact-form/trunk/simple-basic-contact-form.php#L543" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3085036/" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ded1944f-662d-4d25-8277-4b1dc63b2144?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpkube--Simple Basic Contact Form<br> </td>
<td>The Simple Basic Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'scf_email' parameter in versions up to, and including, 20221201 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4150&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4150" target="_blank">CVE-2024-4150</a><br><a href="https://plugins.trac.wordpress.org/browser/simple-basic-contact-form/trunk/simple-basic-contact-form.php#L122" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3080540" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/22074d7a-5dbd-4a0c-bc5d-e4c983e5edb4?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wproyal--Royal Elementor Addons and Templates<br> </td>
<td>The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form Builder widget in all versions up to, and including, 1.3.974 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3887&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">5.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3887" target="_blank">CVE-2024-3887</a><br><a href="https://plugins.trac.wordpress.org/changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3086890%40royal-elementor-addons&amp;old=3081886%40royal-elementor-addons&amp;sfp_email=&amp;sfph_mail=" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5122800d-f274-4129-84d4-02380269502c?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>wpsurface--BlogLentor<br> </td>
<td>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsurface BlogLentor allows Stored XSS.This issue affects BlogLentor: from n/a through 1.0.8.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34421&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" target="_blank" title="CVSS V3 Score">6.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34421" target="_blank">CVE-2024-34421</a><br><a href="https://patchstack.com/database/vulnerability/bloglentor-for-elementor/wordpress-bloglentor-blog-designer-pack-for-elementor-plugin-1-0-8-cross-site-scripting-xss-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>wpzoom--WPZOOM Addons for Elementor (Templates, Widgets)<br> </td>
<td>The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget Image Box in all versions up to, and including, 1.1.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4370&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4370" target="_blank">CVE-2024-4370</a><br><a href="https://plugins.trac.wordpress.org/browser/wpzoom-elementor-addons/trunk/includes/widgets/image-box/image-box.php#L1229" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084540" target="_blank">security@wordfence.com</a><br><a href="https://wordpress.org/plugins/wpzoom-elementor-addons/#developers" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/c7aaff3e-0c81-4fe7-b162-569c517f6c49?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>xpro--140+ Widgets | Best Addons For Elementor FREE<br> </td>
<td>The 140+ Widgets | Best Addons For Elementor - FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4440&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4440" target="_blank">CVE-2024-4440</a><br><a href="https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/contact-form/contact-form.php#L1438" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/course-grid/course-grid.php#L1918" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/custom-field/custom-field.php#L1150" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/post-grid/post-grid.php#L1829" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/woo-product-grid/woo-product-grid.php#L3812" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/5596197e-149d-4072-9fa4-424c9ffd6059?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>yithemes--YITH WooCommerce Gift Cards<br> </td>
<td>The YITH WooCommerce Gift Cards plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_mail_status' and 'save_email_settings' functions in all versions up to, and including, 4.12.0. This makes it possible for unauthenticated attackers to modify WooCommerce settings.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-0870&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">5.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-0870" target="_blank">CVE-2024-0870</a><br><a href="https://plugins.trac.wordpress.org/changeset/3084519/yith-woocommerce-gift-cards/trunk/includes/admin/class-ywgc-admin.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/ca1f0dc6-c0bc-4e9f-b3b6-d6274aa7a7db?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>yoast--Yoast SEO<br> </td>
<td>The Yoast SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 22.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4041&amp;vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4041" target="_blank">CVE-2024-4041</a><br><a href="https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/inc/class-wpseo-admin-bar-menu.php#L601" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/inc/class-wpseo-shortlinker.php#L20" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/src/helpers/short-link-helper.php#L105" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/browser/wordpress-seo/trunk/src/helpers/short-link-helper.php#L45" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3078555/wordpress-seo/trunk#file129" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/4e04b161-3cd0-454d-869c-56f42bd8afb0?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
<tr>
<td>yoast--Yoast SEO<br> </td>
<td>The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name' author meta in all versions up to, and including, 22.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4984&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">6.4</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4984" target="_blank">CVE-2024-4984</a><br><a href="https://developer.yoast.com/changelog/yoast-seo/22.7/" target="_blank">security@wordfence.com</a><br><a href="https://github.com/Yoast/wordpress-seo/pull/21334" target="_blank">security@wordfence.com</a><br><a href="https://plugins.trac.wordpress.org/changeset/3079234/wordpress-seo/trunk/src/presenters/slack/enhanced-data-presenter.php" target="_blank">security@wordfence.com</a><br><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/59bcd246-ca2f-4336-9a6e-89afe873ed25?source=cve" target="_blank">security@wordfence.com</a></td>
</tr>
</tbody>
</table>
<p><a href="https://www.cisa.gov/#top">Back to top</a></p>
</div>
<div>
<h2>Low Vulnerabilities</h2>
<table summary="Low Vulnerabilities" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th scope="col" role="columnheader" data-tablesaw-priority="persist">Primary<br>Vendor -- Product</th>
<th scope="col" role="columnheader">Description</th>
<th scope="col" role="columnheader">Published</th>
<th scope="col" role="columnheader">CVSS Score</th>
<th scope="col" role="columnheader">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>Bill Minozzi--Car Dealer<br> </td>
<td>Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Bill Minozzi Car Dealer allows Code Injection.This issue affects Car Dealer: from n/a through 4.15.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4214&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">2.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4214" target="_blank">CVE-2024-4214</a><br><a href="https://patchstack.com/database/vulnerability/cardealer/wordpress-cardealer-plugin-4-15-content-injection-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/show_student_subject.php. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263593 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4672&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4672" target="_blank">CVE-2024-4672</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2022.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263593" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263593" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331307" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown functionality of the file /view/show_student_grade_subject.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263594 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4673&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4673" target="_blank">CVE-2024-4673</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2023.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263594" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263594" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331308" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /view/show_friend_request.php. The manipulation of the argument my_index leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263595.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4674&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4674" target="_blank">CVE-2024-4674</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2024.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263595" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263595" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331310" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /view/show_events.php. The manipulation of the argument event_id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263596.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4675&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4675" target="_blank">CVE-2024-4675</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2025.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263596" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263596" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331312" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /view/range_grade_text.php. The manipulation of the argument count leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263597 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4676&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4676" target="_blank">CVE-2024-4676</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2026.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263597" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263597" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331313" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /view/my_student_exam_marks1.php. The manipulation of the argument year leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263598 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4677&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4677" target="_blank">CVE-2024-4677</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2027.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263598" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263598" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331314" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /view/find_friends.php. The manipulation of the argument my_type leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263599.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4678&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4678" target="_blank">CVE-2024-4678</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2028.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263599" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263599" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331315" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /view/exam_timetable_update_form.php. The manipulation of the argument exam leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263623.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4682&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4682" target="_blank">CVE-2024-4682</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2029.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263623" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263623" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331772" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /view/exam_timetable_insert_form.php. The manipulation of the argument exam leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263624.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4683&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4683" target="_blank">CVE-2024-4683</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2030.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263624" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263624" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331773" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /view/exam_timetable_grade_wise.php. The manipulation of the argument exam leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263625 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4684&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4684" target="_blank">CVE-2024-4684</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2031.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263625" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263625" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331774" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /view/exam_timetable.php. The manipulation of the argument exam leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263626 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4685&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4685" target="_blank">CVE-2024-4685</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2032.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263626" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263626" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331775" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /view/emarks_range_grade_update_form.php. The manipulation of the argument grade leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263627.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4686&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4686" target="_blank">CVE-2024-4686</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2033.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263627" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263627" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331776" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/create_events.php. The manipulation of the argument my_index leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263628.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4687&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4687" target="_blank">CVE-2024-4687</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2034.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263628" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263628" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331777" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/conversation_history_admin.php. The manipulation of the argument conversation_id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263629 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4688&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4688" target="_blank">CVE-2024-4688</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2035.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263629" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263629" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331778" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/all_teacher.php. The manipulation of the argument page leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263791.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4713&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4713" target="_blank">CVE-2024-4713</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2036.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263791" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263791" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331879" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown functionality of the file /model/update_subject.php. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263792.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4714&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4714" target="_blank">CVE-2024-4714</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2037.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263792" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263792" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331880" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /model/update_grade.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263793 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4715&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4715" target="_blank">CVE-2024-4715</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2038.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263793" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263793" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331881" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /model/update_exam.php. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263794 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4716&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4716" target="_blank">CVE-2024-4716</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2039.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263794" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263794" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331882" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /model/update_classroom.php. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263795.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4717&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4717" target="_blank">CVE-2024-4717</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2040.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263795" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263795" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331883" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /model/delete_student_grade_subject.php. The manipulation of the argument index leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263796.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4718&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4718" target="_blank">CVE-2024-4718</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2041.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263796" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263796" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331884" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /model/delete_record.php. The manipulation of the argument page leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263797 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4719&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4719" target="_blank">CVE-2024-4719</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2042.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263797" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263797" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331885" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /model/approve_petty_cash.php. The manipulation of the argument admin_index leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263798 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4720&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4720" target="_blank">CVE-2024-4720</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2043.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263798" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263798" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331886" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file /model/add_student_subject.php. The manipulation of the argument index leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263799.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4721&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4721" target="_blank">CVE-2024-4721</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2044.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263799" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263799" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331887" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Complete Web-Based School Management System<br> </td>
<td>A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument category leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263800.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4722&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4722" target="_blank">CVE-2024-4722</a><br><a href="https://github.com/E1CHO/cve_hub/blob/main/Complete%20Web-Based%20School%20Management%20System%20-%20xss/Complete%20Web-Based%20School%20Management%20System%20-%20vuln%2045.pdf" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263800" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263800" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331888" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability, which was classified as problematic, has been found in Campcodes Legal Case Management System 1.0. This issue affects some unknown processing of the file /admin/case-status. The manipulation of the argument case_status leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263801 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4723&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4723" target="_blank">CVE-2024-4723</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_case-status.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263801" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263801" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331982" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability, which was classified as problematic, was found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the file /admin/case-type. The manipulation of the argument case_type_name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263802 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4724&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4724" target="_blank">CVE-2024-4724</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_case-type.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263802" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263802" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331983" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability has been found in Campcodes Legal Case Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/client_user. The manipulation of the argument f_name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263803.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4725&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4725" target="_blank">CVE-2024-4725</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_client_user.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263803" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263803" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331988" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/clients. The manipulation of the argument f_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263804.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4726&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4726" target="_blank">CVE-2024-4726</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_clients.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263804" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263804" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331989" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/court-type. The manipulation of the argument court_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263805 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4727&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4727" target="_blank">CVE-2024-4727</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_court-type.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263805" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263805" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331990" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/court. The manipulation of the argument court_name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-263806 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4728&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4728" target="_blank">CVE-2024-4728</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_court.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263806" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263806" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331992" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/expense-type. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263807.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4729&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4729" target="_blank">CVE-2024-4729</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_expense-type.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263807" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263807" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331993" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability classified as problematic has been found in Campcodes Legal Case Management System 1.0. Affected is an unknown function of the file /admin/judge. The manipulation of the argument judge_name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263808.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4730&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4730" target="_blank">CVE-2024-4730</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_judge.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263808" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263808" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331994" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability classified as problematic was found in Campcodes Legal Case Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/role. The manipulation of the argument slug leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263809 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4731&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4731" target="_blank">CVE-2024-4731</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_role.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263809" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263809" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331995" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability, which was classified as problematic, has been found in Campcodes Legal Case Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/service. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263810 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4732&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4732" target="_blank">CVE-2024-4732</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_service.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263810" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263810" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331996" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability has been found in Campcodes Legal Case Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/tasks. The manipulation of the argument task_subject leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263821 was assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4735&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4735" target="_blank">CVE-2024-4735</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_tasks.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263821" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263821" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332408" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/tax. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263822 is the identifier assigned to this vulnerability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4736&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4736" target="_blank">CVE-2024-4736</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_tax.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263822" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263822" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332409" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/vendor. The manipulation of the argument company_name/mobile leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263823.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4737&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4737" target="_blank">CVE-2024-4737</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_vendor.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263823" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263823" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332411" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Legal Case Management System<br> </td>
<td>A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code. The manipulation of the argument new_client leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263824.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4738&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4738" target="_blank">CVE-2024-4738</a><br><a href="https://github.com/yylmm/CVE/blob/main/Legal%20Case%20Management%20System/xss_admin_appointment.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263824" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263824" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332412" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Campcodes--Online Laundry Management System<br> </td>
<td>A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /ajax.php. The manipulation of the argument name/customer_name/username leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263896.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4797&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4797" target="_blank">CVE-2024-4797</a><br><a href="https://github.com/yylmm/CVE/blob/main/Online%20Laundry%20Management%20System/xss_action.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.263896" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.263896" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.332539" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>Filipe Seabra--WordPress Manuteno<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in Filipe Seabra WordPress ManutenÃ§Ã£o allows Functionality Bypass.This issue affects WordPress ManutenÃ§Ã£o: from n/a through 1.0.6.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22139&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22139" target="_blank">CVE-2024-22139</a><br><a href="https://patchstack.com/database/vulnerability/wp-manutencao/wordpress-wordpress-manutencao-plugin-1-0-6-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>Huawei--HarmonyOS<br> </td>
<td>Insufficient verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32989&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">3.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32989" target="_blank">CVE-2024-32989</a><br><a href="https://consumer.huawei.com/en/support/bulletin/2024/5/" target="_blank">psirt@huawei.com</a><br><a href="https://device.harmonyos.com/cn/docs/security/update/security-bulletins-phones-202405-0000001902628049" target="_blank">psirt@huawei.com</a></td>
</tr>
<tr>
<td>IBM--Security Guardium<br> </td>
<td>IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force ID: 271526.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47711&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">2.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47711" target="_blank">CVE-2023-47711</a><br><a href="https://exchange.xforce.ibmcloud.com/vulnerabilities/271526" target="_blank">psirt@us.ibm.com</a><br><a href="https://www.ibm.com/support/pages/node/7150840" target="_blank">psirt@us.ibm.com</a></td>
</tr>
<tr>
<td>JetBrains--TeamCity<br> </td>
<td>In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-35300&amp;vector=CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35300" target="_blank">CVE-2024-35300</a><br><a href="https://www.jetbrains.com/privacy-security/issues-fixed/" target="_blank">cve@jetbrains.com</a></td>
</tr>
<tr>
<td>Nozomi Networks--Arc<br> </td>
<td>On Windows systems, the Arc configuration files resulted to be world-readable. This can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration files.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-5937&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5937" target="_blank">CVE-2023-5937</a><br><a href="https://security.nozominetworks.com/NN-2023:15-01" target="_blank">prodsec@nozominetworks.com</a></td>
</tr>
<tr>
<td>OpenText--iManager<br> </td>
<td>Broken Authentication vulnerability discovered in OpenTextâ„¢ iManager 3.2.6.0200. This vulnerability allows an attacker to manipulate certain parameters to bypass authentication.</td>
<td>2024-05-15</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-3487&amp;vector=CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3487" target="_blank">CVE-2024-3487</a><br><a href="https://www.netiq.com/documentation/imanager-32/imanager326_patch3_hf1_releasenotes/data/imanager326_patch3_hf1_releasenotes.html" target="_blank">security@opentext.com</a></td>
</tr>
<tr>
<td>Pippin Williamson--CGC Maintenance Mode<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in Pippin Williamson CGC Maintenance Mode allows Functionality Bypass.This issue affects CGC Maintenance Mode: from n/a through 1.2.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-30480&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30480" target="_blank">CVE-2024-30480</a><br><a href="https://patchstack.com/database/vulnerability/cgc-maintenance-mode/wordpress-cgc-maintenance-mode-plugin-1-2-ip-filtering-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAP Bank Account Management<br> </td>
<td>SAP Bank Account Management does not perform necessary authorization check for an authorized user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality to the system.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33000&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33000" target="_blank">CVE-2024-33000</a><br><a href="https://me.sap.com/notes/3392049" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>SAP_SE--SAPUI5 (PDFViewer)<br> </td>
<td>PDFViewer is a control delivered as part of SAPUI5 product which shows the PDF content in an embedded mode by default. If a PDF document contains embedded JavaScript (or any harmful client-side script), the PDFViewer will execute the JavaScript embedded in the PDF which can cause a potential security threat.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33007&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33007" target="_blank">CVE-2024-33007</a><br><a href="https://me.sap.com/notes/3446076" target="_blank">cna@sap.com</a><br><a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html" target="_blank">cna@sap.com</a></td>
</tr>
<tr>
<td>Siemens--Parasolid V35.1<br> </td>
<td>A vulnerability has been identified in Parasolid V35.1 (All versions &lt; V35.1.256), Parasolid V36.0 (All versions &lt; V36.0.208), Parasolid V36.1 (All versions &lt; V36.1.173). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted X_T files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32637&amp;vector=CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">3.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32637" target="_blank">CVE-2024-32637</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-046364.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>Siemens--SIMATIC RTLS Locating Manager<br> </td>
<td>A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA30) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA10) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA20) (All versions &lt; V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-1EA30) (All versions &lt; V3.0.1.1). Affected application contains a hidden configuration item to enable debug functionality. This could allow an authenticated local attacker to gain insight into the internal configuration of the deployment.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-33583&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33583" target="_blank">CVE-2024-33583</a><br><a href="https://cert-portal.siemens.com/productcert/html/ssa-093430.html" target="_blank">productcert@siemens.com</a></td>
</tr>
<tr>
<td>SourceCodester--Interactive Map with Marker<br> </td>
<td>A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file Marker Name of the component Add Marker. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264536.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4968&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4968" target="_blank">CVE-2024-4968</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Interactive%20Map%20App/Interactive%20Map%20App%20-%20Cross-Site-Scripting.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264536" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264536" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335191" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>SourceCodester--Simple Image Stack Website<br> </td>
<td>A vulnerability, which was classified as problematic, was found in SourceCodester Simple Image Stack Website 1.0. This affects an unknown part. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264459.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4922&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4922" target="_blank">CVE-2024-4922</a><br><a href="https://github.com/HuoMingZ/aoligei/blob/main/ceshi.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264459" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264459" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.333760" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>TYPO3--typo3<br> </td>
<td>TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, adversaries can still inject malicious HTML markup. Exploiting this vulnerability requires a valid backend user account. TYPO3 version 13.1.1 fixes the problem described.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34355&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34355" target="_blank">CVE-2024-34355</a><br><a href="https://github.com/TYPO3/typo3/commit/56afa304ba8b5ad302e15df5def71bcc8d820375" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/TYPO3/typo3/security/advisories/GHSA-xjwx-78x7-q6jc" target="_blank">security-advisories@github.com</a><br><a href="https://typo3.org/security/advisory/typo3-core-sa-2024-007" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>Wireshark Foundation--editcap<br> </td>
<td>Memory handling issue in editcap could cause denial of service via crafted capture file</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4853&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">3.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4853" target="_blank">CVE-2024-4853</a><br><a href="https://gitlab.com/wireshark/wireshark/-/issues/19724" target="_blank">cve@gitlab.com</a><br><a href="https://www.wireshark.org/security/wnpa-sec-2024-08.html" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>Wireshark Foundation--editcap<br> </td>
<td>Use after free issue in editcap could cause denial of service via crafted capture file</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4855&amp;vector=CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">3.6</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4855" target="_blank">CVE-2024-4855</a><br><a href="https://gitlab.com/wireshark/wireshark/-/issues/19782" target="_blank">cve@gitlab.com</a><br><a href="https://gitlab.com/wireshark/wireshark/-/issues/19783" target="_blank">cve@gitlab.com</a><br><a href="https://gitlab.com/wireshark/wireshark/-/issues/19784" target="_blank">cve@gitlab.com</a><br><a href="https://www.wireshark.org/security/wnpa-sec-2024-08.html" target="_blank">cve@gitlab.com</a></td>
</tr>
<tr>
<td>cea-hpc--sshproxy<br> </td>
<td>sshproxy is used on a gateway to transparently proxy a user SSH connection on the gateway to an internal host via SSH. Prior to version 1.6.3, any user authorized to connect to a ssh server using `sshproxy` can inject options to the `ssh` command executed by `sshproxy`. All versions of `sshproxy` are impacted. The problem is patched starting in version 1.6.3. The only workaround is to use the `force_command` option in `sshproxy.yaml`, but it's rarely relevant.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34713&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34713" target="_blank">CVE-2024-34713</a><br><a href="https://github.com/cea-hpc/sshproxy/commit/f7eabd05d5f0f951e160293692327cad9a7d9580" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/cea-hpc/sshproxy/security/advisories/GHSA-jmqp-37m5-49wh" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>code-projects--Simple Chat System<br> </td>
<td>A vulnerability, which was classified as problematic, was found in code-projects Simple Chat System 1.0. Affected is an unknown function of the file /register.php. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264540.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4974&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4974" target="_blank">CVE-2024-4974</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Simple%20Chat%20App/Simple%20Chat%20App%20-%20Cross-Site-Scripting-1.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264540" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264540" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335205" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>code-projects--Simple Chat System<br> </td>
<td>A vulnerability, which was classified as problematic, has been found in code-projects Simple Chat System 1.0. This issue affects some unknown processing of the component Message Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264539.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4975&amp;vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.5</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4975" target="_blank">CVE-2024-4975</a><br><a href="https://github.com/BurakSevben/CVEs/blob/main/Simple%20Chat%20App/Simple%20Chat%20App%20-%20Cross-Site-Scripting-2.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264539" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264539" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.335206" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>git--git<br> </td>
<td>Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, local clones may end up hardlinking files into the target repository's object database when source and target repository reside on the same disk. If the source repository is owned by a different user, then those hardlinked files may be rewritten at any point in time by the untrusted user. Cloning local repositories will cause Git to either copy or hardlink files of the source repository into the target repository. This significantly speeds up such local clones compared to doing a "proper" clone and saves both disk space and compute time. When cloning a repository located on the same disk that is owned by a different user than the current user we also end up creating such hardlinks. These files will continue to be owned and controlled by the potentially-untrusted user and can be rewritten by them at will in the future. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32020&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">3.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32020" target="_blank">CVE-2024-32020</a><br><a href="https://github.com/git/git/commit/1204e1a824c34071019fe106348eaa6d88f9528d" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/commit/9e65df5eab274bf74c7b570107aacd1303a1e703" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/git/git/security/advisories/GHSA-5rfh-556j-fhgj" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>git--git<br> </td>
<td>Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that contains symlinks via the filesystem, Git may create hardlinks to arbitrary user-readable files on the same filesystem as the target repository in the `objects/` directory. Cloning a local repository over the filesystem may creating hardlinks to arbitrary user-owned files on the same filesystem in the target Git repository's `objects/` directory. When cloning a repository over the filesystem (without explicitly specifying the `file://` protocol or `--no-local`), the optimizations for local cloning will be used, which include attempting to hard link the object files instead of copying them. While the code includes checks against symbolic links in the source repository, which were added during the fix for CVE-2022-39253, these checks can still be raced because the hard link operation ultimately follows symlinks. If the object on the filesystem appears as a file during the check, and then a symlink during the operation, this will allow the adversary to bypass the check and create hardlinks in the destination objects directory to arbitrary, user-readable files. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32021&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">3.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32021" target="_blank">CVE-2024-32021</a><br><a href="https://github.com/git/git/security/advisories/GHSA-mvxm-9j2h-qjx7" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>gocd--gocd<br> </td>
<td>GoCD is a continuous delivery server. GoCD versions from 19.4.0 to 23.5.0 (inclusive) are potentially vulnerable to a reflected cross-site scripting vulnerability on the loading page displayed while GoCD is starting, via abuse of a `redirect_to` query parameter with inadequate validation. Attackers could theoretically abuse the query parameter to steal session tokens or other values from the user's browser. In practice exploiting this to perform privileged actions is likely rather difficult to exploit because the target user would need to be triggered to open an attacker-crafted link in the period where the server is starting up (but not completely started), requiring chaining with a separate denial-of-service vulnerability. Additionally, GoCD server restarts invalidate earlier session tokens (i.e GoCD does not support persistent sessions), so a stolen session token would be unusable once the server has completed restart, and executed XSS would be done within a logged-out context. The issue is fixed in GoCD 24.1.0. As a workaround, it is technically possible in earlier GoCD versions to override the loading page with an earlier version which is not vulnerable, by starting GoCD with the Java system property override as either `-Dloading.page.resource.path=/loading_pages/default.loading.page.html` (simpler early version of loading page without GoCD introduction) or `-Dloading.page.resource.path=/does_not_exist.html` (to display a simple message with no interactivity).</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-28866&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" target="_blank" title="CVSS V3 Score">3.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28866" target="_blank">CVE-2024-28866</a><br><a href="https://github.com/gocd/gocd/commit/388d8893ec4cac51d2b76e923cc9b55c7703e402" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/gocd/gocd/releases/tag/24.1.0" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/gocd/gocd/security/advisories/GHSA-q882-q6mm-mgvh" target="_blank">security-advisories@github.com</a><br><a href="https://www.gocd.org/releases/#24-1-0" target="_blank">security-advisories@github.com</a></td>
</tr>
<tr>
<td>helderk--Maintenance Mode<br> </td>
<td>Authentication Bypass by Spoofing vulnerability in helderk Maintenance Mode allows Functionality Bypass.This issue affects Maintenance Mode: from n/a through 3.0.1.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-32708&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32708" target="_blank">CVE-2024-32708</a><br><a href="https://patchstack.com/database/vulnerability/hkdev-maintenance-mode/wordpress-maintenance-mode-plugin-3-0-1-ip-bypass-vulnerability?_s_id=cve" target="_blank">audit@patchstack.com</a></td>
</tr>
<tr>
<td>n/a--Emlog Pro<br> </td>
<td>A vulnerability was found in Emlog Pro 2.3.4. It has been classified as problematic. This affects an unknown part of the component Cookie Handler. The manipulation of the argument AuthCookie leads to improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The identifier VDB-264741 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.</td>
<td>2024-05-17</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-5044&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5044" target="_blank">CVE-2024-5044</a><br><a href="https://github.com/ssteveez/emlog/blob/main/emlog%20pro%20version%202.3.4%20has%20session(AuthCookie)%20persistence%20and%20any%20user%20login%20vulnerability.md" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?ctiid.264741" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?id.264741" target="_blank">cna@vuldb.com</a><br><a href="https://vuldb.com/?submit.331857" target="_blank">cna@vuldb.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) CBI software<br> </td>
<td>Improper input validation in some Intel(R) CBI software before version 1.1.0 may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-43745&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">2.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-43745" target="_blank">CVE-2023-43745</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01013.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Media SDK and some Intel(R) oneVPL software<br> </td>
<td>Out-of-bounds read in Intel(R) Media SDK and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-22656&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" target="_blank" title="CVSS V3 Score">3.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-22656" target="_blank">CVE-2023-22656</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Media SDK software<br> </td>
<td>Improper buffer restrictions in Intel(R) Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47169&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">3.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47169" target="_blank">CVE-2023-47169</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Power Gadget software for macOS<br> </td>
<td>Improper conditions check in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable information disclosure via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-38420&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-38420" target="_blank">CVE-2023-38420</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01037.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Processors<br> </td>
<td>Hardware logic contains race conditions in some Intel(R) Processors may allow an authenticated user to potentially enable partial information disclosure via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-45733&amp;vector=CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">2.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-45733" target="_blank">CVE-2023-45733</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01051.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) Trace Analyzer and Collector software<br> </td>
<td>Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 2022.0.0 published Nov 2023 may allow an authenticated user to potentially enable information disclosure via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-22384&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">2.8</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22384" target="_blank">CVE-2024-22384</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00983.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) oneVPL software<br> </td>
<td>Out-of-bounds write in Intel(R) Media SDK all versions and some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable escalation of privilege via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-47282&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L" target="_blank" title="CVSS V3 Score">3.9</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-47282" target="_blank">CVE-2023-47282</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--Intel(R) oneVPL software<br> </td>
<td>NULL pointer dereference in some Intel(R) oneVPL software before version 23.3.5 may allow an authenticated user to potentially enable information disclosure via local access.</td>
<td>2024-05-16</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2023-48727&amp;vector=CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.3</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-48727" target="_blank">CVE-2023-48727</a><br><a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00935.html" target="_blank">secure@intel.com</a></td>
</tr>
<tr>
<td>n/a--PostgreSQL<br> </td>
<td>Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected.</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-4317&amp;vector=CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" target="_blank" title="CVSS V3 Score">3.1</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4317" target="_blank">CVE-2024-4317</a><br><a href="https://www.postgresql.org/support/security/CVE-2024-4317/" target="_blank">f86ef6dc-4d3a-42ad-8f28-e6d5547a5007</a></td>
</tr>
<tr>
<td>octo-sts--app<br> </td>
<td>octo-sts is a GitHub App that acts like a Security Token Service (STS) for the Github API. This vulnerability can spike the resource utilization of the STS service, and combined with a significant traffic volume could potentially lead to a denial of service. This vulnerability is fixed in 0.1.0</td>
<td>2024-05-14</td>
<td><a href="https://nvd.nist.gov/cvss.cfm?version=2&amp;name=CVE-2024-34079&amp;vector=CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" target="_blank" title="CVSS V3 Score">3.7</a></td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34079" target="_blank">CVE-2024-34079</a><br><a href="https://github.com/octo-sts/app/commit/74ba874c017cf973edd6711144cf4399a9fcff57" target="_blank">security-advisories@github.com</a><br><a href="https://github.com/octo-sts/app/security/advisories/GHSA-75r6-6jg8-pfcq" target="_blank">security-advisories@github.com</a></td>
</tr>
</tbody>
</table>
<p><a href="https://www.cisa.gov/#top">Back to top</a></p>
</div>
<div>
<h2>Severity Not Yet Assigned</h2>
<table summary="Severity Not Yet Assigned" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th scope="col" role="columnheader" data-tablesaw-priority="persist">Primary<br>Vendor -- Product</th>
<th scope="col" role="columnheader">Description</th>
<th scope="col" role="columnheader">Published</th>
<th scope="col" role="columnheader">CVSS Score</th>
<th scope="col" role="columnheader">Source &amp; Patch Info</th>
</tr>
</thead>
<tbody>
<tr>
<td>Aidin--Phormer<br> </td>
<td>Phormer prior to version 3.35 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote unauthenticated attacker may execute an arbitrary script on the web browser of the user.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34749" target="_blank">CVE-2024-34749</a><br><a href="http://p.horm.org/er/" target="_blank">vultures@jpcert.or.jp</a><br><a href="https://github.com/eyedean/phormer" target="_blank">vultures@jpcert.or.jp</a><br><a href="https://jvn.jp/en/jp/JVN61054671/" target="_blank">vultures@jpcert.or.jp</a><br><a href="https://sourceforge.net/projects/rephormer/" target="_blank">vultures@jpcert.or.jp</a></td>
</tr>
<tr>
<td>Ant Media--Ant Media Server Community Edition<br> </td>
<td>Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative API calls reserved only for authorized users.  All versions up to 2.9.0 (tested) and possibly newer ones are believed to be vulnerable as the vendor has not confirmed releasing a patch.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3462" target="_blank">CVE-2024-3462</a><br><a href="https://antmedia.io/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/en/posts/2024/05/CVE-2024-3462" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/05/CVE-2024-3462" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Apache Software Foundation--Apache Airflow<br> </td>
<td>Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs.  Users are recommended to upgrade to version 2.9.1, which fixes this issue.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32077" target="_blank">CVE-2024-32077</a><br><a href="https://github.com/apache/airflow/pull/38882" target="_blank">security@apache.org</a><br><a href="https://lists.apache.org/thread/gsjmnrqb3m5fzp0vgpty1jxcywo91v77" target="_blank">security@apache.org</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Ventura 13.6.7, macOS Sonoma 14.4. An app may be able to access user-sensitive data.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27789" target="_blank">CVE-2024-27789</a><br><a href="https://support.apple.com/en-us/HT214084" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214100" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214105" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214107" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An attacker may be able to elevate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27796" target="_blank">CVE-2024-27796</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A permissions issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to share items from the lock screen.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27803" target="_blank">CVE-2024-27803</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An app may be able to execute arbitrary code with kernel privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27804" target="_blank">CVE-2024-27804</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214102" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214104" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An app may be able to read sensitive location information.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27810" target="_blank">CVE-2024-27810</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214102" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214104" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A logic issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, watchOS 10.5, macOS Sonoma 14.5. An attacker may be able to access user data.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27816" target="_blank">CVE-2024-27816</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214102" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214104" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An attacker may be able to cause unexpected app termination or arbitrary code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27818" target="_blank">CVE-2024-27818</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. A shortcut may output sensitive user data without consent.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27821" target="_blank">CVE-2024-27821</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214104" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, Safari 17.5, watchOS 10.5, macOS Sonoma 14.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27834" target="_blank">CVE-2024-27834</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214102" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214103" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214104" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to access notes from the lock screen.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27835" target="_blank">CVE-2024-27835</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iPadOS 17.5. A malicious application may be able to determine a user's current location.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27839" target="_blank">CVE-2024-27839</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to disclose kernel memory.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27841" target="_blank">CVE-2024-27841</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>This issue was addressed with improved checks This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to bypass Privacy preferences.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27847" target="_blank">CVE-2024-27847</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iOS and iPadOS<br> </td>
<td>A privacy issue was addressed with improved client ID handling for alternative app marketplaces. This issue is fixed in iOS 17.5 and iPadOS 17.5. A maliciously crafted webpage may be able to distribute a script that tracks users on other webpages.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27852" target="_blank">CVE-2024-27852</a><br><a href="https://support.apple.com/en-us/HT214101" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--iTunes for Windows<br> </td>
<td>The issue was addressed with improved checks. This issue is fixed in iTunes 12.13.2 for Windows. Parsing a file may lead to an unexpected app termination or arbitrary code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27793" target="_blank">CVE-2024-27793</a><br><a href="https://support.apple.com/en-us/HT214099" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.5, macOS Ventura 13.6.5, macOS Sonoma 14.4. A malicious application may be able to access Find My data.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23229" target="_blank">CVE-2024-23229</a><br><a href="https://support.apple.com/en-us/HT214084" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214085" target="_blank">product-security@apple.com</a><br><a href="https://support.apple.com/en-us/HT214105" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to read arbitrary files.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-23236" target="_blank">CVE-2024-23236</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>An authorization issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.5. An attacker may be able to elevate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27798" target="_blank">CVE-2024-27798</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27813" target="_blank">CVE-2024-27813</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to gain root privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27822" target="_blank">CVE-2024-27822</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.5. An app may be able to elevate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27824" target="_blank">CVE-2024-27824</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to bypass certain Privacy preferences.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27825" target="_blank">CVE-2024-27825</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.5. An app may be able to read arbitrary files.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27827" target="_blank">CVE-2024-27827</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.5. Processing a file may lead to unexpected app termination or arbitrary code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27829" target="_blank">CVE-2024-27829</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. A local attacker may gain access to Keychain items.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27837" target="_blank">CVE-2024-27837</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to execute arbitrary code with kernel privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27842" target="_blank">CVE-2024-27842</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Apple--macOS<br> </td>
<td>A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to elevate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27843" target="_blank">CVE-2024-27843</a><br><a href="https://support.apple.com/en-us/HT214106" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>CEMI Tomasz Paweek--CemiPark<br> </td>
<td>The access control in CemiPark software does not properly validate user-entered data, which allows the authentication bypass. An attacker who has network access to the login panel can log in with administrator rights to the application.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4423" target="_blank">CVE-2024-4423</a><br><a href="http://cemi.pl/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/en/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>CEMI Tomasz Paweek--CemiPark<br> </td>
<td>The access control in CemiPark software does not properly validate user-entered data, which allows the stored cross-site scripting (XSS) attack. The parameters used to enter data into the system do not have appropriate validation, which makes possible to smuggle in HTML/JavaScript code. This code will be executed in the user's browser space.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4424" target="_blank">CVE-2024-4424</a><br><a href="http://cemi.pl/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/en/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>CEMI Tomasz Paweek--CemiPark<br> </td>
<td>The access control in CemiPark software stores integration (e.g. FTP or SIP) credentials in plain-text. An attacker who gained unauthorized access to the device can retrieve clear text passwords used by the system.This issue affects CemiPark software: 4.5, 4.7, 5.03 and potentially others. The vendor refused to provide the specific range of affected products.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4425" target="_blank">CVE-2024-4425</a><br><a href="http://cemi.pl/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/en/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/05/CVE-2024-4423/" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Claris--FileMaker Server<br> </td>
<td>Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by eliminating the send of Admin Role passwords in the Node.js socket.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-42955" target="_blank">CVE-2023-42955</a><br><a href="https://support.claris.com/s/article/Administrator-role-passwords-being-exposed-when-logged-into-the-Admin-Console?language=en_US" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Claris--FileMaker Server<br> </td>
<td>Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in FileMaker Server 20.3.2 by validating transactions before replying to client requests.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27790" target="_blank">CVE-2024-27790</a><br><a href="https://support.claris.com/s/answerview?anum=000041674&amp;language=en_US" target="_blank">product-security@apple.com</a></td>
</tr>
<tr>
<td>Devolutions--Server<br> </td>
<td>Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5072" target="_blank">CVE-2024-5072</a><br><a href="https://devolutions.net/security/advisories/DEVO-2024-0007" target="_blank">security@devolutions.net</a></td>
</tr>
<tr>
<td>Digisol--Digisol Router DG-GR1321<br> </td>
<td>This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to improper implementation of password policies. An attacker with physical access could exploit this by creating password that do not adhere to the defined security standards/policy on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to expose the router to potential security threats.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2257" target="_blank">CVE-2024-2257</a><br><a href="https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&amp;VLCODE=CIVN-2024-0158" target="_blank">vdisclose@cert-in.org.in</a></td>
</tr>
<tr>
<td>Digisol--Digisol Router DG-GR1321<br> </td>
<td>This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by identifying UART pins and accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to access the sensitive information on the targeted system.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4231" target="_blank">CVE-2024-4231</a><br><a href="https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&amp;VLCODE=CIVN-2024-0158" target="_blank">vdisclose@cert-in.org.in</a></td>
</tr>
<tr>
<td>Digisol--Digisol Router DG-GR1321<br> </td>
<td>This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by identifying UART pins and accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to access the sensitive information on the targeted system.This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to lack of encryption or hashing in storing of passwords within the router's firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext passwords on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4232" target="_blank">CVE-2024-4232</a><br><a href="https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&amp;VLCODE=CIVN-2024-0158" target="_blank">vdisclose@cert-in.org.in</a></td>
</tr>
<tr>
<td>Google--Chrome<br> </td>
<td>Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4761" target="_blank">CVE-2024-4761</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_13.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/339458194" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>Google--Chrome<br> </td>
<td>Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4947" target="_blank">CVE-2024-4947</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/340221135" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>Google--Chrome<br> </td>
<td>Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4948" target="_blank">CVE-2024-4948</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/333414294" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>Google--Chrome<br> </td>
<td>Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4949" target="_blank">CVE-2024-4949</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/326607001" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>Google--Chrome<br> </td>
<td>Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4950" target="_blank">CVE-2024-4950</a><br><a href="https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html" target="_blank">chrome-cve-admin@google.com</a><br><a href="https://issues.chromium.org/issues/40065403" target="_blank">chrome-cve-admin@google.com</a></td>
</tr>
<tr>
<td>HP Inc.--Plantronics Hub<br> </td>
<td>A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27460" target="_blank">CVE-2024-27460</a><br><a href="https://support.hp.com/us-en/document/ish_9869257-9869285-16/hpsbpy03895" target="_blank">hp-security-alert@hp.com</a></td>
</tr>
<tr>
<td>Ligowave--UNITY<br> </td>
<td>A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through 2-5.95-4.Rt3352.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4999" target="_blank">CVE-2024-4999</a><br><a href="https://onekey.com/blog/security-advisory-remote-code-execution-in-ligowave-devices/" target="_blank">research@onekey.com</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: disable sending io_uring over sockets File reference cycles have caused lots of problems for io_uring in the past, and it still doesn't work exactly right and races with unix_stream_read_generic(). The safest fix would be to completely disallow sending io_uring files via sockets via SCM_RIGHT, so there are no possible cycles invloving registered files and thus rendering SCM accounting on the io_uring side unnecessary.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52654" target="_blank">CVE-2023-52654</a><br><a href="https://git.kernel.org/stable/c/18824f592aad4124d79751bbc1500ea86ac3ff29" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3fe1ea5f921bf5b71cbfdc4469fb96c05936610e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5a33d385eb36991a91e3dddb189d8679e2aac2be" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/705318a99a138c29a512a72c3e0043b3cd7f55f4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bcedd497b3b4a0be56f3adf7c7542720eced0792" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f2f57f51b53be153a522300454ddb3887722fb2c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: aqc111: check packet for fixup for true limit If a device sends a packet that is inbetween 0 and sizeof(u64) the value passed to skb_trim() as length will wrap around ending up as some very large value. The driver will then proceed to parse the header located at that position, which will either oops or process some random value. The fix is to check against sizeof(u64) rather than 0, which the driver currently does. The issue exists since the introduction of the driver.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52655" target="_blank">CVE-2023-52655</a><br><a href="https://git.kernel.org/stable/c/2ebf775f0541ae0d474836fa0cf3220e502f8e3e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/46412b2fb1f9cc895d6d4036bf24f640b5d86dab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/82c386d73689a45d5ee8c1290827bce64056dddd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/84f2e5b3e70f08fce3cb1ff73414631c5e490204" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ccab434e674ca95d483788b1895a70c21b7f016a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d69581c17608d81824dd497d9a54b6a5b6139975" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_uring: drop any code related to SCM_RIGHTS This is dead code after we dropped support for passing io_uring fds over SCM_RIGHTS, get rid of it.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52656" target="_blank">CVE-2023-52656</a><br><a href="https://git.kernel.org/stable/c/6e5e6d274956305f1fc0340522b38f5f5be74bdb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/88c49d9c896143cdc0f77197c4dcf24140375e89" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a3812a47a32022ca76bf46ddacdd823dc2aabf8b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a6771f343af90a25f3a14911634562bb5621df02" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cfb24022bb2c31f1f555dc6bc3cc5e2547446fb3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d909d381c3152393421403be4b6435f17a2378b4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Revert "drm/amd/pm: resolve reboot exception for si oland" This reverts commit e490d60a2f76bff636c68ce4fe34c1b6c34bbd86. This causes hangs on SI when DC is enabled and errors on driver reboot and power off cycles.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52657" target="_blank">CVE-2023-52657</a><br><a href="https://git.kernel.org/stable/c/2e443ed55fe3ffb08327b331a9f45e9382413c94" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/955558030954b9637b41c97b730f9b38c92ac488" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/baac292852c0e347626fb5436916947188e5838f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c51468ac328d3922747be55507c117e47da813e6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Revert "net/mlx5: Block entering switchdev mode with ns inconsistency" This reverts commit 662404b24a4c4d839839ed25e3097571f5938b9b. The revert is required due to the suspicion it is not good for anything and cause crash.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52658" target="_blank">CVE-2023-52658</a><br><a href="https://git.kernel.org/stable/c/1bcdd66d33edb446903132456c948f0b764ef2f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3fba8eab2cfc7334e0f132d29dfd2552f2f2a579" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8deeefb24786ea7950b37bde4516b286c877db00" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: x86/mm: Ensure input to pfn_to_kaddr() is treated as a 64-bit type On 64-bit platforms, the pfn_to_kaddr() macro requires that the input value is 64 bits in order to ensure that valid address bits don't get lost when shifting that input by PAGE_SHIFT to calculate the physical address to provide a virtual address for. One such example is in pvalidate_pages() (used by SEV-SNP guests), where the GFN in the struct used for page-state change requests is a 40-bit bit-field, so attempts to pass this GFN field directly into pfn_to_kaddr() ends up causing guest crashes when dealing with addresses above the 1TB range due to the above. Fix this issue with SEV-SNP guests, as well as any similar cases that might cause issues in current/future code, by using an inline function, instead of a macro, so that the input is implicitly cast to the expected 64-bit input type prior to performing the shift operation. While it might be argued that the issue is on the caller side, other archs/macros have taken similar approaches to deal with instances like this, such as ARM explicitly casting the input to phys_addr_t: e48866647b48 ("ARM: 8396/1: use phys_addr_t in pfn_to_kaddr()") A C inline function is even better though. [ mingo: Refined the changelog some more &amp; added __always_inline. ]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52659" target="_blank">CVE-2023-52659</a><br><a href="https://git.kernel.org/stable/c/325956b0173f11e98f90462be4829a8b8b0682ce" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7e1471888a5e6e846e9b4d306e5327db2b58e64e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/814305b5c23cb815ada68d43019f39050472b25f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8e5647a723c49d73b9f108a8bb38e8c29d3948ea" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: media: rkisp1: Fix IRQ handling due to shared interrupts The driver requests the interrupts as IRQF_SHARED, so the interrupt handlers can be called at any time. If such a call happens while the ISP is powered down, the SoC will hang as the driver tries to access the ISP registers. This can be reproduced even without the platform sharing the IRQ line: Enable CONFIG_DEBUG_SHIRQ and unload the driver, and the board will hang. Fix this by adding a new field, 'irqs_enabled', which is used to bail out from the interrupt handler when the ISP is not operational.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52660" target="_blank">CVE-2023-52660</a><br><a href="https://git.kernel.org/stable/c/abd34206f396d3ae50cddbd5aa840b8cd7f68c63" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b39b4d207d4f236a74e20d291f6356f2231fd9ee" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/edcf92bc66d8361c51dff953a55210e5cfd95587" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ffb635bb398fc07cb38f8a7b4a82cbe5f412f08e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/tegra: rgb: Fix missing clk_put() in the error handling paths of tegra_dc_rgb_probe() If clk_get_sys(..., "pll_d2_out0") fails, the clk_get_sys() call must be undone. Add the missing clk_put and a new 'put_pll_d_out0' label in the error handling path, and use it.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52661" target="_blank">CVE-2023-52661</a><br><a href="https://git.kernel.org/stable/c/2388c36e028fff7f8ffd515681a14c6c2c07fea7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/45c8034db47842b25a3ab6139d71e13b4e67b9b3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5c8dc26e31b8b410ad1895e0d314def50c76eed0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/845322a9c06dd1dcf35b6c4e3af89684297c23cc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f3f407ccbe84a34de9be3195d22cdd5969f3fd9f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fa74e4f5d0821829545b9f7034a0e577c205c101" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: fix a memleak in vmw_gmrid_man_get_node When ida_alloc_max fails, resources allocated before should be freed, including *res allocated by kmalloc and ttm_resource_init.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52662" target="_blank">CVE-2023-52662</a><br><a href="https://git.kernel.org/stable/c/03b1072616a8f7d6e8594f643b416a9467c83fbf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/40624af6674745e174c754a20d7c53c250e65e7a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6fc6233f6db1579b69b54b44571f1a7fde8186e6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/83e0f220d1e992fa074157fcf14945bf170ffbc5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/89709105a6091948ffb6ec2427954cbfe45358ce" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d1e546ab91c670e536a274a75481034ab7534876" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: amd: Fix memory leak in amd_sof_acp_probe() Driver uses kasprintf() to initialize fw_{code,data}_bin members of struct acp_dev_data, but kfree() is never called to deallocate the memory, which results in a memory leak. Fix the issue by switching to devm_kasprintf(). Additionally, ensure the allocation was successful by checking the pointer validity.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52663" target="_blank">CVE-2023-52663</a><br><a href="https://git.kernel.org/stable/c/222be59e5eed1554119294edc743ee548c2371d0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7296152e58858f928db448826eb7ba5ae611297b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/88028c45d5871dfc449b2b0a27abf6428453a5ec" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/be4760799c6a7c01184467287f0de41e0dd255f8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: atlantic: eliminate double free in error handling logic Driver has a logic leak in ring data allocation/free, where aq_ring_free could be called multiple times on same ring, if system is under stress and got memory allocation error. Ring pointer was used as an indicator of failure, but this is not correct since only ring data is allocated/deallocated. Ring itself is an array member. Changing ring allocation functions to return error code directly. This simplifies error handling and eliminates aq_ring_free on higher layer.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52664" target="_blank">CVE-2023-52664</a><br><a href="https://git.kernel.org/stable/c/0edb3ae8bfa31cd544b0c195bdec00e036002b5d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b3cb7a830a24527877b0bc900b9bd74a96aea928" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c11a870a73a3bc4cc7df6dd877a45b181795fcbf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d1fde4a7e1dcc4d49cce285107a7a43c3030878d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: powerpc/ps3_defconfig: Disable PPC64_BIG_ENDIAN_ELF_ABI_V2 Commit 8c5fa3b5c4df ("powerpc/64: Make ELFv2 the default for big-endian builds"), merged in Linux-6.5-rc1 changes the calling ABI in a way that is incompatible with the current code for the PS3's LV1 hypervisor calls. This change just adds the line '# CONFIG_PPC64_BIG_ENDIAN_ELF_ABI_V2 is not set' to the ps3_defconfig file so that the PPC64_ELF_ABI_V1 is used. Fixes run time errors like these: BUG: Kernel NULL pointer dereference at 0x00000000 Faulting instruction address: 0xc000000000047cf0 Oops: Kernel access of bad area, sig: 11 [#1] Call Trace: [c0000000023039e0] [c00000000100ebfc] ps3_create_spu+0xc4/0x2b0 (unreliable) [c000000002303ab0] [c00000000100d4c4] create_spu+0xcc/0x3c4 [c000000002303b40] [c00000000100eae4] ps3_enumerate_spus+0xa4/0xf8</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52665" target="_blank">CVE-2023-52665</a><br><a href="https://git.kernel.org/stable/c/482b718a84f08b6fc84879c3e90cc57dba11c115" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d0f0780f03df54d08ced118d27834ee5008724e4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f70557d48215b14a9284ac3a6ae7e4ee1d039f10" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix potential circular locking issue in smb2_set_ea() smb2_set_ea() can be called in parent inode lock range. So add get_write argument to smb2_set_ea() not to call nested mnt_want_write().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52666" target="_blank">CVE-2023-52666</a><br><a href="https://git.kernel.org/stable/c/5349fd419e4f685d609c85b781f2b70f0fb14848" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6fc0a265e1b932e5e97a038f99e29400a93baad0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e61fc656ceeaec65f19a92f0ffbeb562b7941e8d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e9ec6665de8f706b4f4133b87b2bd02a159ec57b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ecfd93955994ecc2a1308f5ee4bd90c7fca9a8c6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix a potential double-free in fs_any_create_groups When kcalloc() for ft-&gt;g succeeds but kvzalloc() for in fails, fs_any_create_groups() will free ft-&gt;g. However, its caller fs_any_create_table() will free ft-&gt;g again through calling mlx5e_destroy_flow_table(), which will lead to a double-free. Fix this by setting ft-&gt;g to NULL in fs_any_create_groups().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52667" target="_blank">CVE-2023-52667</a><br><a href="https://git.kernel.org/stable/c/2897c981ee63e1be5e530b1042484626a10b26d8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/65a4ade8a6d205979292e88beeb6a626ddbd4779" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/72a729868592752b5a294d27453da264106983b1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/aef855df7e1bbd5aa4484851561211500b22707e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b2fa86b2aceb4bc9ada51cea90f61546d7512cbe" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix lock ordering in btrfs_zone_activate() The btrfs CI reported a lockdep warning as follows by running generic generic/129. WARNING: possible circular locking dependency detected 6.7.0-rc5+ #1 Not tainted ------------------------------------------------------ kworker/u5:5/793427 is trying to acquire lock: ffff88813256d028 (&amp;cache-&gt;lock){+.+.}-{2:2}, at: btrfs_zone_finish_one_bg+0x5e/0x130 but task is already holding lock: ffff88810a23a318 (&amp;fs_info-&gt;zone_active_bgs_lock){+.+.}-{2:2}, at: btrfs_zone_finish_one_bg+0x34/0x130 which lock already depends on the new lock. the existing dependency chain (in reverse order) is: -&gt; #1 (&amp;fs_info-&gt;zone_active_bgs_lock){+.+.}-{2:2}: ... -&gt; #0 (&amp;cache-&gt;lock){+.+.}-{2:2}: ... This is because we take fs_info-&gt;zone_active_bgs_lock after a block_group's lock in btrfs_zone_activate() while doing the opposite in other places. Fix the issue by expanding the fs_info-&gt;zone_active_bgs_lock's critical section and taking it before a block_group's lock.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52668" target="_blank">CVE-2023-52668</a><br><a href="https://git.kernel.org/stable/c/1908e9d01e5395adff68d9d308a0fb15337e6272" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6f74989f5909cdec9b1274641f0fa306b15bb476" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b18f3b60b35a8c01c9a2a0f0d6424c6d73971dc3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: crypto: s390/aes - Fix buffer overread in CTR mode When processing the last block, the s390 ctr code will always read a whole block, even if there isn't a whole block of data left. Fix this by using the actual length left and copy it into a buffer first for processing.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52669" target="_blank">CVE-2023-52669</a><br><a href="https://git.kernel.org/stable/c/a7f580cdb42ec3d53bbb7c4e4335a98423703285" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cd51e26a3b89706beec64f2d8296cfb1c34e0c79" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d07f951903fa9922c375b8ab1ce81b18a0034e3b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d68ac38895e84446848b7647ab9458d54cacba3e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dbc9a791a70ea47be9f2acf251700fe254a2ab23" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e78f1a43e72daf77705ad5b9946de66fc708b874" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: rpmsg: virtio: Free driver_override when rpmsg_remove() Free driver_override when rpmsg_remove(), otherwise the following memory leak will occur: unreferenced object 0xffff0000d55d7080 (size 128): comm "kworker/u8:2", pid 56, jiffies 4294893188 (age 214.272s) hex dump (first 32 bytes): 72 70 6d 73 67 5f 6e 73 00 00 00 00 00 00 00 00 rpmsg_ns........ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [&lt;000000009c94c9c1&gt;] __kmem_cache_alloc_node+0x1f8/0x320 [&lt;000000002300d89b&gt;] __kmalloc_node_track_caller+0x44/0x70 [&lt;00000000228a60c3&gt;] kstrndup+0x4c/0x90 [&lt;0000000077158695&gt;] driver_set_override+0xd0/0x164 [&lt;000000003e9c4ea5&gt;] rpmsg_register_device_override+0x98/0x170 [&lt;000000001c0c89a8&gt;] rpmsg_ns_register_device+0x24/0x30 [&lt;000000008bbf8fa2&gt;] rpmsg_probe+0x2e0/0x3ec [&lt;00000000e65a68df&gt;] virtio_dev_probe+0x1c0/0x280 [&lt;00000000443331cc&gt;] really_probe+0xbc/0x2dc [&lt;00000000391064b1&gt;] __driver_probe_device+0x78/0xe0 [&lt;00000000a41c9a5b&gt;] driver_probe_device+0xd8/0x160 [&lt;000000009c3bd5df&gt;] __device_attach_driver+0xb8/0x140 [&lt;0000000043cd7614&gt;] bus_for_each_drv+0x7c/0xd4 [&lt;000000003b929a36&gt;] __device_attach+0x9c/0x19c [&lt;00000000a94e0ba8&gt;] device_initial_probe+0x14/0x20 [&lt;000000003c999637&gt;] bus_probe_device+0xa0/0xac</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52670" target="_blank">CVE-2023-52670</a><br><a href="https://git.kernel.org/stable/c/229ce47cbfdc7d3a9415eb676abbfb77d676cb08" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2d27a7b19cb354c6d04bcdc9239e261ff29858d6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4e6cef3fae5c164968118a13f3fe293700adc81a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/69ca89d80f2c8a1f5af429b955637beea7eead30" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a416d624e5fb7246ea97c11fbfea7e0e27abf43" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d5362c37e1f8a40096452fc201c30e705750e687" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dd50fe18c234bd5ff22f658f4d414e8fa8cd6a5d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f4bb1d5daf77b1a95a43277268adf0d1430c2346" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix hang/underflow when transitioning to ODM4:1 [Why] Under some circumstances, disabling an OPTC and attempting to reclaim its OPP(s) for a different OPTC could cause a hang/underflow due to OPPs not being properly disconnected from the disabled OPTC. [How] Ensure that all OPPs are unassigned from an OPTC when it gets disabled.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52671" target="_blank">CVE-2023-52671</a><br><a href="https://git.kernel.org/stable/c/4b6b479b2da6badff099b2e3abf0248936eefbf5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ae62f1dde66a6f0eee98defc4c7a346bd5acd239" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e7b2b108cdeab76a7e7324459e50b0c1214c0386" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: pipe: wakeup wr_wait after setting max_usage Commit c73be61cede5 ("pipe: Add general notification queue support") a regression was introduced that would lock up resized pipes under certain conditions. See the reproducer in [1]. The commit resizing the pipe ring size was moved to a different function, doing that moved the wakeup for pipe-&gt;wr_wait before actually raising pipe-&gt;max_usage. If a pipe was full before the resize occured it would result in the wakeup never actually triggering pipe_write. Set @max_usage and @nr_accounted before waking writers if this isn't a watch queue. [Christian Brauner &lt;brauner@kernel.org&gt;: rewrite to account for watch queues]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52672" target="_blank">CVE-2023-52672</a><br><a href="https://git.kernel.org/stable/c/162ae0e78bdabf84ef10c1293c4ed7865cb7d3c8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3efbd114b91525bb095b8ae046382197d92126b9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/68e51bdb1194f11d3452525b99c98aff6f837b24" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6fb70694f8d1ac34e45246b0ac988f025e1e5b55" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b87a1229d8668fbc78ebd9ca0fc797a76001c60f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e95aada4cb93d42e25c30a0ef9eb2923d9711d4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix a debugfs null pointer error [WHY &amp; HOW] Check whether get_subvp_en() callback exists before calling it.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52673" target="_blank">CVE-2023-52673</a><br><a href="https://git.kernel.org/stable/c/43235db21fc23559f50a62f8f273002eeb506f5a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/efb91fea652a42fcc037d2a9ef4ecd1ffc5ff4b7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add clamp() in scarlett2_mixer_ctl_put() Ensure the value passed to scarlett2_mixer_ctl_put() is between 0 and SCARLETT2_MIXER_MAX_VALUE so we don't attempt to access outside scarlett2_mixer_values[].</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52674" target="_blank">CVE-2023-52674</a><br><a href="https://git.kernel.org/stable/c/03035872e17897ba89866940bbc9cefca601e572" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/04f8f053252b86c7583895c962d66747ecdc61b7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ad945ea8d47dd4454c271510bea24850119847c2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d8d8897d65061cbe36bf2909057338303a904810" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e517645ead5ea22c69d2a44694baa23fe1ce7c2b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: powerpc/imc-pmu: Add a null pointer check in update_events_in_group() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52675" target="_blank">CVE-2023-52675</a><br><a href="https://git.kernel.org/stable/c/024352f7928b28f53609660663329d8c0f4ad032" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0a233867a39078ebb0f575e2948593bbff5826b3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1e80aa25d186a7aa212df5acd8c75f55ac8dae34" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5a669f3511d273c8c1ab1c1d268fbcdf53fc7a05" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/75fc599bcdcb1de093c9ced2e3cccc832f3787f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a2da3f9b1a1019c887ee1d164475a8fcdb0a3fec" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c7d828e12b326ea50fb80c369d7aa87519ed14c6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f105c263009839d80fad6998324a4e1b3511cba0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: bpf: Guard stack limits against 32bit overflow This patch promotes the arithmetic around checking stack bounds to be done in the 64-bit domain, instead of the current 32bit. The arithmetic implies adding together a 64-bit register with a int offset. The register was checked to be below 1&lt;&lt;29 when it was variable, but not when it was fixed. The offset either comes from an instruction (in which case it is 16 bit), from another register (in which case the caller checked it to be below 1&lt;&lt;29 [1]), or from the size of an argument to a kfunc (in which case it can be a u32 [2]). Between the register being inconsistently checked to be below 1&lt;&lt;29, and the offset being up to an u32, it appears that we were open to overflowing the `int`s which were currently used for arithmetic. [1] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L7494-L7498 [2] https://github.com/torvalds/linux/blob/815fb87b753055df2d9e50f6cd80eb10235fe3e9/kernel/bpf/verifier.c#L11904</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52676" target="_blank">CVE-2023-52676</a><br><a href="https://git.kernel.org/stable/c/1d38a9ee81570c4bd61f557832dead4d6f816760" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ad140fc856f0b1d5e2215bcb6d0cc247a86805a2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e5ad9ecb84405637df82732ee02ad741a5f782a6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: riscv: Check if the code to patch lies in the exit section Otherwise we fall through to vmalloc_to_page() which panics since the address does not lie in the vmalloc region.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52677" target="_blank">CVE-2023-52677</a><br><a href="https://git.kernel.org/stable/c/1d7a03052846f34d624d0ab41a879adf5e85c85f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/420370f3ae3d3b883813fd3051a38805160b2b9f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/890cfe5337e0aaf03ece1429db04d23c88da72e7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8db56df4a954b774bdc68917046a685a9fa2e4bc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/938f70d14618ec72e10d6fcf8a546134136d7c13" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Confirm list is non-empty before utilizing list_first_entry in kfd_topology.c Before using list_first_entry, make sure to check that list is not empty, if list is empty return -ENODATA. Fixes the below: drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_topology.c:1347 kfd_create_indirect_link_prop() warn: can 'gpu_link' even be NULL? drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_topology.c:1428 kfd_add_peer_prop() warn: can 'iolink1' even be NULL? drivers/gpu/drm/amd/amdgpu/../amdkfd/kfd_topology.c:1433 kfd_add_peer_prop() warn: can 'iolink2' even be NULL?</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52678" target="_blank">CVE-2023-52678</a><br><a href="https://git.kernel.org/stable/c/4525525cb7161d08f95d0e47025323dd10214313" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/499839eca34ad62d43025ec0b46b80e77065f6d8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4ac4e023ed7ab1c7c67d2d12b7b6198fcd099e5c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5024cce888e11e5688f77df81db9e14828495d64" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: of: Fix double free in of_parse_phandle_with_args_map In of_parse_phandle_with_args_map() the inner loop that iterates through the map entries calls of_node_put(new) to free the reference acquired by the previous iteration of the inner loop. This assumes that the value of "new" is NULL on the first iteration of the inner loop. Make sure that this is true in all iterations of the outer loop by setting "new" to NULL after its value is assigned to "cur". Extend the unittest to detect the double free and add an additional test case that actually triggers this path.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52679" target="_blank">CVE-2023-52679</a><br><a href="https://git.kernel.org/stable/c/26b4d702c44f9e5cf3c5c001ae619a4a001889db" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4541004084527ce9e95a818ebbc4e6b293ffca21" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4dde83569832f9377362e50f7748463340c5db6b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a0a061151a6200c13149dbcdb6c065203c8425d2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b64d09a4e8596f76d27f4b4a90a1cf6baf6a82f8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b9d760dae5b10e73369b769073525acd7b3be2bd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cafa992134124e785609a406da4ff2b54052aff7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d5f490343c77e6708b6c4aa7dbbfbcbb9546adea" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add missing error checks to *_ctl_get() The *_ctl_get() functions which call scarlett2_update_*() were not checking the return value. Fix to check the return value and pass to the caller.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52680" target="_blank">CVE-2023-52680</a><br><a href="https://git.kernel.org/stable/c/3a09488f4f67f7ade59b8ac62a6c7fb29439cf51" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/50603a67daef161c78c814580d57f7f0be57167e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/773e38f73461ef2134a0d33a08f1668edde9b7c3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/821fbaeaaae23d483d3df799fe91ec8045973ec3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cda7762bea857e6951315a2f7d0632ea1850ed43" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: efivarfs: Free s_fs_info on unmount Now that we allocate a s_fs_info struct on fs context creation, we should ensure that we free it again when the superblock goes away.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52681" target="_blank">CVE-2023-52681</a><br><a href="https://git.kernel.org/stable/c/48be1364dd387e375e1274b76af986cb8747be2c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/547713d502f7b4b8efccd409cff84d731a23853b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/92be3095c6ca1cdc46237839c6087555be9160e3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ea6b597fcaca99562fa56a473bcbbbd79b40af03" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to wait on block writeback for post_read case If inode is compressed, but not encrypted, it missed to call f2fs_wait_on_block_writeback() to wait for GCed page writeback in IPU write path. Thread A GC-Thread - f2fs_gc - do_garbage_collect - gc_data_segment - move_data_block - f2fs_submit_page_write migrate normal cluster's block via meta_inode's page cache - f2fs_write_single_data_page - f2fs_do_write_data_page - f2fs_inplace_write_data - f2fs_submit_page_bio IRQ - f2fs_read_end_io IRQ old data overrides new data due to out-of-order GC and common IO. - f2fs_read_end_io</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52682" target="_blank">CVE-2023-52682</a><br><a href="https://git.kernel.org/stable/c/4535be48780431753505e74e1b1ad4836a189bc2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/55fdc1c24a1d6229fe0ecf31335fb9a2eceaaa00" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9bfd5ea71521d0e522ba581c6ccc5db93759c0c3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f904c156d8011d8291ffd5b6b398f3747e294986" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ACPI: LPIT: Avoid u32 multiplication overflow In lpit_update_residency() there is a possibility of overflow in multiplication, if tsc_khz is large enough (&gt; UINT_MAX/1000). Change multiplication to mul_u32_u32(). Found by Linux Verification Center (linuxtesting.org) with SVACE.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52683" target="_blank">CVE-2023-52683</a><br><a href="https://git.kernel.org/stable/c/56d2eeda87995245300836ee4dbd13b002311782" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/647d1d50c31e60ef9ccb9756a8fdf863329f7aee" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6c38e791bde07d6ca2a0a619ff9b6837e0d5f9ad" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/72222dfd76a79d9666ab3117fcdd44ca8cd0c4de" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b7aab9d906e2e252a7783f872406033ec49b6dae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c1814a4ffd016ce5392c6767d22ef3aa2f0d4bd1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d1ac288b2742aa4af746c5613bac71760fadd1c4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f39c3d578c7d09a18ceaf56750fc7f20b02ada63" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: qseecom: fix memory leaks in error paths Fix instances of returning error codes directly instead of jumping to the relevant labels where memory allocated for the SCM calls would be freed.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52684" target="_blank">CVE-2023-52684</a><br><a href="https://git.kernel.org/stable/c/6c57d7b593c4a4e60db65d5ce0fe1d9f79ccbe9b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/85fdbf6840455be64eac16bdfe0df3368ee3d0f0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: pstore: ram_core: fix possible overflow in persistent_ram_init_ecc() In persistent_ram_init_ecc(), on 64-bit arches DIV_ROUND_UP() will return 64-bit value since persistent_ram_zone::buffer_size has type size_t which is derived from the 64-bit *unsigned long*, while the ecc_blocks variable this value gets assigned to has (always 32-bit) *int* type. Even if that value fits into *int* type, an overflow is still possible when calculating the size_t typed ecc_total variable further below since there's no cast to any 64-bit type before multiplication. Declaring the ecc_blocks variable as *size_t* should fix this mess... Found by Linux Verification Center (linuxtesting.org) with the SVACE static analysis tool.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52685" target="_blank">CVE-2023-52685</a><br><a href="https://git.kernel.org/stable/c/3b333cded94fbe5ce30d699b316c4715151268ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/48dcfc42ce705b652c0619cb99846afc43029de9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/86222a8fc16ec517de8da2604d904c9df3a08e5d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8fb12524c86bdd542a54857d5d076b1b6778c78c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a34946ec3de88a16cc3a87fdab50aad06255a22b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/acd413da3e1f37582207cd6078a41d57c9011918" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d1fe1aede684bd014714dacfdc75586a9ad38657" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f9b891a7e8fcf83901f8507241e23e7420103b61" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null pointer check in opal_event_init() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52686" target="_blank">CVE-2023-52686</a><br><a href="https://git.kernel.org/stable/c/8422d179cf46889c15ceff9ede48c5bfa4e7f0b4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8649829a1dd25199bbf557b2621cedb4bf9b3050" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a523e1da6d88c2034f946adfa4f74b236c95ca9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a14c55eb461d630b836f80591d8caf1f74e62877" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c0b111ea786ddcc8be0682612830796ece9436c7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e08c2e275fa1874de945b87093f925997722ee42" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e6ad05e3ae9c84c5a71d7bb2d44dc845ae7990cf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e93d7cf4c1ddbcd846739e7ad849f955a4f18031" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: crypto: safexcel - Add error handling for dma_map_sg() calls Macro dma_map_sg() may return 0 on error. This patch enables checks in case of the macro failure and ensures unmapping of previously mapped buffers with dma_unmap_sg(). Found by Linux Verification Center (linuxtesting.org) with static analysis tool SVACE.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52687" target="_blank">CVE-2023-52687</a><br><a href="https://git.kernel.org/stable/c/4c0ac81a172a69a7733290915276672787e904ec" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8084b788c2fb1260f7d44c032d5124680b20d2b2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/87e02063d07708cac5bfe9fd3a6a242898758ac8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fc0b785802b856566df3ac943e38a072557001c4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix the error handler of rfkill config When the core rfkill config throws error, it should free the allocated resources. Currently it is not freeing the core pdev create resources. Avoid this issue by calling the core pdev destroy in the error handler of core rfkill config. Found this issue in the code review and it is compile tested only.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52688" target="_blank">CVE-2023-52688</a><br><a href="https://git.kernel.org/stable/c/898d8b3e1414cd900492ee6a0b582f8095ba4a1a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b4e593a7a22fa3c7d0550ef51c90b5c21f790aa8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add missing mutex lock around get meter levels As scarlett2_meter_ctl_get() uses meter_level_map[], the data_mutex should be locked while accessing it.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52689" target="_blank">CVE-2023-52689</a><br><a href="https://git.kernel.org/stable/c/74e3de7cdcc31ce75ab42350ae0946eff62a2da2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/993f7b42fa066b055e3a19b7f76ad8157c0927a0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null pointer check to scom_debug_init_one() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure. Add a null pointer check, and release 'ent' to avoid memory leaks.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52690" target="_blank">CVE-2023-52690</a><br><a href="https://git.kernel.org/stable/c/1eefa93faf69188540b08b024794fa90b1d82e8b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2a82c4439b903639e0a1f21990cd399fb0a49c19" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a260f2dd827bbc82cc60eb4f4d8c22707d80742" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a9c05cbb6644a2103c75b6906e9dafb9981ebd13" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dd8422ff271c22058560832fc3006324ded895a9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ed8d023cfa97b559db58c0e1afdd2eec7a83d8f2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f84c1446daa552e9699da8d1f8375eac0f65edc7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix a double-free in si_dpm_init When the allocation of adev-&gt;pm.dpm.dyn_state.vddc_dependency_on_dispclk.entries fails, amdgpu_free_extended_power_table is called to free some fields of adev. However, when the control flow returns to si_dpm_sw_init, it goes to label dpm_failed and calls si_dpm_fini, which calls amdgpu_free_extended_power_table again and free those fields again. Thus a double-free is triggered.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52691" target="_blank">CVE-2023-52691</a><br><a href="https://git.kernel.org/stable/c/06d95c99d5a4f5accdb79464076efe62e668c706" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2bf47c89bbaca2bae16581ef1b28aaec0ade0334" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ac16667237a82e2597e329eb9bc520d1cf9dff30" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/aeed2b4e4a70c7568d4a5eecd6a109713c0dfbf4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/afe9f5b871f86d58ecdc45b217b662227d7890d0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ca8e2e251c65e5a712f6025e27bd9b26d16e6f4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f957a1be647f7fc65926cbf572992ec2747a93f2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fb1936cb587262cd539e84b34541abb06e42b2f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALSA: scarlett2: Add missing error check to scarlett2_usb_set_config() scarlett2_usb_set_config() calls scarlett2_usb_get() but was not checking the result. Return the error if it fails rather than continuing with an invalid value.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52692" target="_blank">CVE-2023-52692</a><br><a href="https://git.kernel.org/stable/c/145c5aa51486171025ab47f35cff34bff8d0cea3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/51d5697e1c0380d482c3eab002bfc8d0be177e99" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/996fde492ad9b9563ee483b363af40d7696a8467" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/be96acd3eaa790d10a5b33e65267f52d02f6ad88" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ca459dfa7d4ed9098fcf13e410963be6ae9b6bf3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ACPI: video: check for error while searching for backlight device parent If acpi_get_parent() called in acpi_video_dev_register_backlight() fails, for example, because acpi_ut_acquire_mutex() fails inside acpi_get_parent), this can lead to incorrect (uninitialized) acpi_parent handle being passed to acpi_get_pci_dev() for detecting the parent pci device. Check acpi_get_parent() result and set parent device only in case of success. Found by Linux Verification Center (linuxtesting.org) with SVACE.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52693" target="_blank">CVE-2023-52693</a><br><a href="https://git.kernel.org/stable/c/1e3a2b9b4039bb4d136dca59fb31e06465e056f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2124c5bc22948fc4d09a23db4a8acdccc7d21e95" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/39af144b6d01d9b40f52e5d773e653957e6c379c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3a370502a5681986f9828e43be75ce26c6ab24af" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/556f02699d33c1f40b1b31bd25828ce08fa165d8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/72884ce4e10417b1233b614bf134da852df0f15f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c4e1a0ef0b4782854c9b77a333ca912b392bed2f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ccd45faf4973746c4f30ea41eec864e5cf191099" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/bridge: tpd12s015: Drop buggy __exit annotation for remove function With tpd12s015_remove() marked with __exit this function is discarded when the driver is compiled as a built-in. The result is that when the driver unbinds there is no cleanup done which results in resource leakage or worse.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52694" target="_blank">CVE-2023-52694</a><br><a href="https://git.kernel.org/stable/c/08ccff6ece35f08e8107e975903c370d849089e5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/53926e2a39629702f7f809d614b3ca89c2478205" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/81f1bd85960b7a089a91e679ff7cd2524390bbf1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a8657406e12aa10412134622c58977ac657f16d2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ce3e112e7ae854249d8755906acc5f27e1542114" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e00ec5901954d85b39b5f10f94e60ab9af463eb1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check writeback connectors in create_validate_stream_for_sink [WHY &amp; HOW] This is to check connector type to avoid unhandled null pointer for writeback connectors.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52695" target="_blank">CVE-2023-52695</a><br><a href="https://git.kernel.org/stable/c/0fe85301b95077ac4fa4a91909d38b7341e81187" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dbf5d3d02987faa0eec3710dd687cd912362d7b5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: powerpc/powernv: Add a null pointer check in opal_powercap_init() kasprintf() returns a pointer to dynamically allocated memory which can be NULL upon failure.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52696" target="_blank">CVE-2023-52696</a><br><a href="https://git.kernel.org/stable/c/69f95c5e9220f77ce7c540686b056c2b49e9a664" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6b58d16037217d0c64a2a09b655f370403ec7219" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9da4a56dd3772570512ca58aa8832b052ae910dc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a67a04ad05acb56640798625e73fa54d6d41cce1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b02ecc35d01a76b4235e008d2dd292895b28ecab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e123015c0ba859cf48aa7f89c5016cc6e98e018d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f152a6bfd187f67afeffc9fd68cbe46f51439be0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw_rt_sdca_jack_common: ctx-&gt;headset_codec_dev = NULL sof_sdw_rt_sdca_jack_exit() are used by different codecs, and some of them use the same dai name. For example, rt712 and rt713 both use "rt712-sdca-aif1" and sof_sdw_rt_sdca_jack_exit(). As a result, sof_sdw_rt_sdca_jack_exit() will be called twice by mc_dailink_exit_loop(). Set ctx-&gt;headset_codec_dev = NULL; after put_device(ctx-&gt;headset_codec_dev); to avoid ctx-&gt;headset_codec_dev being put twice.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52697" target="_blank">CVE-2023-52697</a><br><a href="https://git.kernel.org/stable/c/582231a8c4f73ac153493687ecc1bed853e9c9ef" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a410d58117d6da4b7d41f3c91365f191d006bc3d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e38e252dbceeef7d2f848017132efd68e9ae1416" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: calipso: fix memory leak in netlbl_calipso_add_pass() If IPv6 support is disabled at boot (ipv6.disable=1), the calipso_init() -&gt; netlbl_calipso_ops_register() function isn't called, and the netlbl_calipso_ops_get() function always returns NULL. In this case, the netlbl_calipso_add_pass() function allocates memory for the doi_def variable but doesn't free it with the calipso_doi_free(). BUG: memory leak unreferenced object 0xffff888011d68180 (size 64): comm "syz-executor.1", pid 10746, jiffies 4295410986 (age 17.928s) hex dump (first 32 bytes): 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace: [&lt;...&gt;] kmalloc include/linux/slab.h:552 [inline] [&lt;...&gt;] netlbl_calipso_add_pass net/netlabel/netlabel_calipso.c:76 [inline] [&lt;...&gt;] netlbl_calipso_add+0x22e/0x4f0 net/netlabel/netlabel_calipso.c:111 [&lt;...&gt;] genl_family_rcv_msg_doit+0x22f/0x330 net/netlink/genetlink.c:739 [&lt;...&gt;] genl_family_rcv_msg net/netlink/genetlink.c:783 [inline] [&lt;...&gt;] genl_rcv_msg+0x341/0x5a0 net/netlink/genetlink.c:800 [&lt;...&gt;] netlink_rcv_skb+0x14d/0x440 net/netlink/af_netlink.c:2515 [&lt;...&gt;] genl_rcv+0x29/0x40 net/netlink/genetlink.c:811 [&lt;...&gt;] netlink_unicast_kernel net/netlink/af_netlink.c:1313 [inline] [&lt;...&gt;] netlink_unicast+0x54b/0x800 net/netlink/af_netlink.c:1339 [&lt;...&gt;] netlink_sendmsg+0x90a/0xdf0 net/netlink/af_netlink.c:1934 [&lt;...&gt;] sock_sendmsg_nosec net/socket.c:651 [inline] [&lt;...&gt;] sock_sendmsg+0x157/0x190 net/socket.c:671 [&lt;...&gt;] ____sys_sendmsg+0x712/0x870 net/socket.c:2342 [&lt;...&gt;] ___sys_sendmsg+0xf8/0x170 net/socket.c:2396 [&lt;...&gt;] __sys_sendmsg+0xea/0x1b0 net/socket.c:2429 [&lt;...&gt;] do_syscall_64+0x30/0x40 arch/x86/entry/common.c:46 [&lt;...&gt;] entry_SYSCALL_64_after_hwframe+0x61/0xc6 Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with Syzkaller [PM: merged via the LSM tree at Jakub Kicinski request]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52698" target="_blank">CVE-2023-52698</a><br><a href="https://git.kernel.org/stable/c/321b3a5592c8a9d6b654c7c64833ea67dbb33149" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/36e19f84634aaa94f543fedc0a07588949638d53" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/408bbd1e1746fe33e51f4c81c2febd7d3841d031" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/44a88650ba55e6a7f2ec485d2c2413ba7e216f01" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a8f811a146aa2a0230f8edb2e9f4b6609aab8da" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a4529a08d3704c17ea9c7277d180e46b99250ded" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ec4e9d630a64df500641892f4e259e8149594a99" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f14d36e6e97fe935a20e0ceb159c100f90b6627c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: xen-netfront: Add missing skb_mark_for_recycle Notice that skb_mark_for_recycle() is introduced later than fixes tag in commit 6a5bcd84e886 ("page_pool: Allow drivers to hint on SKB recycling"). It is believed that fixes tag were missing a call to page_pool_release_page() between v5.9 to v5.14, after which is should have used skb_mark_for_recycle(). Since v6.6 the call page_pool_release_page() were removed (in commit 535b9c61bdef ("net: page_pool: hide page_pool_release_page()") and remaining callers converted (in commit 6bfef2ec0172 ("Merge branch 'net-page_pool-remove-page_pool_release_page'")). This leak became visible in v6.8 via commit dba1b8a7ab68 ("mm/page_pool: catch page_pool memory leaks").</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27393" target="_blank">CVE-2024-27393</a><br><a href="https://git.kernel.org/stable/c/037965402a010898d34f4e35327d22c0a95cd51f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/27aa3e4b3088426b7e34584274ad45b5afaf7629" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4143b9479caa29bb2380f3620dcbe16ea84eb3b1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7c1250796b6c262b505a46192f4716b8c6a6a8c6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c8b7b2f158d9d4fb89cd2f68244af154f7549bb4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: tcp: Fix Use-After-Free in tcp_ao_connect_init Since call_rcu, which is called in the hlist_for_each_entry_rcu traversal of tcp_ao_connect_init, is not part of the RCU read critical section, it is possible that the RCU grace period will pass during the traversal and the key will be free. To prevent this, it should be changed to hlist_for_each_entry_safe.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27394" target="_blank">CVE-2024-27394</a><br><a href="https://git.kernel.org/stable/c/80e679b352c3ce5158f3f778cfb77eb767e586fb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ca4fb6c6764b3f75b4f5aa81db1536291897ff7f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: Fix Use-After-Free in ovs_ct_exit Since kfree_rcu, which is called in the hlist_for_each_entry_rcu traversal of ovs_ct_limit_exit, is not part of the RCU read critical section, it is possible that the RCU grace period will pass during the traversal and the key will be free. To prevent this, it should be changed to hlist_for_each_entry_safe.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27395" target="_blank">CVE-2024-27395</a><br><a href="https://git.kernel.org/stable/c/2db9a8c0a01fa1c762c1e61a13c212c492752994" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/35880c3fa6f8fe281a19975d2992644588ca33d3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/589523cf0b384164e445dd5db8d5b1bf97982424" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5ea7b72d4fac2fdbc0425cd8f2ea33abe95235b2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9048616553c65e750d43846f225843ed745ec0d4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bca6fa2d9a9f560e6b89fd5190b05cc2f5d422c1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eaa5e164a2110d2fb9e16c8a29e4501882235137" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/edee0758747d7c219e29db9ed1d4eb33e8d32865" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: gtp: Fix Use-After-Free in gtp_dellink Since call_rcu, which is called in the hlist_for_each_entry_rcu traversal of gtp_dellink, is not part of the RCU read critical section, it is possible that the RCU grace period will pass during the traversal and the key will be free. To prevent this, it should be changed to hlist_for_each_entry_safe.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27396" target="_blank">CVE-2024-27396</a><br><a href="https://git.kernel.org/stable/c/07b20d0a3dc13fb1adff10b60021a4924498da58" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0caff3e6390f840666b8dc1ecebf985c2ef3f1dd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/25a1c2d4b1fcf938356a9688a96a6456abd44b29" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2aacd4de45477582993f8a8abb9505a06426bfb6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2e74b3fd6bf542349758f283676dff3660327c07" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/718df1bc226c383dd803397d7f5d95557eb81ac7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cd957d1716ec979d8f5bf38fc659aeb9fdaa2474" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f2a904107ee2b647bb7794a1a82b67740d7c8a64" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use timestamp to check for set element timeout Add a timestamp field at the beginning of the transaction, store it in the nftables per-netns area. Update set backend .insert, .deactivate and sync gc path to use the timestamp, this avoids that an element expires while control plane transaction is still unfinished. .lookup and .update, which are used from packet path, still use the current time to check if the element has expired. And .get path and dump also since this runs lockless under rcu read size lock. Then, there is async gc which also needs to check the current time since it runs asynchronously from a workqueue.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27397" target="_blank">CVE-2024-27397</a><br><a href="https://git.kernel.org/stable/c/383182db8d58c4237772ba0764cded4938a235c3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7395dfacfff65e9938ac0889dafa1ab01e987d15" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco connection is established and then, the sco socket is releasing, timeout_work will be scheduled to judge whether the sco disconnection is timeout. The sock will be deallocated later, but it is dereferenced again in sco_sock_timeout. As a result, the use-after-free bugs will happen. The root cause is shown below: Cleanup Thread | Worker Thread sco_sock_release | sco_sock_close | __sco_sock_close | sco_sock_set_timer | schedule_delayed_work | sco_sock_kill | (wait a time) sock_put(sk) //FREE | sco_sock_timeout | sock_hold(sk) //USE The KASAN report triggered by POC is shown below: [ 95.890016] ================================================================== [ 95.890496] BUG: KASAN: slab-use-after-free in sco_sock_timeout+0x5e/0x1c0 [ 95.890755] Write of size 4 at addr ffff88800c388080 by task kworker/0:0/7 ... [ 95.890755] Workqueue: events sco_sock_timeout [ 95.890755] Call Trace: [ 95.890755] &lt;TASK&gt; [ 95.890755] dump_stack_lvl+0x45/0x110 [ 95.890755] print_address_description+0x78/0x390 [ 95.890755] print_report+0x11b/0x250 [ 95.890755] ? __virt_addr_valid+0xbe/0xf0 [ 95.890755] ? sco_sock_timeout+0x5e/0x1c0 [ 95.890755] kasan_report+0x139/0x170 [ 95.890755] ? update_load_avg+0xe5/0x9f0 [ 95.890755] ? sco_sock_timeout+0x5e/0x1c0 [ 95.890755] kasan_check_range+0x2c3/0x2e0 [ 95.890755] sco_sock_timeout+0x5e/0x1c0 [ 95.890755] process_one_work+0x561/0xc50 [ 95.890755] worker_thread+0xab2/0x13c0 [ 95.890755] ? pr_cont_work+0x490/0x490 [ 95.890755] kthread+0x279/0x300 [ 95.890755] ? pr_cont_work+0x490/0x490 [ 95.890755] ? kthread_blkcg+0xa0/0xa0 [ 95.890755] ret_from_fork+0x34/0x60 [ 95.890755] ? kthread_blkcg+0xa0/0xa0 [ 95.890755] ret_from_fork_asm+0x11/0x20 [ 95.890755] &lt;/TASK&gt; [ 95.890755] [ 95.890755] Allocated by task 506: [ 95.890755] kasan_save_track+0x3f/0x70 [ 95.890755] __kasan_kmalloc+0x86/0x90 [ 95.890755] __kmalloc+0x17f/0x360 [ 95.890755] sk_prot_alloc+0xe1/0x1a0 [ 95.890755] sk_alloc+0x31/0x4e0 [ 95.890755] bt_sock_alloc+0x2b/0x2a0 [ 95.890755] sco_sock_create+0xad/0x320 [ 95.890755] bt_sock_create+0x145/0x320 [ 95.890755] __sock_create+0x2e1/0x650 [ 95.890755] __sys_socket+0xd0/0x280 [ 95.890755] __x64_sys_socket+0x75/0x80 [ 95.890755] do_syscall_64+0xc4/0x1b0 [ 95.890755] entry_SYSCALL_64_after_hwframe+0x67/0x6f [ 95.890755] [ 95.890755] Freed by task 506: [ 95.890755] kasan_save_track+0x3f/0x70 [ 95.890755] kasan_save_free_info+0x40/0x50 [ 95.890755] poison_slab_object+0x118/0x180 [ 95.890755] __kasan_slab_free+0x12/0x30 [ 95.890755] kfree+0xb2/0x240 [ 95.890755] __sk_destruct+0x317/0x410 [ 95.890755] sco_sock_release+0x232/0x280 [ 95.890755] sock_close+0xb2/0x210 [ 95.890755] __fput+0x37f/0x770 [ 95.890755] task_work_run+0x1ae/0x210 [ 95.890755] get_signal+0xe17/0xf70 [ 95.890755] arch_do_signal_or_restart+0x3f/0x520 [ 95.890755] syscall_exit_to_user_mode+0x55/0x120 [ 95.890755] do_syscall_64+0xd1/0x1b0 [ 95.890755] entry_SYSCALL_64_after_hwframe+0x67/0x6f [ 95.890755] [ 95.890755] The buggy address belongs to the object at ffff88800c388000 [ 95.890755] which belongs to the cache kmalloc-1k of size 1024 [ 95.890755] The buggy address is located 128 bytes inside of [ 95.890755] freed 1024-byte region [ffff88800c388000, ffff88800c388400) [ 95.890755] [ 95.890755] The buggy address belongs to the physical page: [ 95.890755] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff88800c38a800 pfn:0xc388 [ 95.890755] head: order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0 [ 95.890755] ano ---truncated---</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27398" target="_blank">CVE-2024-27398</a><br><a href="https://git.kernel.org/stable/c/012363cb1bec5f33a7b94629ab2c1086f30280f2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1b33d55fb7355e27f8c82cd4ecd560f162469249" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3212afd00e3cda790fd0583cb3eaef8f9575a014" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/33a6e92161a78c1073d90e27abe28d746feb0a53" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/483bc08181827fc475643272ffb69c533007e546" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/50c2037fc28df870ef29d9728c770c8955d32178" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6a18eeb1b3bbc67c20d9609c31dca6a69b4bcde5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bfab2c1f7940a232cd519e82fff137e308abfd93" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout There is a race condition between l2cap_chan_timeout() and l2cap_chan_del(). When we use l2cap_chan_del() to delete the channel, the chan-&gt;conn will be set to null. But the conn could be dereferenced again in the mutex_lock() of l2cap_chan_timeout(). As a result the null pointer dereference bug will happen. The KASAN report triggered by POC is shown below: [ 472.074580] ================================================================== [ 472.075284] BUG: KASAN: null-ptr-deref in mutex_lock+0x68/0xc0 [ 472.075308] Write of size 8 at addr 0000000000000158 by task kworker/0:0/7 [ 472.075308] [ 472.075308] CPU: 0 PID: 7 Comm: kworker/0:0 Not tainted 6.9.0-rc5-00356-g78c0094a146b #36 [ 472.075308] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu4 [ 472.075308] Workqueue: events l2cap_chan_timeout [ 472.075308] Call Trace: [ 472.075308] &lt;TASK&gt; [ 472.075308] dump_stack_lvl+0x137/0x1a0 [ 472.075308] print_report+0x101/0x250 [ 472.075308] ? __virt_addr_valid+0x77/0x160 [ 472.075308] ? mutex_lock+0x68/0xc0 [ 472.075308] kasan_report+0x139/0x170 [ 472.075308] ? mutex_lock+0x68/0xc0 [ 472.075308] kasan_check_range+0x2c3/0x2e0 [ 472.075308] mutex_lock+0x68/0xc0 [ 472.075308] l2cap_chan_timeout+0x181/0x300 [ 472.075308] process_one_work+0x5d2/0xe00 [ 472.075308] worker_thread+0xe1d/0x1660 [ 472.075308] ? pr_cont_work+0x5e0/0x5e0 [ 472.075308] kthread+0x2b7/0x350 [ 472.075308] ? pr_cont_work+0x5e0/0x5e0 [ 472.075308] ? kthread_blkcg+0xd0/0xd0 [ 472.075308] ret_from_fork+0x4d/0x80 [ 472.075308] ? kthread_blkcg+0xd0/0xd0 [ 472.075308] ret_from_fork_asm+0x11/0x20 [ 472.075308] &lt;/TASK&gt; [ 472.075308] ================================================================== [ 472.094860] Disabling lock debugging due to kernel taint [ 472.096136] BUG: kernel NULL pointer dereference, address: 0000000000000158 [ 472.096136] #PF: supervisor write access in kernel mode [ 472.096136] #PF: error_code(0x0002) - not-present page [ 472.096136] PGD 0 P4D 0 [ 472.096136] Oops: 0002 [#1] PREEMPT SMP KASAN NOPTI [ 472.096136] CPU: 0 PID: 7 Comm: kworker/0:0 Tainted: G B 6.9.0-rc5-00356-g78c0094a146b #36 [ 472.096136] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu4 [ 472.096136] Workqueue: events l2cap_chan_timeout [ 472.096136] RIP: 0010:mutex_lock+0x88/0xc0 [ 472.096136] Code: be 08 00 00 00 e8 f8 23 1f fd 4c 89 f7 be 08 00 00 00 e8 eb 23 1f fd 42 80 3c 23 00 74 08 48 88 [ 472.096136] RSP: 0018:ffff88800744fc78 EFLAGS: 00000246 [ 472.096136] RAX: 0000000000000000 RBX: 1ffff11000e89f8f RCX: ffffffff8457c865 [ 472.096136] RDX: 0000000000000001 RSI: 0000000000000008 RDI: ffff88800744fc78 [ 472.096136] RBP: 0000000000000158 R08: ffff88800744fc7f R09: 1ffff11000e89f8f [ 472.096136] R10: dffffc0000000000 R11: ffffed1000e89f90 R12: dffffc0000000000 [ 472.096136] R13: 0000000000000158 R14: ffff88800744fc78 R15: ffff888007405a00 [ 472.096136] FS: 0000000000000000(0000) GS:ffff88806d200000(0000) knlGS:0000000000000000 [ 472.096136] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 472.096136] CR2: 0000000000000158 CR3: 000000000da32000 CR4: 00000000000006f0 [ 472.096136] Call Trace: [ 472.096136] &lt;TASK&gt; [ 472.096136] ? __die_body+0x8d/0xe0 [ 472.096136] ? page_fault_oops+0x6b8/0x9a0 [ 472.096136] ? kernelmode_fixup_or_oops+0x20c/0x2a0 [ 472.096136] ? do_user_addr_fault+0x1027/0x1340 [ 472.096136] ? _printk+0x7a/0xa0 [ 472.096136] ? mutex_lock+0x68/0xc0 [ 472.096136] ? add_taint+0x42/0xd0 [ 472.096136] ? exc_page_fault+0x6a/0x1b0 [ 472.096136] ? asm_exc_page_fault+0x26/0x30 [ 472.096136] ? mutex_lock+0x75/0xc0 [ 472.096136] ? mutex_lock+0x88/0xc0 [ 472.096136] ? mutex_lock+0x75/0xc0 [ 472.096136] l2cap_chan_timeo ---truncated---</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27399" target="_blank">CVE-2024-27399</a><br><a href="https://git.kernel.org/stable/c/06acb75e7ed600d0bbf7bff5628aa8f24a97978c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6466ee65e5b27161c846c73ef407f49dfa1bd1d9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8960ff650aec70485b40771cd8e6e8c4cb467d33" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/955b5b6c54d95b5e7444dfc81c95c8e013f27ac0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/adf0398cee86643b8eacde95f17d073d022f782c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e137e2ba96e51902dc2878131823a96bf8e638ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e97e16433eb4533083b096a3824b93a5ca3aee79" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eb86f955488c39526534211f2610e48a5cf8ead4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: once more fix the call oder in amdgpu_ttm_move() v2 This reverts drm/amdgpu: fix ftrace event amdgpu_bo_move always move on same heap. The basic problem here is that after the move the old location is simply not available any more. Some fixes were suggested, but essentially we should call the move notification before actually moving things because only this way we have the correct order for DMA-buf and VM move notifications as well. Also rework the statistic handling so that we don't update the eviction counter before the move. v2: add missing NULL check</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27400" target="_blank">CVE-2024-27400</a><br><a href="https://git.kernel.org/stable/c/0c7ed3ed35eec9138b88d42217b5a6b9a62bda4d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5c25b169f9a0b34ee410891a96bc9d7b9ed6f9be" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a4f6e138720b6e9adf7b82a71d0292f3f276480" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d3a9331a6591e9df64791e076f6591f440af51c3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: firewire: nosy: ensure user_length is taken into account when fetching packet contents Ensure that packet_buffer_get respects the user_length provided. If the length of the head packet exceeds the user_length, packet_buffer_get will now return 0 to signify to the user that no data were read and a larger buffer size is required. Helps prevent user space overflows.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27401" target="_blank">CVE-2024-27401</a><br><a href="https://git.kernel.org/stable/c/1fe60ee709436550f8cfbab01295936b868d5baa" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/38762a0763c10c24a4915feee722d7aa6e73eb98" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4ee0941da10e8fdcdb34756b877efd3282594c1f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/539d51ac48bcfcfa1b3d4a85f8df92fa22c1d41c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/67f34f093c0f7bf33f5b4ae64d3d695a3b978285" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/79f988d3ffc1aa778fc5181bdfab312e57956c6b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7b8c7bd2296e95b38a6ff346242356a2e7190239" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cca330c59c54207567a648357835f59df9a286bb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: phonet/pep: fix racy skb_queue_empty() use The receive queues are protected by their respective spin-lock, not the socket lock. This could lead to skb_peek() unexpectedly returning NULL or a pointer to an already dequeued socket buffer.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27402" target="_blank">CVE-2024-27402</a><br><a href="https://git.kernel.org/stable/c/0a9f558c72c47472c38c05fcb72c70abb9104277" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7d2a894d7f487dcb894df023e9d3014cf5b93fe5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8ef4fcc7014b9f93619851d6b78d6cc2789a4c88" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9d5523e065b568e79dfaa2ea1085a5bcf74baf78" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_flow_offload: reset dst in route object after setting up flow dst is transferred to the flow object, route object does not own it anymore. Reset dst in route object, otherwise if flow_offload_add() fails, error path releases dst twice, leading to a refcount underflow.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27403" target="_blank">CVE-2024-27403</a><br><a href="https://git.kernel.org/stable/c/012df10717da02367aaf92c65f9c89db206c15f4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4c167af9f6b5ae4a5dbc243d5983c295ccc2e43c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/558b00a30e05753a62ecc7e05e939ca8f0241148" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/670548c8db44d76e40e1dfc06812bca36a61e9ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9e0f0430389be7696396c62f037be4bf72cf93e3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mptcp: fix data races on remote_id Similar to the previous patch, address the data race on remote_id, adding the suitable ONCE annotations.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27404" target="_blank">CVE-2024-27404</a><br><a href="https://git.kernel.org/stable/c/2dba5774e8ed326a78ad4339d921a4291281ea6e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/967d3c27127e71a10ff5c083583a038606431b61" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/987c3ed7297e5661bc7f448f06fc366e497ac9b2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e64148635509bf13eea851986f5a0b150e5bd066" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: gadget: ncm: Avoid dropping datagrams of properly parsed NTBs It is observed sometimes when tethering is used over NCM with Windows 11 as host, at some instances, the gadget_giveback has one byte appended at the end of a proper NTB. When the NTB is parsed, unwrap call looks for any leftover bytes in SKB provided by u_ether and if there are any pending bytes, it treats them as a separate NTB and parses it. But in case the second NTB (as per unwrap call) is faulty/corrupt, all the datagrams that were parsed properly in the first NTB and saved in rx_list are dropped. Adding a few custom traces showed the following: [002] d..1 7828.532866: dwc3_gadget_giveback: ep1out: req 000000003868811a length 1025/16384 zsI ==&gt; 0 [002] d..1 7828.532867: ncm_unwrap_ntb: K: ncm_unwrap_ntb toprocess: 1025 [002] d..1 7828.532867: ncm_unwrap_ntb: K: ncm_unwrap_ntb nth: 1751999342 [002] d..1 7828.532868: ncm_unwrap_ntb: K: ncm_unwrap_ntb seq: 0xce67 [002] d..1 7828.532868: ncm_unwrap_ntb: K: ncm_unwrap_ntb blk_len: 0x400 [002] d..1 7828.532868: ncm_unwrap_ntb: K: ncm_unwrap_ntb ndp_len: 0x10 [002] d..1 7828.532869: ncm_unwrap_ntb: K: Parsed NTB with 1 frames In this case, the giveback is of 1025 bytes and block length is 1024. The rest 1 byte (which is 0x00) won't be parsed resulting in drop of all datagrams in rx_list. Same is case with packets of size 2048: [002] d..1 7828.557948: dwc3_gadget_giveback: ep1out: req 0000000011dfd96e length 2049/16384 zsI ==&gt; 0 [002] d..1 7828.557949: ncm_unwrap_ntb: K: ncm_unwrap_ntb nth: 1751999342 [002] d..1 7828.557950: ncm_unwrap_ntb: K: ncm_unwrap_ntb blk_len: 0x800 Lecroy shows one byte coming in extra confirming that the byte is coming in from PC: Transfer 2959 - Bytes Transferred(1025) Timestamp((18.524 843 590) - Transaction 8391 - Data(1025 bytes) Timestamp(18.524 843 590) --- Packet 4063861 Data(1024 bytes) Duration(2.117us) Idle(14.700ns) Timestamp(18.524 843 590) --- Packet 4063863 Data(1 byte) Duration(66.160ns) Time(282.000ns) Timestamp(18.524 845 722) According to Windows driver, no ZLP is needed if wBlockLength is non-zero, because the non-zero wBlockLength has already told the function side the size of transfer to be expected. However, there are in-market NCM devices that rely on ZLP as long as the wBlockLength is multiple of wMaxPacketSize. To deal with such devices, it pads an extra 0 at end so the transfer is no longer multiple of wMaxPacketSize.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27405" target="_blank">CVE-2024-27405</a><br><a href="https://git.kernel.org/stable/c/059285e04ebb273d32323fbad5431c5b94f77e48" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2b7ec68869d50ea998908af43b643bca7e54577e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2cb66b62a5d64ccf09b0591ab86fb085fa491fc5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/35b604a37ec70d68b19dafd10bbacf1db505c9ca" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/57ca0e16f393bb21d69734e536e383a3a4c665fd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/76c51146820c5dac629f21deafab0a7039bc3ccd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a31cf46d108dabce3df80b3e5c07661e24912151" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c7f43900bc723203d7554d299a2ce844054fab8e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: lib/Kconfig.debug: TEST_IOV_ITER depends on MMU Trying to run the iov_iter unit test on a nommu system such as the qemu kc705-nommu emulation results in a crash. KTAP version 1 # Subtest: iov_iter # module: kunit_iov_iter 1..9 BUG: failure at mm/nommu.c:318/vmap()! Kernel panic - not syncing: BUG! The test calls vmap() directly, but vmap() is not supported on nommu systems, causing the crash. TEST_IOV_ITER therefore needs to depend on MMU.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27406" target="_blank">CVE-2024-27406</a><br><a href="https://git.kernel.org/stable/c/1eb1e984379e2da04361763f66eec90dd75cf63e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9e6e541b97762d5b1143070067f7c68f39a408f8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e6316749d603fe9c4c91f6ec3694e06e4de632a3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fixed overflow check in mi_enum_attr()</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27407" target="_blank">CVE-2024-27407</a><br><a href="https://git.kernel.org/stable/c/1c0a95d99b1b2b5d842e5abc7ef7eed1193b60d7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/652cfeb43d6b9aba5c7c4902bed7a7340df131fb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8c77398c72618101d66480b94b34fe9087ee3d08" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: eDMA: Add sync read before starting the DMA transfer in remote setup The Linked list element and pointer are not stored in the same memory as the eDMA controller register. If the doorbell register is toggled before the full write of the linked list a race condition error will occur. In remote setup we can only use a readl to the memory to assure the full write has occurred.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27408" target="_blank">CVE-2024-27408</a><br><a href="https://git.kernel.org/stable/c/bbcc1c83f343e580c3aa1f2a8593343bf7b55bba" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d24fe6d5a1cfdddb7a9ef56736ec501c4d0a5fd3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f396b4df27cfe01a99f4b41f584c49e56477be3a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: HDMA: Add sync read before starting the DMA transfer in remote setup The Linked list element and pointer are not stored in the same memory as the HDMA controller register. If the doorbell register is toggled before the full write of the linked list a race condition error will occur. In remote setup we can only use a readl to the memory to assure the full write has occurred.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27409" target="_blank">CVE-2024-27409</a><br><a href="https://git.kernel.org/stable/c/17be6f5cb223f22e4733ed8fe8b2247cbb677716" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/227ef58a9b0c372efba422e8886a8015a1509eba" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/712a92a48158e02155b4b6b21e03a817f78c9b7e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject iftype change with mesh ID change It's currently possible to change the mesh ID when the interface isn't yet in mesh mode, at the same time as changing it into mesh mode. This leads to an overwrite of data in the wdev-&gt;u union for the interface type it currently has, causing cfg80211_change_iface() to do wrong things when switching. We could probably allow setting an interface to mesh while setting the mesh ID at the same time by doing a different order of operations here, but realistically there's no userspace that's going to do this, so just disallow changes in iftype when setting mesh ID.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27410" target="_blank">CVE-2024-27410</a><br><a href="https://git.kernel.org/stable/c/063715c33b4c37587aeca2c83cf08ead0c542995" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0cfbb26ee5e7b3d6483a73883f9f6157bca22ec9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/177d574be4b58f832354ab1ef5a297aa0c9aa2df" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/930e826962d9f01dcd2220176134427358d112f2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/99eb2159680af8786104dac80528acd5acd45980" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a2add961a5ed25cfd6a74f9ffb9e7ab6d6ded838" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d38d31bbbb9dc0d4d71a45431eafba03d0bc150d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f78c1375339a291cba492a70eaf12ec501d28a8e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: keep DMA buffers required for suspend/resume Nouveau deallocates a few buffers post GPU init which are required for GPU suspend/resume to function correctly. This is likely not as big an issue on systems where the NVGPU is the only GPU, but on multi-GPU set ups it leads to a regression where the kernel module errors and results in a system-wide rendering freeze. This commit addresses that regression by moving the two buffers required for suspend and resume to be deallocated at driver unload instead of post init.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27411" target="_blank">CVE-2024-27411</a><br><a href="https://git.kernel.org/stable/c/be00e15b240ed71fc30c0576af7ab670c8271661" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f6ecfdad359a01c7fd8a3bcfde3ef0acdf107e6e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: power: supply: bq27xxx-i2c: Do not free non existing IRQ The bq27xxx i2c-client may not have an IRQ, in which case client-&gt;irq will be 0. bq27xxx_battery_i2c_probe() already has an if (client-&gt;irq) check wrapping the request_threaded_irq(). But bq27xxx_battery_i2c_remove() unconditionally calls free_irq(client-&gt;irq) leading to: [ 190.310742] ------------[ cut here ]------------ [ 190.310843] Trying to free already-free IRQ 0 [ 190.310861] WARNING: CPU: 2 PID: 1304 at kernel/irq/manage.c:1893 free_irq+0x1b8/0x310 Followed by a backtrace when unbinding the driver. Add an if (client-&gt;irq) to bq27xxx_battery_i2c_remove() mirroring probe() to fix this.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27412" target="_blank">CVE-2024-27412</a><br><a href="https://git.kernel.org/stable/c/083686474e7c97b0f8b66df37fcb64e432e8b771" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2df70149e73e79783bcbc7db4fa51ecef0e2022c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7394abc8926adee6a817bab10797e0adc898af77" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cefe18e9ec84f8fe3e198ccebb815cc996eb9797" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d4d813c0a14d6bf52d810a55db06a2e7e3d98eaa" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d7acc4a569f5f4513120c85ea2b9f04909b7490f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e601ae81910ce6a3797876e190a2d8ef6cf828bc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fbca8bae1ba79d443a58781b45e92a73a24ac8f8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: efi/capsule-loader: fix incorrect allocation size gcc-14 notices that the allocation with sizeof(void) on 32-bit architectures is not enough for a 64-bit phys_addr_t: drivers/firmware/efi/capsule-loader.c: In function 'efi_capsule_open': drivers/firmware/efi/capsule-loader.c:295:24: error: allocation of insufficient size '4' for type 'phys_addr_t' {aka 'long long unsigned int'} with size '8' [-Werror=alloc-size] 295 | cap_info-&gt;phys = kzalloc(sizeof(void *), GFP_KERNEL); | ^ Use the correct type instead here.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27413" target="_blank">CVE-2024-27413</a><br><a href="https://git.kernel.org/stable/c/00cf21ac526011a29fc708f8912da446fac19f7b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/11aabd7487857b8e7d768fefb092f66dfde68492" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4b73473c050a612fb4317831371073eda07c3050" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/537e3f49dbe88881a6f0752beaa596942d9efd64" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/62a5dcd9bd3097e9813de62fa6f22815e84a0172" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/950d4d74d311a18baed6878dbfba8180d7e5dddd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ddc547dd05a46720866c32022300f7376c40119f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fccfa646ef3628097d59f7d9c1a3e84d4b6bb45e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: rtnetlink: fix error logic of IFLA_BRIDGE_FLAGS writing back In the commit d73ef2d69c0d ("rtnetlink: let rtnl_bridge_setlink checks IFLA_BRIDGE_MODE length"), an adjustment was made to the old loop logic in the function `rtnl_bridge_setlink` to enable the loop to also check the length of the IFLA_BRIDGE_MODE attribute. However, this adjustment removed the `break` statement and led to an error logic of the flags writing back at the end of this function. if (have_flags) memcpy(nla_data(attr), &amp;flags, sizeof(flags)); // attr should point to IFLA_BRIDGE_FLAGS NLA !!! Before the mentioned commit, the `attr` is granted to be IFLA_BRIDGE_FLAGS. However, this is not necessarily true fow now as the updated loop will let the attr point to the last NLA, even an invalid NLA which could cause overflow writes. This patch introduces a new variable `br_flag` to save the NLA pointer that points to IFLA_BRIDGE_FLAGS and uses it to resolve the mentioned error logic.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27414" target="_blank">CVE-2024-27414</a><br><a href="https://git.kernel.org/stable/c/167d8642daa6a44b51de17f8ff0f584e1e762db7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/743ad091fb46e622f1b690385bb15e3cd3daf874" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/831bc2728fb48a8957a824cba8c264b30dca1425" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/882a51a10ecf24ce135d573afa0872aef02c5125" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a1227b27fcccc99dc44f912b479e01a17e2d7d31" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b9fbc44159dfc3e9a7073032752d9e03f5194a6f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f2261eb994aa5757c1da046b78e3229a3ece0ad9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: confirm multicast packets before passing them up the stack conntrack nf_confirm logic cannot handle cloned skbs referencing the same nf_conn entry, which will happen for multicast (broadcast) frames on bridges. Example: macvlan0 | br0 / \ ethX ethY ethX (or Y) receives a L2 multicast or broadcast packet containing an IP packet, flow is not yet in conntrack table. 1. skb passes through bridge and fake-ip (br_netfilter)Prerouting. -&gt; skb-&gt;_nfct now references a unconfirmed entry 2. skb is broad/mcast packet. bridge now passes clones out on each bridge interface. 3. skb gets passed up the stack. 4. In macvlan case, macvlan driver retains clone(s) of the mcast skb and schedules a work queue to send them out on the lower devices. The clone skb-&gt;_nfct is not a copy, it is the same entry as the original skb. The macvlan rx handler then returns RX_HANDLER_PASS. 5. Normal conntrack hooks (in NF_INET_LOCAL_IN) confirm the orig skb. The Macvlan broadcast worker and normal confirm path will race. This race will not happen if step 2 already confirmed a clone. In that case later steps perform skb_clone() with skb-&gt;_nfct already confirmed (in hash table). This works fine. But such confirmation won't happen when eb/ip/nftables rules dropped the packets before they reached the nf_confirm step in postrouting. Pablo points out that nf_conntrack_bridge doesn't allow use of stateful nat, so we can safely discard the nf_conn entry and let inet call conntrack again. This doesn't work for bridge netfilter: skb could have a nat transformation. Also bridge nf prevents re-invocation of inet prerouting via 'sabotage_in' hook. Work around this problem by explicit confirmation of the entry at LOCAL_IN time, before upper layer has a chance to clone the unconfirmed entry. The downside is that this disables NAT and conntrack helpers. Alternative fix would be to add locking to all code parts that deal with unconfirmed packets, but even if that could be done in a sane way this opens up other problems, for example: -m physdev --physdev-out eth0 -j SNAT --snat-to 1.2.3.4 -m physdev --physdev-out eth1 -j SNAT --snat-to 1.2.3.5 For multicast case, only one of such conflicting mappings will be created, conntrack only handles 1:1 NAT mappings. Users should set create a setup that explicitly marks such traffic NOTRACK (conntrack bypass) to avoid this, but we cannot auto-bypass them, ruleset might have accept rules for untracked traffic already, so user-visible behaviour would change.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27415" target="_blank">CVE-2024-27415</a><br><a href="https://git.kernel.org/stable/c/2b1414d5e94e477edff1d2c79030f1d742625ea0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/62e7151ae3eb465e0ab52a20c941ff33bb6332e9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7c3f28599652acf431a2211168de4a583f30b6d5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/80cd0487f630b5382734997c3e5e3003a77db315" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cb734975b0ffa688ff6cc0eed463865bf07b6c01" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST If we received HCI_EV_IO_CAPA_REQUEST while HCI_OP_READ_REMOTE_EXT_FEATURES is yet to be responded assume the remote does support SSP since otherwise this event shouldn't be generated.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27416" target="_blank">CVE-2024-27416</a><br><a href="https://git.kernel.org/stable/c/30a5e812f78e3d1cced90e1ed750bf027599205f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/79820a7e1e057120c49be07cbe10643d0706b259" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7e74aa53a68bf60f6019bd5d9a9a1406ec4d4865" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8e2758cc25891d2b76717aaf89b40ed215de188c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/afec8f772296dd8e5a2a6f83bbf99db1b9ca877f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c3df637266df29edee85e94cab5fd7041e5753ba" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/df193568d61234c81de7ed4d540c01975de60277" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fba268ac36ab19f9763ff90d276cde0ce6cd5f31" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ipv6: fix potential "struct net" leak in inet6_rtm_getaddr() It seems that if userspace provides a correct IFA_TARGET_NETNSID value but no IFA_ADDRESS and IFA_LOCAL attributes, inet6_rtm_getaddr() returns -EINVAL with an elevated "struct net" refcount.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27417" target="_blank">CVE-2024-27417</a><br><a href="https://git.kernel.org/stable/c/10bfd453da64a057bcfd1a49fb6b271c48653cdb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1b0998fdd85776775d975d0024bca227597e836a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/33a1b6bfef6def2068c8703403759024ce17053e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/44112bc5c74e64f28f5a9127dc34066c7a09bd0f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/810fa7d5e5202fcfb22720304b755f1bdfd4c174" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8a54834c03c30e549c33d5da0975f3e1454ec906" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9d4ffb5b9d879a75e4f7460e8b10e756b4dfb132" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: mctp: take ownership of skb in mctp_local_output Currently, mctp_local_output only takes ownership of skb on success, and we may leak an skb if mctp_local_output fails in specific states; the skb ownership isn't transferred until the actual output routing occurs. Instead, make mctp_local_output free the skb on all error paths up to the route action, so it always consumes the passed skb.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27418" target="_blank">CVE-2024-27418</a><br><a href="https://git.kernel.org/stable/c/3773d65ae5154ed7df404b050fd7387a36ab5ef3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a3c8fa54e904b0ddb52a08cc2d8ac239054f61fd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a639441c880ac479495e5ab37e3c29f21ae5771b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cbebc55ceacef1fc0651e80e0103cc184552fc68" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix data-races around sysctl_net_busy_read We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27419" target="_blank">CVE-2024-27419</a><br><a href="https://git.kernel.org/stable/c/0866afaff19d8460308b022345ed116a12b1d0e1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/16d71319e29d5825ab53f263b59fdd8dc2d60ad4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/34cab94f7473e7b09f5205d4583fb5096cb63b5b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/43464808669ba9d23996f0b6d875450191687caf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bbf950a6e96a91cf8cf0c71117b94ed3fafc9dd3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d380ce70058a4ccddc3e5f5c2063165dc07672c6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d623fd5298d95b65d27ef5a618ebf39541074856" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f9055fa2b2931261d5f89948ee5bc315b6a22d4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_link_fails_count We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27420" target="_blank">CVE-2024-27420</a><br><a href="https://git.kernel.org/stable/c/07bbccd1adb56b39eef982b8960d59e3c005c6a1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0b8eb369c182814d817b9449bc9e86bfae4310f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/97a4d8b9f67cc7efe9a0c137e12f6d9e40795bf1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bc76645ebdd01be9b9994dac39685a3d0f6f7985" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c558e54f7712b086fbcb611723272a0a4b0d451c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cfe0f73fb38a01bce86fe15ef5f750f850f7d3fe" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cfedde3058bf976f2f292c0a236edd43afcdab57" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/db364859ce68fb3a52d42cd87a54da3dc42dc1c8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_routing_control We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27421" target="_blank">CVE-2024-27421</a><br><a href="https://git.kernel.org/stable/c/4c02b9ccbb11862ee39850b2b285664cd579b039" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/859175d4bc11af829e2fdd261a7effdaba9b5d8f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b5dffcb8f71bdd02a4e5799985b51b12f4eeaf76" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b7d33e083f9d5d39445c0a91e7ad4f3e2c47fcb5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c13fbb5902bce848759385986d4833f5b90782c1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c4309e5f8e80584715c814e1d012dbc3eee5a500" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d732b83251322ecd3b503e03442247745d6052ce" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f9c4d42464173b826190fae2283ed1a4bbae0c8b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_no_activity_timeout We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27422" target="_blank">CVE-2024-27422</a><br><a href="https://git.kernel.org/stable/c/01d4e3afe257768cd2a45f15a0e57bacf932b140" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2309b369fae2d9cdc3c945cd3eaec84eb1958ca3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/498f1d6da11ed6d736d655a2db14ee2d9569eecb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4eacb242e22e31385a50a393681d0fe4b55ed1e9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6f254abae02abd4a0aca062c1b3812d7e2d8ea94" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/73426c32e259c767d40613b956d5b80d0c28a9a9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cbba77abb4a553c1f5afac1ba2a0861aa1f13549" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f99b494b40431f0ca416859f2345746199398e2b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_requested_window_size We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27423" target="_blank">CVE-2024-27423</a><br><a href="https://git.kernel.org/stable/c/0d43a58900e5a2bfcc9de47e16c6c501c0bef853" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/46803b776d869b0c36041828a83c4f7da2dfa03b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/489e05c614dbeb1a1148959f02bdb788891819e6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4f2efa17c3ec5e4be0567b47439b9713c0dc6550" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/652b0b35819610a42b8a90d21acb12f69943b397" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/89aa78a34340e9dbc3248095f44d81d0e1c23193" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a2e706841488f474c06e9b33f71afc947fb3bf56" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/db006d7edbf0b4800390ece3727a82f4ae764043" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_busy_delay We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27424" target="_blank">CVE-2024-27424</a><br><a href="https://git.kernel.org/stable/c/0a30016e892bccabea30af218782c4b6ce0970af" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1f60795dcafc97c45984240d442cdc151f825977" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/43547d8699439a67b78d6bb39015113f7aa360fd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4ccad39009e7bd8a03d60a97c87b0327ae812880" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5ac337138272d26d6d3d4f71bc5b1a87adf8b24d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7782e5e7047cae6b9255ee727c99fc73d77cf773" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/85f34d352f4b79afd63dd13634b23dafe6b570f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f3315a6edaec12b461031eab8c98c78111a41f95" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_acknowledge_delay We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27425" target="_blank">CVE-2024-27425</a><br><a href="https://git.kernel.org/stable/c/33081e0f34899d5325e7c45683dd8dc9cb18b583" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/34c84e0036a60e7e50ae50b42ed194d8daef8cc9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5deaef2bf56456c71b841e0dfde1bee2fd88c4eb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6133a71c75dacea12fcc85838b4455c2055b0f14" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7d56ffc51ebd2777ded8dca50d631ee19d97db5c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/80578681ea274e0a6512bb7515718c206a7b74cf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/806f462ba9029d41aadf8ec93f2f99c5305deada" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a22f9194f61ad4f2b6405c7c86bee85eac1befa5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_maximum_tries We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27426" target="_blank">CVE-2024-27426</a><br><a href="https://git.kernel.org/stable/c/34a164d2448264b62af82bc0af3d2c83d12d38ac" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/42e71408e2c138be9ccce60920bd6cf094ba1e32" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/84b8486e9cedc93875f251ba31abcf73bd586a3a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d28fa5f0e6c1554e2829f73a6a276c9a49689d04" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e799299aafed417cc1f32adccb2a0e5268b3f6d5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f716a68234242f95305dffb5c9426caa64b316b0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f84f7709486d8a578ab4b7d2a556d1b1a59cfc97" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fa3f3ab5c399852d32a0c3cbb8c55882f7e2c61f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_timeout We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27427" target="_blank">CVE-2024-27427</a><br><a href="https://git.kernel.org/stable/c/291d36d772f5ea5c68a263ee440f2c9eade371c9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/500936692ccca8617a955652d1929f079b17a201" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5d5c14efc987900509cec465af26608e39ac607c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/60a7a152abd494ed4f69098cf0f322e6bb140612" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7d1e00fc2af3b7c30835d643a3655b7e9ff7cb20" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b8006cb0a34aaf85cdd8741f4148fd9c76b351d3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eadec8da4451c2c0897199691184602e4ee497d1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fed835d415766a94fc0246dcebc3af4c03fe9941" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix data-races around sysctl_netrom_network_ttl_initialiser We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27428" target="_blank">CVE-2024-27428</a><br><a href="https://git.kernel.org/stable/c/119cae5ea3f9e35cdada8e572cc067f072fa825a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5731369af2de21695fe7c1c91fe134fabe5b33b8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/775ed3549819f814a6ecef5726d2b4c23f249b77" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a47d68d777b41862757b7e3051f2d46d6e25f87b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/acc653e8a3aaab1b7103f98645f2cce7be89e3d3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d1261bde59a3a087ab0c81181821e194278d9264" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dca1d93fe42fb9c42b66f61714fbdc55c87eb002" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eda02a0bed550f07a8283d3e1f25b90a38e151ed" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_obsolescence_count_initialiser We need to protect the reader reading the sysctl value because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27429" target="_blank">CVE-2024-27429</a><br><a href="https://git.kernel.org/stable/c/18c95d11c347a12e5c31df1325cef6b995d14ecf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1e84b108f2a71daa8d04032e4d2096522376debb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/591192c3a9fc728a0af7b9dd50bf121220062293" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7e1e25891f090e24a871451c9403abac63cb45dd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b3f0bc3a315cf1af03673a0163c08fe037587acd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cfd9f4a740f772298308b2e6070d2c744fb5cf79" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e3a3718b1723253d4f068e88e81d880d71f1a1e9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e439607291c082332e1e35baf8faf8552e6bcb4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_default_path_quality We need to protect the reader reading sysctl_netrom_default_path_quality because the value can be changed concurrently.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27430" target="_blank">CVE-2024-27430</a><br><a href="https://git.kernel.org/stable/c/392eb88416dcbc5f1d61b9a88d79d78dc8b27652" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7510b08c5f5ba15983da004b021fc6154eeb4047" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7644df766006d4878a556e427e3ecc78c2d5606b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7f615232556f3c6e3eeecef96ef2b00d0aa905bb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/958d6145a6d9ba9e075c921aead8753fb91c9101" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bbc21f134b89535d1cf110c5f2b33ac54e5839c4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dec82a8fc45c6ce494c2cb31f001a2aadb132b57" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e041df5dc9e68adffcba5499ca28e1252bed6f4b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: cpumap: Zero-initialise xdp_rxq_info struct before running XDP program When running an XDP program that is attached to a cpumap entry, we don't initialise the xdp_rxq_info data structure being used in the xdp_buff that backs the XDP program invocation. Tobias noticed that this leads to random values being returned as the xdp_md-&gt;rx_queue_index value for XDP programs running in a cpumap. This means we're basically returning the contents of the uninitialised memory, which is bad. Fix this by zero-initialising the rxq data structure before running the XDP program.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27431" target="_blank">CVE-2024-27431</a><br><a href="https://git.kernel.org/stable/c/2487007aa3b9fafbd2cb14068f49791ce1d7ede5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3420b3ff1ff489c177ea1cb7bd9fbbc4e9a0be95" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5f4e51abfbe6eb444fa91906a5cd083044278297" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eaa7cb836659ced2d9f814ac32aa3ec193803ed6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f0363af9619c77730764f10360e36c6445c12f7b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f562e4c4aab00986dde3093c4be919c3f2b85a4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: fix PPE hanging issue A patch to resolve an issue was found in MediaTek's GPL-licensed SDK: In the mtk_ppe_stop() function, the PPE scan mode is not disabled before disabling the PPE. This can potentially lead to a hang during the process of disabling the PPE. Without this patch, the PPE may experience a hang during the reboot test.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27432" target="_blank">CVE-2024-27432</a><br><a href="https://git.kernel.org/stable/c/09a1907433865b7c8ee6777e507f5126bdd38c0f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/49202a8256fc50517ef06fd5e2084c4febde6369" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/943c14ece95eb1cf98d477462aebcbfdfd714633" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9fcadd125044007351905d40c405fadc2d3bb6d6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ea80e3ed09ab2c2b75724faf5484721753e92c31" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f78807362828ad01db2a9ed005bf79501b620f27" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: mt7622-apmixedsys: Fix an error handling path in clk_mt8135_apmixed_probe() 'clk_data' is allocated with mtk_devm_alloc_clk_data(). So calling mtk_free_clk_data() explicitly in the remove function would lead to a double-free. Remove the redundant call.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27433" target="_blank">CVE-2024-27433</a><br><a href="https://git.kernel.org/stable/c/a32e88f2b20259f5fe4f8eed598bbc85dc4879ed" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/de3340533bd68a7b3d6be1841b8eb3fa6c762fe6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f3633fed984f1db106ff737a0bb52fadb2d89ac7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fa761ce7a1d15cca1a306b3635f81a22b15fee5b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: don't set the MFP flag for the GTK The firmware doesn't need the MFP flag for the GTK, it can even make the firmware crash. in case the AP is configured with: group cipher TKIP and MFPC. We would send the GTK with cipher = TKIP and MFP which is of course not possible.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27434" target="_blank">CVE-2024-27434</a><br><a href="https://git.kernel.org/stable/c/40405cbb20eb6541c603e7b3d54ade0a7be9d715" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/60f6d5fc84a9fd26528a24d8a267fc6a6698b628" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b4f1b0b3b91762edd19bf9d3b2e4c3a0740501f8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e35f316bce9e5733c9826120c1838f4c447b2c4c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: nvme: fix reconnection fail due to reserved tag allocation We found a issue on production environment while using NVMe over RDMA, admin_q reconnect failed forever while remote target and network is ok. After dig into it, we found it may caused by a ABBA deadlock due to tag allocation. In my case, the tag was hold by a keep alive request waiting inside admin_q, as we quiesced admin_q while reset ctrl, so the request maked as idle and will not process before reset success. As fabric_q shares tagset with admin_q, while reconnect remote target, we need a tag for connect command, but the only one reserved tag was held by keep alive command which waiting inside admin_q. As a result, we failed to reconnect admin_q forever. In order to fix this issue, I think we should keep two reserved tags for admin queue.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27435" target="_blank">CVE-2024-27435</a><br><a href="https://git.kernel.org/stable/c/149afee5c7418ec5db9d7387b9c9a5c1eb7ea2a8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/262da920896e2f2ab0e3947d9dbee0aa09045818" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6851778504cdb49431809b4ba061903d5f592c96" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/de105068fead55ed5c07ade75e9c8e7f86a00d1d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ff2f90f88d78559802466ad1c84ac5bda4416b3a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Stop parsing channels bits when all channels are found. If a usb audio device sets more bits than the amount of channels it could write outside of the map array.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27436" target="_blank">CVE-2024-27436</a><br><a href="https://git.kernel.org/stable/c/22cad1b841a63635a38273b799b4791f202ade72" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5cd466673b34bac369334f66cbe14bb77b7d7827" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/629af0d5fe94a35f498ba2c3f19bd78bfa591be6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6d5dc96b154be371df0d62ecb07efe400701ed8a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6d88b289fb0a8d055cb79d1c46a56aba7809d96d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7e2c1b0f6dd9abde9e60f0f9730026714468770f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9af1658ba293458ca6a13f70637b9654fa4be064" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a39d51ff1f52cd0b6fe7d379ac93bd8b4237d1b7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c8a24fd281dcdf3c926413dafbafcf35cde517a9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: btrfs: fix deadlock with fiemap and extent locking While working on the patchset to remove extent locking I got a lockdep splat with fiemap and pagefaulting with my new extent lock replacement lock. This deadlock exists with our normal code, we just don't have lockdep annotations with the extent locking so we've never noticed it. Since we're copying the fiemap extent to user space on every iteration we have the chance of pagefaulting. Because we hold the extent lock for the entire range we could mkwrite into a range in the file that we have mmap'ed. This would deadlock with the following stack trace [&lt;0&gt;] lock_extent+0x28d/0x2f0 [&lt;0&gt;] btrfs_page_mkwrite+0x273/0x8a0 [&lt;0&gt;] do_page_mkwrite+0x50/0xb0 [&lt;0&gt;] do_fault+0xc1/0x7b0 [&lt;0&gt;] __handle_mm_fault+0x2fa/0x460 [&lt;0&gt;] handle_mm_fault+0xa4/0x330 [&lt;0&gt;] do_user_addr_fault+0x1f4/0x800 [&lt;0&gt;] exc_page_fault+0x7c/0x1e0 [&lt;0&gt;] asm_exc_page_fault+0x26/0x30 [&lt;0&gt;] rep_movs_alternative+0x33/0x70 [&lt;0&gt;] _copy_to_user+0x49/0x70 [&lt;0&gt;] fiemap_fill_next_extent+0xc8/0x120 [&lt;0&gt;] emit_fiemap_extent+0x4d/0xa0 [&lt;0&gt;] extent_fiemap+0x7f8/0xad0 [&lt;0&gt;] btrfs_fiemap+0x49/0x80 [&lt;0&gt;] __x64_sys_ioctl+0x3e1/0xb50 [&lt;0&gt;] do_syscall_64+0x94/0x1a0 [&lt;0&gt;] entry_SYSCALL_64_after_hwframe+0x6e/0x76 I wrote an fstest to reproduce this deadlock without my replacement lock and verified that the deadlock exists with our existing locking. To fix this simply don't take the extent lock for the entire duration of the fiemap. This is safe in general because we keep track of where we are when we're searching the tree, so if an ordered extent updates in the middle of our fiemap call we'll still emit the correct extents because we know what offset we were on before. The only place we maintain the lock is searching delalloc. Since the delalloc stuff can change during writeback we want to lock the extent range so we have a consistent view of delalloc at the time we're checking to see if we need to set the delalloc flag. With this patch applied we no longer deadlock with my testcase.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35784" target="_blank">CVE-2024-35784</a><br><a href="https://git.kernel.org/stable/c/89bca7fe6382d61e88c67a0b0e7bce315986fb8b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b0ad381fa7690244802aed119b478b4bdafc31dd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ded566b4637f1b6b4c9ba74e7d0b8493e93f19cf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix kernel panic caused by incorrect error handling The error path while failing to register devices on the TEE bus has a bug leading to kernel panic as follows: [ 15.398930] Unable to handle kernel paging request at virtual address ffff07ed00626d7c [ 15.406913] Mem abort info: [ 15.409722] ESR = 0x0000000096000005 [ 15.413490] EC = 0x25: DABT (current EL), IL = 32 bits [ 15.418814] SET = 0, FnV = 0 [ 15.421878] EA = 0, S1PTW = 0 [ 15.425031] FSC = 0x05: level 1 translation fault [ 15.429922] Data abort info: [ 15.432813] ISV = 0, ISS = 0x00000005, ISS2 = 0x00000000 [ 15.438310] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 15.443372] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [ 15.448697] swapper pgtable: 4k pages, 48-bit VAs, pgdp=00000000d9e3e000 [ 15.455413] [ffff07ed00626d7c] pgd=1800000bffdf9003, p4d=1800000bffdf9003, pud=0000000000000000 [ 15.464146] Internal error: Oops: 0000000096000005 [#1] PREEMPT SMP Commit 7269cba53d90 ("tee: optee: Fix supplicant based device enumeration") lead to the introduction of this bug. So fix it appropriately.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35785" target="_blank">CVE-2024-35785</a><br><a href="https://git.kernel.org/stable/c/4b12ff5edd141926d49c9ace4791adf3a4902fe7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/520f79c110ff712b391b3d87fcacf03c74bc56ee" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/95915ba4b987cf2b222b0f251280228a1ff977ac" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bc40ded92af55760d12bec8222d4108de725dbe4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bfa344afbe472a9be08f78551fa2190c1a07d7d3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e5b5948c769aa1ebf962dddfb972f87d8f166f95" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix stale locked mutex in nouveau_gem_ioctl_pushbuf If VM_BIND is enabled on the client the legacy submission ioctl can't be used, however if a client tries to do so regardless it will return an error. In this case the clients mutex remained unlocked leading to a deadlock inside nouveau_drm_postclose or any other nouveau ioctl call.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35786" target="_blank">CVE-2024-35786</a><br><a href="https://git.kernel.org/stable/c/b466416bdd6ecbde15ce987226ea633a0268fbb1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c288a61a48ddb77ec097e11ab81b81027cd4e197" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/daf8739c3322a762ce84f240f50e0c39181a41ab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: md/md-bitmap: fix incorrect usage for sb_index Commit d7038f951828 ("md-bitmap: don't use -&gt;index for pages backing the bitmap file") removed page-&gt;index from bitmap code, but left wrong code logic for clustered-md. current code never set slot offset for cluster nodes, will sometimes cause crash in clustered env. Call trace (partly): md_bitmap_file_set_bit+0x110/0x1d8 [md_mod] md_bitmap_startwrite+0x13c/0x240 [md_mod] raid1_make_request+0x6b0/0x1c08 [raid1] md_handle_request+0x1dc/0x368 [md_mod] md_submit_bio+0x80/0xf8 [md_mod] __submit_bio+0x178/0x300 submit_bio_noacct_nocheck+0x11c/0x338 submit_bio_noacct+0x134/0x614 submit_bio+0x28/0xdc submit_bh_wbc+0x130/0x1cc submit_bh+0x1c/0x28</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35787" target="_blank">CVE-2024-35787</a><br><a href="https://git.kernel.org/stable/c/55e55eb65fd5e09faf5a0e49ffcdd37905aaf4da" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5a95815b17428ce2f56ec18da5e0d1b2a1a15240" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/736ad6c577a367834118f57417038d45bb5e0a31" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ecbd8ebb51bf7e4939d83b9e6022a55cac44ef06" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix bounds check for dcn35 DcfClocks [Why] NumFclkLevelsEnabled is used for DcfClocks bounds check instead of designated NumDcfClkLevelsEnabled. That can cause array index out-of-bounds access. [How] Use designated variable for dcn35 DcfClocks bounds check.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35788" target="_blank">CVE-2024-35788</a><br><a href="https://git.kernel.org/stable/c/2f10d4a51bbcd938f1f02f16c304ad1d54717b96" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c373f233dab44a13752daec13788e2ad3bf86410" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f6e163e9c3d50cd167ab9d411ed01b7718177387" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes When moving a station out of a VLAN and deleting the VLAN afterwards, the fast_rx entry still holds a pointer to the VLAN's netdev, which can cause use-after-free bugs. Fix this by immediately calling ieee80211_check_fast_rx after the VLAN change.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35789" target="_blank">CVE-2024-35789</a><br><a href="https://git.kernel.org/stable/c/2884a50f52313a7a911de3afcad065ddbb3d78fc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4f2bdb3c5e3189297e156b3ff84b140423d64685" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6b948b54c8bd620725e0c906e44b10c0b13087a7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7eeabcea79b67cc29563e6a9a5c81f9e2c664d5b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/be1dd9254fc115321d6fbee042026d42afc8d931" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c8bddbd91bc8e42c961a5e2cec20ab879f21100f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e8678551c0243f799b4859448781cbec1bd6f1cb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e8b067c4058c0121ac8ca71559df8e2e08ff1a7e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ea9a0cfc07a7d3601cc680718d9cff0d6927a921" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: create sysfs nodes as driver's default device attribute group The DisplayPort driver's sysfs nodes may be present to the userspace before typec_altmode_set_drvdata() completes in dp_altmode_probe. This means that a sysfs read can trigger a NULL pointer error by deferencing dp-&gt;hpd in hpd_show or dp-&gt;lock in pin_assignment_show, as dev_get_drvdata() returns NULL in those cases. Remove manual sysfs node creation in favor of adding attribute group as default for devices bound to the driver. The ATTRIBUTE_GROUPS() macro is not used here otherwise the path to the sysfs nodes is no longer compliant with the ABI.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35790" target="_blank">CVE-2024-35790</a><br><a href="https://git.kernel.org/stable/c/0ad011776c057ce881b7fd6d8c79ecd459c087e9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/165376f6b23e9a779850e750fb2eb06622e5a531" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4a22aeac24d0d5f26ba741408e8b5a4be6dc5dc0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Flush pages under kvm-&gt;lock to fix UAF in svm_register_enc_region() Do the cache flush of converted pages in svm_register_enc_region() before dropping kvm-&gt;lock to fix use-after-free issues where region and/or its array of pages could be freed by a different task, e.g. if userspace has __unregister_enc_region_locked() already queued up for the region. Note, the "obvious" alternative of using local variables doesn't fully resolve the bug, as region-&gt;pages is also dynamically allocated. I.e. the region structure itself would be fine, but region-&gt;pages could be freed. Flushing multiple pages under kvm-&gt;lock is unfortunate, but the entire flow is a rare slow path, and the manual flush is only needed on CPUs that lack coherency for encrypted memory.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35791" target="_blank">CVE-2024-35791</a><br><a href="https://git.kernel.org/stable/c/12f8e32a5a389a5d58afc67728c76e61beee1ad4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2d13b79640b147bd77c34a5998533b2021a4122d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4868c0ecdb6cfde7c70cf478c46e06bb9c7e5865" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5ef1d8c1ddbf696e47b226e11888eaf8d9e8e807" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e126b508ed2e616d679d85fca2fbe77bb48bbdd7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f6d53d8a2617dd58c89171a6b9610c470ebda38a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: crypto: rk3288 - Fix use after free in unprepare The unprepare call must be carried out before the finalize call as the latter can free the request.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35792" target="_blank">CVE-2024-35792</a><br><a href="https://git.kernel.org/stable/c/48dd260fdb728eda4a246f635d1325e82f0d3555" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c0afb6b88fbbc177fa322a835f874be217bffe45" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eb2a41a8ae8c8c4f68aef3bd94665c0cf23e04be" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: debugfs: fix wait/cancellation handling during remove Ben Greear further reports deadlocks during concurrent debugfs remove while files are being accessed, even though the code in question now uses debugfs cancellations. Turns out that despite all the review on the locking, we missed completely that the logic is wrong: if the refcount hits zero we can finish (and need not wait for the completion), but if it doesn't we have to trigger all the cancellations. As written, we can _never_ get into the loop triggering the cancellations. Fix this, and explain it better while at it.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35793" target="_blank">CVE-2024-35793</a><br><a href="https://git.kernel.org/stable/c/3d08cca5fd0aabb62b7015067ab40913b33da906" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/952c3fce297f12c7ff59380adb66b564e2bc9b64" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e88b5ae01901c4a655a53158397746334778a57b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dm-raid: really frozen sync_thread during suspend 1) commit f52f5c71f3d4 ("md: fix stopping sync thread") remove MD_RECOVERY_FROZEN from __md_stop_writes() and doesn't realize that dm-raid relies on __md_stop_writes() to frozen sync_thread indirectly. Fix this problem by adding MD_RECOVERY_FROZEN in md_stop_writes(), and since stop_sync_thread() is only used for dm-raid in this case, also move stop_sync_thread() to md_stop_writes(). 2) The flag MD_RECOVERY_FROZEN doesn't mean that sync thread is frozen, it only prevent new sync_thread to start, and it can't stop the running sync thread; In order to frozen sync_thread, after seting the flag, stop_sync_thread() should be used. 3) The flag MD_RECOVERY_FROZEN doesn't mean that writes are stopped, use it as condition for md_stop_writes() in raid_postsuspend() doesn't look correct. Consider that reentrant stop_sync_thread() do nothing, always call md_stop_writes() in raid_postsuspend(). 4) raid_message can set/clear the flag MD_RECOVERY_FROZEN at anytime, and if MD_RECOVERY_FROZEN is cleared while the array is suspended, new sync_thread can start unexpected. Fix this by disallow raid_message() to change sync_thread status during suspend. Note that after commit f52f5c71f3d4 ("md: fix stopping sync thread"), the test shell/lvconvert-raid-reshape.sh start to hang in stop_sync_thread(), and with previous fixes, the test won't hang there anymore, however, the test will still fail and complain that ext4 is corrupted. And with this patch, the test won't hang due to stop_sync_thread() or fail due to ext4 is corrupted anymore. However, there is still a deadlock related to dm-raid456 that will be fixed in following patches.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35794" target="_blank">CVE-2024-35794</a><br><a href="https://git.kernel.org/stable/c/16c4770c75b1223998adbeb7286f9a15c65fba73" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/af916cb66a80597f3523bc85812e790bcdcfd62b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/eaa8fc9b092837cf2c754bde1a15d784ce9a85ab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix deadlock while reading mqd from debugfs An errant disk backup on my desktop got into debugfs and triggered the following deadlock scenario in the amdgpu debugfs files. The machine also hard-resets immediately after those lines are printed (although I wasn't able to reproduce that part when reading by hand): [ 1318.016074][ T1082] ====================================================== [ 1318.016607][ T1082] WARNING: possible circular locking dependency detected [ 1318.017107][ T1082] 6.8.0-rc7-00015-ge0c8221b72c0 #17 Not tainted [ 1318.017598][ T1082] ------------------------------------------------------ [ 1318.018096][ T1082] tar/1082 is trying to acquire lock: [ 1318.018585][ T1082] ffff98c44175d6a0 (&amp;mm-&gt;mmap_lock){++++}-{3:3}, at: __might_fault+0x40/0x80 [ 1318.019084][ T1082] [ 1318.019084][ T1082] but task is already holding lock: [ 1318.020052][ T1082] ffff98c4c13f55f8 (reservation_ww_class_mutex){+.+.}-{3:3}, at: amdgpu_debugfs_mqd_read+0x6a/0x250 [amdgpu] [ 1318.020607][ T1082] [ 1318.020607][ T1082] which lock already depends on the new lock. [ 1318.020607][ T1082] [ 1318.022081][ T1082] [ 1318.022081][ T1082] the existing dependency chain (in reverse order) is: [ 1318.023083][ T1082] [ 1318.023083][ T1082] -&gt; #2 (reservation_ww_class_mutex){+.+.}-{3:3}: [ 1318.024114][ T1082] __ww_mutex_lock.constprop.0+0xe0/0x12f0 [ 1318.024639][ T1082] ww_mutex_lock+0x32/0x90 [ 1318.025161][ T1082] dma_resv_lockdep+0x18a/0x330 [ 1318.025683][ T1082] do_one_initcall+0x6a/0x350 [ 1318.026210][ T1082] kernel_init_freeable+0x1a3/0x310 [ 1318.026728][ T1082] kernel_init+0x15/0x1a0 [ 1318.027242][ T1082] ret_from_fork+0x2c/0x40 [ 1318.027759][ T1082] ret_from_fork_asm+0x11/0x20 [ 1318.028281][ T1082] [ 1318.028281][ T1082] -&gt; #1 (reservation_ww_class_acquire){+.+.}-{0:0}: [ 1318.029297][ T1082] dma_resv_lockdep+0x16c/0x330 [ 1318.029790][ T1082] do_one_initcall+0x6a/0x350 [ 1318.030263][ T1082] kernel_init_freeable+0x1a3/0x310 [ 1318.030722][ T1082] kernel_init+0x15/0x1a0 [ 1318.031168][ T1082] ret_from_fork+0x2c/0x40 [ 1318.031598][ T1082] ret_from_fork_asm+0x11/0x20 [ 1318.032011][ T1082] [ 1318.032011][ T1082] -&gt; #0 (&amp;mm-&gt;mmap_lock){++++}-{3:3}: [ 1318.032778][ T1082] __lock_acquire+0x14bf/0x2680 [ 1318.033141][ T1082] lock_acquire+0xcd/0x2c0 [ 1318.033487][ T1082] __might_fault+0x58/0x80 [ 1318.033814][ T1082] amdgpu_debugfs_mqd_read+0x103/0x250 [amdgpu] [ 1318.034181][ T1082] full_proxy_read+0x55/0x80 [ 1318.034487][ T1082] vfs_read+0xa7/0x360 [ 1318.034788][ T1082] ksys_read+0x70/0xf0 [ 1318.035085][ T1082] do_syscall_64+0x94/0x180 [ 1318.035375][ T1082] entry_SYSCALL_64_after_hwframe+0x46/0x4e [ 1318.035664][ T1082] [ 1318.035664][ T1082] other info that might help us debug this: [ 1318.035664][ T1082] [ 1318.036487][ T1082] Chain exists of: [ 1318.036487][ T1082] &amp;mm-&gt;mmap_lock --&gt; reservation_ww_class_acquire --&gt; reservation_ww_class_mutex [ 1318.036487][ T1082] [ 1318.037310][ T1082] Possible unsafe locking scenario: [ 1318.037310][ T1082] [ 1318.037838][ T1082] CPU0 CPU1 [ 1318.038101][ T1082] ---- ---- [ 1318.038350][ T1082] lock(reservation_ww_class_mutex); [ 1318.038590][ T1082] lock(reservation_ww_class_acquire); [ 1318.038839][ T1082] lock(reservation_ww_class_mutex); [ 1318.039083][ T1082] rlock(&amp;mm-&gt;mmap_lock); [ 1318.039328][ T1082] [ 1318.039328][ T1082] *** DEADLOCK *** [ 1318.039328][ T1082] [ 1318.040029][ T1082] 1 lock held by tar/1082: [ 1318.040259][ T1082] #0: ffff98c4c13f55f8 (reservation_ww_class_mutex){+.+.}-{3:3}, at: amdgpu_debugfs_mqd_read+0x6a/0x250 [amdgpu] [ 1318.040560][ T1082] [ 1318.040560][ T1082] stack backtrace: [ ---truncated---</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35795" target="_blank">CVE-2024-35795</a><br><a href="https://git.kernel.org/stable/c/197f6d6987c55860f6eea1c93e4f800c59078874" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4687e3c6ee877ee25e57b984eca00be53b9a8db5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8678b1060ae2b75feb60b87e5b75e17374e3c1c5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8b03556da6e576c62664b6cd01809e4a09d53b5b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: ll_temac: platform_get_resource replaced by wrong function The function platform_get_resource was replaced with devm_platform_ioremap_resource_byname and is called using 0 as name. This eventually ends up in platform_get_resource_byname in the call stack, where it causes a null pointer in strcmp. if (type == resource_type(r) &amp;&amp; !strcmp(r-&gt;name, name)) It should have been replaced with devm_platform_ioremap_resource.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35796" target="_blank">CVE-2024-35796</a><br><a href="https://git.kernel.org/stable/c/3a38a829c8bc27d78552c28e582eb1d885d07d11" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/46efbdbc95a30951c2579caf97b6df2ee2b3bef3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/476eed5f1c22034774902a980aa48dc4662cb39a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/553d294db94b5f139378022df480a9fb6c3ae39e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6d9395ba7f85bdb7af0b93272e537484ecbeff48" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7e9edb569fd9f688d887e36db8170f6e22bafbc8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/92c0c29f667870f17c0b764544bdf22ce0e886a1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix two shmem bugs When cachestat on shmem races with swapping and invalidation, there are two possible bugs: 1) A swapin error can have resulted in a poisoned swap entry in the shmem inode's xarray. Calling get_shadow_from_swap_cache() on it will result in an out-of-bounds access to swapper_spaces[]. Validate the entry with non_swap_entry() before going further. 2) When we find a valid swap entry in the shmem's inode, the shadow entry in the swapcache might not exist yet: swap IO is still in progress and we're before __remove_mapping; swapin, invalidation, or swapoff have removed the shadow from swapcache after we saw the shmem swap entry. This will send a NULL to workingset_test_recent(). The latter purely operates on pointer bits, so it won't crash - node 0, memcg ID 0, eviction timestamp 0, etc. are all valid inputs - but it's a bogus test. In theory that could result in a false "recently evicted" count. Such a false positive wouldn't be the end of the world. But for code clarity and (future) robustness, be explicit about this case. Bail on get_shadow_from_swap_cache() returning NULL.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35797" target="_blank">CVE-2024-35797</a><br><a href="https://git.kernel.org/stable/c/24a0e73d544439bb9329fbbafac44299e548a677" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b79f9e1ff27c994a4c452235ba09e672ec698e23" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d5d39c707a4cf0bcc84680178677b97aa2cb2627" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d962f6c583458037dc7e529659b2b02b9dd3d94b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: btrfs: fix race in read_extent_buffer_pages() There are reports from tree-checker that detects corrupted nodes, without any obvious pattern so possibly an overwrite in memory. After some debugging it turns out there's a race when reading an extent buffer the uptodate status can be missed. To prevent concurrent reads for the same extent buffer, read_extent_buffer_pages() performs these checks: /* (1) */ if (test_bit(EXTENT_BUFFER_UPTODATE, &amp;eb-&gt;bflags)) return 0; /* (2) */ if (test_and_set_bit(EXTENT_BUFFER_READING, &amp;eb-&gt;bflags)) goto done; At this point, it seems safe to start the actual read operation. Once that completes, end_bbio_meta_read() does /* (3) */ set_extent_buffer_uptodate(eb); /* (4) */ clear_bit(EXTENT_BUFFER_READING, &amp;eb-&gt;bflags); Normally, this is enough to ensure only one read happens, and all other callers wait for it to finish before returning. Unfortunately, there is a racey interleaving: Thread A | Thread B | Thread C ---------+----------+--------- (1) | | | (1) | (2) | | (3) | | (4) | | | (2) | | | (1) When this happens, thread B kicks of an unnecessary read. Worse, thread C will see UPTODATE set and return immediately, while the read from thread B is still in progress. This race could result in tree-checker errors like this as the extent buffer is concurrently modified: BTRFS critical (device dm-0): corrupted node, root=256 block=8550954455682405139 owner mismatch, have 11858205567642294356 expect [256, 18446744073709551360] Fix it by testing UPTODATE again after setting the READING bit, and if it's been set, skip the unnecessary read. [ minor update of changelog ]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35798" target="_blank">CVE-2024-35798</a><br><a href="https://git.kernel.org/stable/c/0427c8ef8bbb7f304de42ef51d69c960e165e052" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2885d54af2c2e1d910e20d5c8045bae40e02fbc1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3a25878a3378adce5d846300c9570f15aa7f7a80" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ef1e68236b9153c27cb7cf29ead0c532870d4215" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Prevent crash when disable stream [Why] Disabling stream encoder invokes a function that no longer exists. [How] Check if the function declaration is NULL in disable stream encoder.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35799" target="_blank">CVE-2024-35799</a><br><a href="https://git.kernel.org/stable/c/2b17133a0a2e0e111803124dad09e803718d4a48" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4356a2c3f296503c8b420ae8adece053960a9f06" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/59772327d439874095516673b4b30c48bd83ca38" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/72d72e8fddbcd6c98e1b02d32cf6f2b04e10bd1c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: efi: fix panic in kdump kernel Check if get_next_variable() is actually valid pointer before calling it. In kdump kernel this method is set to NULL that causes panic during the kexec-ed kernel boot. Tested with QEMU and OVMF firmware.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35800" target="_blank">CVE-2024-35800</a><br><a href="https://git.kernel.org/stable/c/090d2b4515ade379cd592fbc8931344945978210" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/62b71cd73d41ddac6b1760402bbe8c4932e23531" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7784135f134c13af17d9ffb39a57db8500bc60ff" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9114ba9987506bcfbb454f6e68558d68cb1abbde" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b9d103aca85f082a343b222493f3cab1219aaaf4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Keep xfd_state in sync with MSR_IA32_XFD Commit 672365477ae8 ("x86/fpu: Update XFD state where required") and commit 8bf26758ca96 ("x86/fpu: Add XFD state to fpstate") introduced a per CPU variable xfd_state to keep the MSR_IA32_XFD value cached, in order to avoid unnecessary writes to the MSR. On CPU hotplug MSR_IA32_XFD is reset to the init_fpstate.xfd, which wipes out any stale state. But the per CPU cached xfd value is not reset, which brings them out of sync. As a consequence a subsequent xfd_update_state() might fail to update the MSR which in turn can result in XRSTOR raising a #NM in kernel space, which crashes the kernel. To fix this, introduce xfd_set_state() to write xfd_state together with MSR_IA32_XFD, and use it in all places that set MSR_IA32_XFD.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35801" target="_blank">CVE-2024-35801</a><br><a href="https://git.kernel.org/stable/c/10e4b5166df9ff7a2d5316138ca668b42d004422" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1acbca933313aa866e39996904c9aca4d435c4cd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/21c7c00dae55cb0e3810d5f9506b58f68475d41d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/92b0f04e937665bde5768f3fcc622dcce44413d8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b61e3b7055ac6edee4be071c52f48c26472d2624" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: x86/sev: Fix position dependent variable references in startup code The early startup code executes from a 1:1 mapping of memory, which differs from the mapping that the code was linked and/or relocated to run at. The latter mapping is not active yet at this point, and so symbol references that rely on it will fault. Given that the core kernel is built without -fPIC, symbol references are typically emitted as absolute, and so any such references occuring in the early startup code will therefore crash the kernel. While an attempt was made to work around this for the early SEV/SME startup code, by forcing RIP-relative addressing for certain global SEV/SME variables via inline assembly (see snp_cpuid_get_table() for example), RIP-relative addressing must be pervasively enforced for SEV/SME global variables when accessed prior to page table fixups. __startup_64() already handles this issue for select non-SEV/SME global variables using fixup_pointer(), which adjusts the pointer relative to a `physaddr` argument. To avoid having to pass around this `physaddr` argument across all functions needing to apply pointer fixups, introduce a macro RIP_RELATIVE_REF() which generates a RIP-relative reference to a given global variable. It is used where necessary to force RIP-relative accesses to global variables. For backporting purposes, this patch makes no attempt at cleaning up other occurrences of this pattern, involving either inline asm or fixup_pointer(). Those will be addressed later. [ bp: Call it "rip_rel_ref" everywhere like other code shortens "rIP-relative reference" and make the asm wrapper __always_inline. ]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35802" target="_blank">CVE-2024-35802</a><br><a href="https://git.kernel.org/stable/c/0982fd6bf0b822876f2e93ec782c4c28a3f85535" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1c811d403afd73f04bde82b83b24c754011bd0e8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/66fa3fcb474b2b892fe42d455a6f7ec5aaa98fb9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/954a4a87814465ad61cc97c1cd3de1525baaaf07" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fe272b61506bb1534922ef07aa165fd3c37a6a90" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: x86/efistub: Call mixed mode boot services on the firmware's stack Normally, the EFI stub calls into the EFI boot services using the stack that was live when the stub was entered. According to the UEFI spec, this stack needs to be at least 128k in size - this might seem large but all asynchronous processing and event handling in EFI runs from the same stack and so quite a lot of space may be used in practice. In mixed mode, the situation is a bit different: the bootloader calls the 32-bit EFI stub entry point, which calls the decompressor's 32-bit entry point, where the boot stack is set up, using a fixed allocation of 16k. This stack is still in use when the EFI stub is started in 64-bit mode, and so all calls back into the EFI firmware will be using the decompressor's limited boot stack. Due to the placement of the boot stack right after the boot heap, any stack overruns have gone unnoticed. However, commit 5c4feadb0011983b ("x86/decompressor: Move global symbol references to C code") moved the definition of the boot heap into C code, and now the boot stack is placed right at the base of BSS, where any overruns will corrupt the end of the .data section. While it would be possible to work around this by increasing the size of the boot stack, doing so would affect all x86 systems, and mixed mode systems are a tiny (and shrinking) fraction of the x86 installed base. So instead, record the firmware stack pointer value when entering from the 32-bit firmware, and switch to this stack every time a EFI boot service call is made.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35803" target="_blank">CVE-2024-35803</a><br><a href="https://git.kernel.org/stable/c/2149f8a56e2ed345c7a4d022a79f6b8fc53ae926" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/725351c036452b7db5771a7bed783564bc4b99cc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/930775060ca348b8665f60eef14b204172d14f31" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cefcd4fe2e3aaf792c14c9e56dab89e3d7a65d02" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fba7ee7187581b5bc222003e73e2592b398bb06d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Mark target gfn of emulated atomic instruction as dirty When emulating an atomic access on behalf of the guest, mark the target gfn dirty if the CMPXCHG by KVM is attempted and doesn't fault. This fixes a bug where KVM effectively corrupts guest memory during live migration by writing to guest memory without informing userspace that the page is dirty. Marking the page dirty got unintentionally dropped when KVM's emulated CMPXCHG was converted to do a user access. Before that, KVM explicitly mapped the guest page into kernel memory, and marked the page dirty during the unmap phase. Mark the page dirty even if the CMPXCHG fails, as the old data is written back on failure, i.e. the page is still written. The value written is guaranteed to be the same because the operation is atomic, but KVM's ABI is that all writes are dirty logged regardless of the value written. And more importantly, that's what KVM did before the buggy commit. Huge kudos to the folks on the Cc list (and many others), who did all the actual work of triaging and debugging. base-commit: 6769ea8da8a93ed4630f1ce64df6aafcaabfce64</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35804" target="_blank">CVE-2024-35804</a><br><a href="https://git.kernel.org/stable/c/225d587a073584946c05c9b7651d637bd45c0c71" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/726374dde5d608b15b9756bd52b6fc283fda7a06" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/910c57dfa4d113aae6571c2a8b9ae8c430975902" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9d1b22e573a3789ed1f32033ee709106993ba551" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a9bd6bb6f02bf7132c1ab192ba62bbfa52df7d66" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dm snapshot: fix lockup in dm_exception_table_exit There was reported lockup when we exit a snapshot with many exceptions. Fix this by adding "cond_resched" to the loop that frees the exceptions.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35805" target="_blank">CVE-2024-35805</a><br><a href="https://git.kernel.org/stable/c/116562e804ffc9dc600adab6326dde31d72262c7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3d47eb405781cc5127deca9a14e24b27696087a1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5f4ad4d0b0943296287313db60b3f84df4aad683" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6e7132ed3c07bd8a6ce3db4bb307ef2852b322dc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9759ff196e7d248bcf8386a7451d6ff8537a7d9c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e50f83061ac250f90710757a3e51b70a200835e2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e7d4cff57c3c43fdd72342c78d4138f509c7416e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fa5c055800a7fd49a36bbb52593aca4ea986a366" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: soc: fsl: qbman: Always disable interrupts when taking cgr_lock smp_call_function_single disables IRQs when executing the callback. To prevent deadlocks, we must disable IRQs when taking cgr_lock elsewhere. This is already done by qman_update_cgr and qman_delete_cgr; fix the other lockers.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35806" target="_blank">CVE-2024-35806</a><br><a href="https://git.kernel.org/stable/c/0e6521b0f93ff350434ed4ae61a250907e65d397" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/276af8efb05c8e47acf2738a5609dd72acfc703f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/584c2a9184a33a40fceee838f856de3cffa19be3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/62c3ecd2833cff0eff4a82af4082c44ca8d2518a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a62168653774c36398d65846a98034436ee66d03" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/af25c5180b2b1796342798f6c56fcfd12f5035bd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b56a793f267679945d1fdb9a280013bd2d0ed7f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dd199e5b759ffe349622a4b8fbcafc51fc51b1ec" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e6378314bb920acb39013051fa65d8f9f8030430" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ext4: fix corruption during on-line resize We observed a corruption during on-line resize of a file system that is larger than 16 TiB with 4k block size. With having more then 2^32 blocks resize_inode is turned off by default by mke2fs. The issue can be reproduced on a smaller file system for convenience by explicitly turning off resize_inode. An on-line resize across an 8 GiB boundary (the size of a meta block group in this setup) then leads to a corruption: dev=/dev/&lt;some_dev&gt; # should be &gt;= 16 GiB mkdir -p /corruption /sbin/mke2fs -t ext4 -b 4096 -O ^resize_inode $dev $((2 * 2**21 - 2**15)) mount -t ext4 $dev /corruption dd if=/dev/zero bs=4096 of=/corruption/test count=$((2*2**21 - 4*2**15)) sha1sum /corruption/test # 79d2658b39dcfd77274e435b0934028adafaab11 /corruption/test /sbin/resize2fs $dev $((2*2**21)) # drop page cache to force reload the block from disk echo 1 &gt; /proc/sys/vm/drop_caches sha1sum /corruption/test # 3c2abc63cbf1a94c9e6977e0fbd72cd832c4d5c3 /corruption/test 2^21 = 2^15*2^6 equals 8 GiB whereof 2^15 is the number of blocks per block group and 2^6 are the number of block groups that make a meta block group. The last checksum might be different depending on how the file is laid out across the physical blocks. The actual corruption occurs at physical block 63*2^15 = 2064384 which would be the location of the backup of the meta block group's block descriptor. During the on-line resize the file system will be converted to meta_bg starting at s_first_meta_bg which is 2 in the example - meaning all block groups after 16 GiB. However, in ext4_flex_group_add we might add block groups that are not part of the first meta block group yet. In the reproducer we achieved this by substracting the size of a whole block group from the point where the meta block group would start. This must be considered when updating the backup block group descriptors to follow the non-meta_bg layout. The fix is to add a test whether the group to add is already part of the meta block group or not.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35807" target="_blank">CVE-2024-35807</a><br><a href="https://git.kernel.org/stable/c/239c669edb2bffa1aa2612519b1d438ab35d6be6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/37b6a3ba793bbbae057f5b991970ebcc52cb3db5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/722d2c01b8b108f8283d1b7222209d5b2a5aa7bd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/75cc31c2e7193b69f5d25650bda5bb42ed92f8a1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a6b3bfe176e8a5b05ec4447404e412c2a3fc92cc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b461910af8ba3bed80f48c2bf852686d05c6fc5c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e8e8b197317228b5089ed9e7802dadf3ccaa027a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ee4e9c1976147a850f6085a13fca95bcaa00d84c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fb1088d51bbaa0faec5a55d4f5818a9ab79e24df" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: md/dm-raid: don't call md_reap_sync_thread() directly Currently md_reap_sync_thread() is called from raid_message() directly without holding 'reconfig_mutex', this is definitely unsafe because md_reap_sync_thread() can change many fields that is protected by 'reconfig_mutex'. However, hold 'reconfig_mutex' here is still problematic because this will cause deadlock, for example, commit 130443d60b1b ("md: refactor idle/frozen_sync_thread() to fix deadlock"). Fix this problem by using stop_sync_thread() to unregister sync_thread, like md/raid did.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35808" target="_blank">CVE-2024-35808</a><br><a href="https://git.kernel.org/stable/c/347dcdc15a1706f61aa545ae498ededdf31aeebc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9e59b8d76ff511505eb0dd1478329f09e0f04669" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cd32b27a66db8776d8b8e82ec7d7dde97a8693b0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: PCI/PM: Drain runtime-idle callbacks before driver removal A race condition between the .runtime_idle() callback and the .remove() callback in the rtsx_pcr PCI driver leads to a kernel crash due to an unhandled page fault [1]. The problem is that rtsx_pci_runtime_idle() is not expected to be running after pm_runtime_get_sync() has been called, but the latter doesn't really guarantee that. It only guarantees that the suspend and resume callbacks will not be running when it returns. However, if a .runtime_idle() callback is already running when pm_runtime_get_sync() is called, the latter will notice that the runtime PM status of the device is RPM_ACTIVE and it will return right away without waiting for the former to complete. In fact, it cannot wait for .runtime_idle() to complete because it may be called from that callback (it arguably does not make much sense to do that, but it is not strictly prohibited). Thus in general, whoever is providing a .runtime_idle() callback needs to protect it from running in parallel with whatever code runs after pm_runtime_get_sync(). [Note that .runtime_idle() will not start after pm_runtime_get_sync() has returned, but it may continue running then if it has started earlier.] One way to address that race condition is to call pm_runtime_barrier() after pm_runtime_get_sync() (not before it, because a nonzero value of the runtime PM usage counter is necessary to prevent runtime PM callbacks from being invoked) to wait for the .runtime_idle() callback to complete should it be running at that point. A suitable place for doing that is in pci_device_remove() which calls pm_runtime_get_sync() before removing the driver, so it may as well call pm_runtime_barrier() subsequently, which will prevent the race in question from occurring, not just in the rtsx_pcr driver, but in any PCI drivers providing .runtime_idle() callbacks.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35809" target="_blank">CVE-2024-35809</a><br><a href="https://git.kernel.org/stable/c/47d8aafcfe313511a98f165a54d0adceb34e54b1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6347348c6aba52dda0b33296684cbb627bdc6970" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7cc94dd36e48879e76ae7a8daea4ff322b7d9674" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/900b81caf00c89417172afe0e7e49ac4eb110f4b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a87375bb586515c0af63d5dcdcd58ec4acf20a6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9d5286d4e7f68beab450deddbb6a32edd5ecf4bf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bbe068b24409ef740657215605284fc7cdddd491" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d534198311c345e4b062c4b88bb609efb8bd91d5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d86ad8c3e152349454b82f37007ff6ba45f26989" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix the lifetime of the bo cursor memory The cleanup can be dispatched while the atomic update is still active, which means that the memory acquired in the atomic update needs to not be invalidated by the cleanup. The buffer objects in vmw_plane_state instead of using the builtin map_and_cache were trying to handle the lifetime of the mapped memory themselves, leading to crashes. Use the map_and_cache instead of trying to manage the lifetime of the buffer objects held by the vmw_plane_state. Fixes kernel oops'es in IGT's kms_cursor_legacy forked-bo.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35810" target="_blank">CVE-2024-35810</a><br><a href="https://git.kernel.org/stable/c/104a5b2772bc7c0715ae7355ccf9d294a472765c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/86cb706a40b7e6b2221ee49a298a65ad9b46c02d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a9e8a7159ca09af9b1a300a6c8e8b6ff7501c76" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ed381800ea6d9a4c7f199235a471c0c48100f0ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix use-after-free bug in brcmf_cfg80211_detach This is the candidate patch of CVE-2023-47233 : https://nvd.nist.gov/vuln/detail/CVE-2023-47233 In brcm80211 driver,it starts with the following invoking chain to start init a timeout worker: -&gt;brcmf_usb_probe -&gt;brcmf_usb_probe_cb -&gt;brcmf_attach -&gt;brcmf_bus_started -&gt;brcmf_cfg80211_attach -&gt;wl_init_priv -&gt;brcmf_init_escan -&gt;INIT_WORK(&amp;cfg-&gt;escan_timeout_work, brcmf_cfg80211_escan_timeout_worker); If we disconnect the USB by hotplug, it will call brcmf_usb_disconnect to make cleanup. The invoking chain is : brcmf_usb_disconnect -&gt;brcmf_usb_disconnect_cb -&gt;brcmf_detach -&gt;brcmf_cfg80211_detach -&gt;kfree(cfg); While the timeout woker may still be running. This will cause a use-after-free bug on cfg in brcmf_cfg80211_escan_timeout_worker. Fix it by deleting the timer and canceling the worker in brcmf_cfg80211_detach. [arend.vanspriel@broadcom.com: keep timer delete as is and cancel work just before free]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35811" target="_blank">CVE-2024-35811</a><br><a href="https://git.kernel.org/stable/c/0a7591e14a8da794d0b93b5d1c6254ccb23adacb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0b812f706fd7090be74812101114a0e165b36744" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/0f7352557a35ab7888bc7831411ec8a3cbe20d78" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/190794848e2b9d15de92d502b6ac652806904f5a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/202c503935042272e2f9e1bb549d5f69a8681169" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6678a1e7d896c00030b31491690e8ddc9a90767a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8c36205123dc57349b59b4f1a2301eb278cbc731" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8e3f03f4ef7c36091f46e7349096efb5a2cdb3a1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bacb8c3ab86dcd760c15903fcee58169bc3026aa" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: cdc-wdm: close race between read and workqueue wdm_read() cannot race with itself. However, in service_outstanding_interrupt() it can race with the workqueue, which can be triggered by error handling. Hence we need to make sure that the WDM_RESPONDING flag is not just only set but tested.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35812" target="_blank">CVE-2024-35812</a><br><a href="https://git.kernel.org/stable/c/164be0a824387301312689bb29b2be92ab2cd39d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/19f955ad9437a6859a529af34e2eafd903d5e7c1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2ff436b6399859e06539a2b9c667897d3cc85ad5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/339f83612f3a569b194680768b22bf113c26a29d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/347cca11bb78b9f3c29b45a9c52e70258bd008bf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3afdcc4e1a00facad210f5c5891bb2fbc026067f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5904411219601127ffdbd2d622bb5d67f9d8d16c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7182175f565ffffa2ba1911726c5656bfc7a1bae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8672ad663a22d0e4a325bb7d817b36ec412b967c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/916cd2fcbc1e344bcabf4b2a834cdf5a0417d30c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9723602387217caa71d623ffcce314dc39e84a09" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9b319f4a88094b2e020e6db6e819c808d890098d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a86e54a345139f1a7668c9f83bdc7ac6f91b6f78" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ab92e11b73b48b79f144421430891f3aa6242656" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/da3b75931bb737be74d6b4341e0080f233ed1409" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e4e47e406d74cab601b2ab21ba5e3add811e05ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mmc: core: Avoid negative index with array access Commit 4d0c8d0aef63 ("mmc: core: Use mrq.sbc in close-ended ffu") assigns prev_idata = idatas[i - 1], but doesn't check that the iterator i is greater than zero. Let's fix this by adding a check.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35813" target="_blank">CVE-2024-35813</a><br><a href="https://git.kernel.org/stable/c/064db53f9023a2d5877a2d12de6bc27995f6ca56" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2b539c88940e22494da80a93ee1c5a28bbad10f6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4466677dcabe2d70de6aa3d4bd4a4fafa94a71f2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7d0e8a6147550aa058fa6ade8583ad252aa61304" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/81b8645feca08a54c7c4bf36e7b176f4983b2f28" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ad9cc5e9e53ab94aa0c7ac65d43be7eb208dcb55" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b9a7339ae403035ffe7fc37cb034b36947910f68" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cf55a7acd1ed38afe43bba1c8a0935b51d1dc014" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: swiotlb: Fix double-allocation of slots due to broken alignment handling Commit bbb73a103fbb ("swiotlb: fix a braino in the alignment check fix"), which was a fix for commit 0eee5ae10256 ("swiotlb: fix slot alignment checks"), causes a functional regression with vsock in a virtual machine using bouncing via a restricted DMA SWIOTLB pool. When virtio allocates the virtqueues for the vsock device using dma_alloc_coherent(), the SWIOTLB search can return page-unaligned allocations if 'area-&gt;index' was left unaligned by a previous allocation from the buffer: # Final address in brackets is the SWIOTLB address returned to the caller | virtio-pci 0000:00:07.0: orig_addr 0x0 alloc_size 0x2000, iotlb_align_mask 0x800 stride 0x2: got slot 1645-1649/7168 (0x98326800) | virtio-pci 0000:00:07.0: orig_addr 0x0 alloc_size 0x2000, iotlb_align_mask 0x800 stride 0x2: got slot 1649-1653/7168 (0x98328800) | virtio-pci 0000:00:07.0: orig_addr 0x0 alloc_size 0x2000, iotlb_align_mask 0x800 stride 0x2: got slot 1653-1657/7168 (0x9832a800) This ends badly (typically buffer corruption and/or a hang) because swiotlb_alloc() is expecting a page-aligned allocation and so blindly returns a pointer to the 'struct page' corresponding to the allocation, therefore double-allocating the first half (2KiB slot) of the 4KiB page. Fix the problem by treating the allocation alignment separately to any additional alignment requirements from the device, using the maximum of the two as the stride to search the buffer slots and taking care to ensure a minimum of page-alignment for buffers larger than a page. This also resolves swiotlb allocation failures occuring due to the inclusion of ~PAGE_MASK in 'iotlb_align_mask' for large allocations and resulting in alignment requirements exceeding swiotlb_max_mapping_size().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35814" target="_blank">CVE-2024-35814</a><br><a href="https://git.kernel.org/stable/c/04867a7a33324c9c562ee7949dbcaab7aaad1fb4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3e7acd6e25ba77dde48c3b721c54c89cd6a10534" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/777391743771040e12cc40d3d0d178f70c616491" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c88668aa6c1da240ea3eb4d128b7906e740d3cb8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: fs/aio: Check IOCB_AIO_RW before the struct aio_kiocb conversion The first kiocb_set_cancel_fn() argument may point at a struct kiocb that is not embedded inside struct aio_kiocb. With the current code, depending on the compiler, the req-&gt;ki_ctx read happens either before the IOCB_AIO_RW test or after that test. Move the req-&gt;ki_ctx read such that it is guaranteed that the IOCB_AIO_RW test happens first.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35815" target="_blank">CVE-2024-35815</a><br><a href="https://git.kernel.org/stable/c/10ca82aff58434e122c7c757cf0497c335f993f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/18d5fc3c16cc317bd0e5f5dabe0660df415cadb7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/396dbbc18963648e9d1a4edbb55cfe08fa374d50" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5c43d0041e3a05c6c41c318b759fff16d2384596" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/94eb0293703ced580f05dfbe5a57da5931e9aee2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/961ebd120565cb60cebe21cb634fbc456022db4a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a71cba07783abc76b547568b6452cd1dd9981410" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c01ed748847fe8b810d86efc229b9e6c7fafa01e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: firewire: ohci: prevent leak of left-over IRQ on unbind Commit 5a95f1ded28691e6 ("firewire: ohci: use devres for requested IRQ") also removed the call to free_irq() in pci_remove(), leading to a leftover irq of devm_request_irq() at pci_disable_msi() in pci_remove() when unbinding the driver from the device remove_proc_entry: removing non-empty directory 'irq/136', leaking at least 'firewire_ohci' Call Trace: ? remove_proc_entry+0x19c/0x1c0 ? __warn+0x81/0x130 ? remove_proc_entry+0x19c/0x1c0 ? report_bug+0x171/0x1a0 ? console_unlock+0x78/0x120 ? handle_bug+0x3c/0x80 ? exc_invalid_op+0x17/0x70 ? asm_exc_invalid_op+0x1a/0x20 ? remove_proc_entry+0x19c/0x1c0 unregister_irq_proc+0xf4/0x120 free_desc+0x3d/0xe0 ? kfree+0x29f/0x2f0 irq_free_descs+0x47/0x70 msi_domain_free_locked.part.0+0x19d/0x1d0 msi_domain_free_irqs_all_locked+0x81/0xc0 pci_free_msi_irqs+0x12/0x40 pci_disable_msi+0x4c/0x60 pci_remove+0x9d/0xc0 [firewire_ohci 01b483699bebf9cb07a3d69df0aa2bee71db1b26] pci_device_remove+0x37/0xa0 device_release_driver_internal+0x19f/0x200 unbind_store+0xa1/0xb0 remove irq with devm_free_irq() before pci_disable_msi() also remove it in fail_msi: of pci_probe() as this would lead to an identical leak</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35816" target="_blank">CVE-2024-35816</a><br><a href="https://git.kernel.org/stable/c/318f6d53dd425c400e35f1a9b7af682c2c6a66d6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/43c70cbc2502cf2557105c662eeed6a15d082b88" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/575801663c7dc38f826212b39e3b91a4a8661c33" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: amdgpu_ttm_gart_bind set gtt bound flag Otherwise after the GTT bo is released, the GTT and gart space is freed but amdgpu_ttm_backend_unbind will not clear the gart page table entry and leave valid mapping entry pointing to the stale system page. Then if GPU access the gart address mistakely, it will read undefined value instead page fault, harder to debug and reproduce the real issue.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35817" target="_blank">CVE-2024-35817</a><br><a href="https://git.kernel.org/stable/c/589c414138a1bed98e652c905937d8f790804efe" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5cdce3dda3b3dacde902f63a8ee72c2b7f91912d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5d5f1a7f3b1039925f79c7894f153c2a905201fb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6c6064cbe58b43533e3451ad6a8ba9736c109ac3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6fcd12cb90888ef2d8af8d4c04e913252eee4ef3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e8d27caef2c829a306e1f762fb95f06e8ec676f6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: LoongArch: Define the __io_aw() hook as mmiowb() Commit fb24ea52f78e0d595852e ("drivers: Remove explicit invocations of mmiowb()") remove all mmiowb() in drivers, but it says: "NOTE: mmiowb() has only ever guaranteed ordering in conjunction with spin_unlock(). However, pairing each mmiowb() removal in this patch with the corresponding call to spin_unlock() is not at all trivial, so there is a small chance that this change may regress any drivers incorrectly relying on mmiowb() to order MMIO writes between CPUs using lock-free synchronisation." The mmio in radeon_ring_commit() is protected by a mutex rather than a spinlock, but in the mutex fastpath it behaves similar to spinlock. We can add mmiowb() calls in the radeon driver but the maintainer says he doesn't like such a workaround, and radeon is not the only example of mutex protected mmio. So we should extend the mmiowb tracking system from spinlock to mutex, and maybe other locking primitives. This is not easy and error prone, so we solve it in the architectural code, by simply defining the __io_aw() hook as mmiowb(). And we no longer need to override queued_spin_unlock() so use the generic definition. Without this, we get such an error when run 'glxgears' on weak ordering architectures such as LoongArch: radeon 0000:04:00.0: ring 0 stalled for more than 10324msec radeon 0000:04:00.0: ring 3 stalled for more than 10240msec radeon 0000:04:00.0: GPU lockup (current fence id 0x000000000001f412 last fence id 0x000000000001f414 on ring 3) radeon 0000:04:00.0: GPU lockup (current fence id 0x000000000000f940 last fence id 0x000000000000f941 on ring 0) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35) radeon 0000:04:00.0: scheduling IB failed (-35). [drm:radeon_gem_va_ioctl [radeon]] *ERROR* Couldn't update BO_VA (-35)</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35818" target="_blank">CVE-2024-35818</a><br><a href="https://git.kernel.org/stable/c/0b61a7dc6712b78799b3949997e8a5e94db5c4b0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/97cd43ba824aec764f5ea2790d0c0a318f885167" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9adec248bba33b1503252caf8e59d81febfc5ceb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9c68ece8b2a5c5ff9b2fcaea923dd73efeb174cd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d7d7c6cdea875be3b241d7d39873bb431db7154d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: soc: fsl: qbman: Use raw spinlock for cgr_lock smp_call_function always runs its callback in hard IRQ context, even on PREEMPT_RT, where spinlocks can sleep. So we need to use a raw spinlock for cgr_lock to ensure we aren't waiting on a sleeping task. Although this bug has existed for a while, it was not apparent until commit ef2a8d5478b9 ("net: dpaa: Adjust queue depth on rate change") which invokes smp_call_function_single via qman_update_cgr_safe every time a link goes up or down.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35819" target="_blank">CVE-2024-35819</a><br><a href="https://git.kernel.org/stable/c/2b3fede8225133671ce837c0d284804aa3bc7a02" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/32edca2f03a6cc42c650ddc3ad83d086e3f365d1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/54d26adf64c04f186098b39dba86b86037084baa" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9a3ca8292ce9fdcce122706c28c3f07bc857fe5e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cd53a8ae5aacb4ecd25088486dea1cd02e74b506" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d6b5aac451c9cc12e43ab7308e0e2ddc52c62c14" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f39d36b7540cf0088ed7ce2de2794f2aa237f6df" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fbec4e7fed89b579f2483041fabf9650fb0dd6bc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ff50716b7d5b7985979a5b21163cd79fb3d21d59" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_uring: fix io_queue_proc modifying req-&gt;flags With multiple poll entries __io_queue_proc() might be running in parallel with poll handlers and possibly task_work, we should not be carelessly modifying req-&gt;flags there. io_poll_double_prepare() handles a similar case with locking but it's much easier to move it into __io_arm_poll_handler().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35820" target="_blank">CVE-2024-35820</a><br><a href="https://git.kernel.org/stable/c/0ecb8919469e6d5c74eea24086b34ce1bda5aef7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1a8ec63b2b6c91caec87d4e132b1f71b5df342be" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/51a490a7f63cae0754120e7c04f4f47920bd48db" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ubifs: Set page uptodate in the correct place Page cache reads are lockless, so setting the freshly allocated page uptodate before we've overwritten it with the data it's supposed to have in it will allow a simultaneous reader to see old data. Move the call to SetPageUptodate into ubifs_write_end(), which is after we copied the new data into the page.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35821" target="_blank">CVE-2024-35821</a><br><a href="https://git.kernel.org/stable/c/142d87c958d9454c3cffa625fab56f3016e8f9f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/17772bbe9cfa972ea1ff827319f6e1340de76566" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4aa554832b9dc9e66249df75b8f447d87853e12e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4b7c4fc60d6a46350fbe54f5dc937aeaa02e675e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/723012cab779eee8228376754e22c6594229bf8f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/778c6ad40256f1c03244fc06d7cdf71f6b5e7310" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8f599ab6fabbca4c741107eade70722a98adfd9f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f19b1023a3758f40791ec166038d6411c8894ae3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fc99f4e2d2f1ce766c14e98463c2839194ae964f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: udc: remove warning when queue disabled ep It is possible trigger below warning message from mass storage function, WARNING: CPU: 6 PID: 3839 at drivers/usb/gadget/udc/core.c:294 usb_ep_queue+0x7c/0x104 pc : usb_ep_queue+0x7c/0x104 lr : fsg_main_thread+0x494/0x1b3c Root cause is mass storage function try to queue request from main thread, but other thread may already disable ep when function disable. As there is no function failure in the driver, in order to avoid effort to fix warning, change WARN_ON_ONCE() in usb_ep_queue() to pr_debug().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35822" target="_blank">CVE-2024-35822</a><br><a href="https://git.kernel.org/stable/c/2a587a035214fa1b5ef598aea0b81848c5b72e5e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2b002c308e184feeaeb72987bca3f1b11e5f70b8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/30511676eb54d480d014352bf784f02577a10252" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/36177c2595df12225b95ce74eb1ac77b43d5a58c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3e944ddc17c042945d983e006df7860687a8849a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/68d951880d0c52c7f13dcefb5501b69b8605ce8c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/99731076722eb7ed26b0c87c879da7bb71d24290" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/df5cbb908f1687e8ab97e222a16b7890d5501acf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f74c5e0b54b02706d9a862ac6cddade30ac86bcf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: vt: fix unicode buffer corruption when deleting characters This is the same issue that was fixed for the VGA text buffer in commit 39cdb68c64d8 ("vt: fix memory overlapping when deleting chars in the buffer"). The cure is also the same i.e. replace memcpy() with memmove() due to the overlaping buffers.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35823" target="_blank">CVE-2024-35823</a><br><a href="https://git.kernel.org/stable/c/0190d19d7651c08abc187dac3819c61b726e7e3f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1581dafaf0d34bc9c428a794a22110d7046d186d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1ce408f75ccf1e25b3fddef75cca878b55f2ac90" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2933b1e4757a0a5c689cf48d80b1a2a85f237ff1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7529cbd8b5f6697b369803fe1533612c039cabda" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/994a1e583c0c206c8ca7d03334a65b79f4d8bc51" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fc7dfe3d123f00e720be80b920da287810a1f37d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ff7342090c1e8c5a37015c89822a68b275b46f8a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: misc: lis3lv02d_i2c: Fix regulators getting en-/dis-abled twice on suspend/resume When not configured for wakeup lis3lv02d_i2c_suspend() will call lis3lv02d_poweroff() even if the device has already been turned off by the runtime-suspend handler and if configured for wakeup and the device is runtime-suspended at this point then it is not turned back on to serve as a wakeup source. Before commit b1b9f7a49440 ("misc: lis3lv02d_i2c: Add missing setting of the reg_ctrl callback"), lis3lv02d_poweroff() failed to disable the regulators which as a side effect made calling poweroff() twice ok. Now that poweroff() correctly disables the regulators, doing this twice triggers a WARN() in the regulator core: unbalanced disables for regulator-dummy WARNING: CPU: 1 PID: 92 at drivers/regulator/core.c:2999 _regulator_disable ... Fix lis3lv02d_i2c_suspend() to not call poweroff() a second time if already runtime-suspended and add a poweron() call when necessary to make wakeup work. lis3lv02d_i2c_resume() has similar issues, with an added weirness that it always powers on the device if it is runtime suspended, after which the first runtime-resume will call poweron() again, causing the enabled count for the regulator to increase by 1 every suspend/resume. These unbalanced regulator_enable() calls cause the regulator to never be turned off and trigger the following WARN() on driver unbind: WARNING: CPU: 1 PID: 1724 at drivers/regulator/core.c:2396 _regulator_put Fix this by making lis3lv02d_i2c_resume() mirror the new suspend().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35824" target="_blank">CVE-2024-35824</a><br><a href="https://git.kernel.org/stable/c/4154e767354140db7804207117e7238fb337b0e7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/997ca415384612c8df76d99d9a768e0b3f42b325" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ac3e0384073b2408d6cb0d972fee9fcc3776053d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f6df761182fc953907b18aba5049fc2a044ecb45" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: usb: gadget: ncm: Fix handling of zero block length packets While connecting to a Linux host with CDC_NCM_NTB_DEF_SIZE_TX set to 65536, it has been observed that we receive short packets, which come at interval of 5-10 seconds sometimes and have block length zero but still contain 1-2 valid datagrams present. According to the NCM spec: "If wBlockLength = 0x0000, the block is terminated by a short packet. In this case, the USB transfer must still be shorter than dwNtbInMaxSize or dwNtbOutMaxSize. If exactly dwNtbInMaxSize or dwNtbOutMaxSize bytes are sent, and the size is a multiple of wMaxPacketSize for the given pipe, then no ZLP shall be sent. wBlockLength= 0x0000 must be used with extreme care, because of the possibility that the host and device may get out of sync, and because of test issues. wBlockLength = 0x0000 allows the sender to reduce latency by starting to send a very large NTB, and then shortening it when the sender discovers that there's not sufficient data to justify sending a large NTB" However, there is a potential issue with the current implementation, as it checks for the occurrence of multiple NTBs in a single giveback by verifying if the leftover bytes to be processed is zero or not. If the block length reads zero, we would process the same NTB infintely because the leftover bytes is never zero and it leads to a crash. Fix this by bailing out if block length reads zero.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35825" target="_blank">CVE-2024-35825</a><br><a href="https://git.kernel.org/stable/c/6b2c73111a252263807b7598682663dc33aa4b4c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7664ee8bd80309b90d53488b619764f0a057f2b7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/92b051b87658df7649ffcdef522593f21a2b296b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a0f77b5d6067285b8eca0ee3bd1e448a6258026f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a766761d206e7c36d7526e0ae749949d17ca582c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e2dbfea520e60d58e0c498ba41bde10452257779" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ef846cdbd100f7f9dc045e8bcd7fe4b3a3713c03" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f90ce1e04cbcc76639d6cba0fdbd820cd80b3c70" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: block: Fix page refcounts for unaligned buffers in __bio_release_pages() Fix an incorrect number of pages being released for buffers that do not start at the beginning of a page.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35826" target="_blank">CVE-2024-35826</a><br><a href="https://git.kernel.org/stable/c/242006996d15f5ca62e22f8c7de077d9c4a8f367" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/38b43539d64b2fa020b3b9a752a986769f87f7a6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7d3765550374f71248c55e6206ea1d6fd4537e65" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c9d3d2fbde9b8197bce88abcbe8ee8e713ffe7c2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ecbd9ced84dd655a8f4cd49d2aad0e80dbf6bf35" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_uring/net: fix overflow check in io_recvmsg_mshot_prep() The "controllen" variable is type size_t (unsigned long). Casting it to int could lead to an integer underflow. The check_add_overflow() function considers the type of the destination which is type int. If we add two positive values and the result cannot fit in an integer then that's counted as an overflow. However, if we cast "controllen" to an int and it turns negative, then negative values *can* fit into an int type so there is no overflow. Good: 100 + (unsigned long)-4 = 96 &lt;-- overflow Bad: 100 + (int)-4 = 96 &lt;-- no overflow I deleted the cast of the sizeof() as well. That's not a bug but the cast is unnecessary.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35827" target="_blank">CVE-2024-35827</a><br><a href="https://git.kernel.org/stable/c/0c8c74bb59e7d77554016efc34c2d10376985e5e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/59a534690ecc3af72c6ab121aeac1237a4adae66" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/868ec868616438df487b9e2baa5a99f8662cc47c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8ede3db5061bb1fe28e2c9683329aafa89d2b1b4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b6563ad0d599110bd5cf8f56c47d279c3ed796fe" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix some memleaks in lbs_allocate_cmd_buffer() In the for statement of lbs_allocate_cmd_buffer(), if the allocation of cmdarray[i].cmdbuf fails, both cmdarray and cmdarray[i].cmdbuf needs to be freed. Otherwise, there will be memleaks in lbs_allocate_cmd_buffer().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35828" target="_blank">CVE-2024-35828</a><br><a href="https://git.kernel.org/stable/c/4d99d267da3415db2124029cb5a6d2d955ca43f9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5f0e4aede01cb01fa633171f0533affd25328c3a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8e243ac649c10922a6b4855170eaefe4c5b3faab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/96481624fb5a6319079fb5059e46dbce43a90186" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bea9573c795acec5614d4ac2dcc7b3b684cea5bf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d219724d4b0ddb8ec7dfeaed5989f23edabaf591" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/da10f6b7918abd5b4bc5c9cb66f0fc6763ac48f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e888c4461e109f7b93c3522afcbbaa5a8fdf29d2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f0dd27314c7afe34794c2aa19dd6f2d30eb23bc7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: drm/lima: fix a memleak in lima_heap_alloc When lima_vm_map_bo fails, the resources need to be deallocated, or there will be memleaks.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35829" target="_blank">CVE-2024-35829</a><br><a href="https://git.kernel.org/stable/c/04ae3eb470e52a3c41babe85ff8cee195e4dcbea" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4ab14eccf5578af1dd5668a5f2d771df27683cab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/746606d37d662c70ae1379fc658ee9c65f06880f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8e25c0ee5665e8a768b8e21445db1f86e9156eb7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ec6bb037e4a35fcbb5cd7bc78242d034ed893fcd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f2e80ac9344aebbff576453d5c0290b332e187ed" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f6d51a91b41704704e395de6839c667b0f810bbf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: media: tc358743: register v4l2 async device only after successful setup Ensure the device has been setup correctly before registering the v4l2 async device, thus allowing userspace to access.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35830" target="_blank">CVE-2024-35830</a><br><a href="https://git.kernel.org/stable/c/17c2650de14842c25c569cbb2126c421489a3a24" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4f1490a5d7a0472ee5d9f36547bc4ba46be755c7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/610f20e5cf35ca9c0992693cae0dd8643ce932e7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/87399f1ff92203d65f1febf5919429f4bb613a02" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8ba8db9786b55047df5ad3db3e01dd886687a77d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b8505a1aee8f1edc9d16d72ae09c93de086e2a1a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c915c46a25c3efb084c4f5e69a053d7f7a635496" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/daf21394f9898fb9f0698c3e50de08132d2164e6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/edbb3226c985469a2f8eb69885055c9f5550f468" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: io_uring: Fix release of pinned pages when __io_uaddr_map fails Looking at the error path of __io_uaddr_map, if we fail after pinning the pages for any reasons, ret will be set to -EINVAL and the error handler won't properly release the pinned pages. I didn't manage to trigger it without forcing a failure, but it can happen in real life when memory is heavily fragmented.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35831" target="_blank">CVE-2024-35831</a><br><a href="https://git.kernel.org/stable/c/0b6f39c175ba5f0ef72bdb3b9d2a06ad78621d62" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4d376d7ad62b6a8e8dfff56b559d9d275e5b9b3a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/67d1189d1095d471ed7fa426c7e384a7140a5dd7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/712e2c8415f55a4a4ddaa98a430b87f624109f69" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: bcachefs: kvfree bch_fs::snapshots in bch2_fs_snapshots_exit bch_fs::snapshots is allocated by kvzalloc in __snapshot_t_mut. It should be freed by kvfree not kfree. Or umount will triger: [ 406.829178 ] BUG: unable to handle page fault for address: ffffe7b487148008 [ 406.830676 ] #PF: supervisor read access in kernel mode [ 406.831643 ] #PF: error_code(0x0000) - not-present page [ 406.832487 ] PGD 0 P4D 0 [ 406.832898 ] Oops: 0000 [#1] PREEMPT SMP PTI [ 406.833512 ] CPU: 2 PID: 1754 Comm: umount Kdump: loaded Tainted: G OE 6.7.0-rc7-custom+ #90 [ 406.834746 ] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014 [ 406.835796 ] RIP: 0010:kfree+0x62/0x140 [ 406.836197 ] Code: 80 48 01 d8 0f 82 e9 00 00 00 48 c7 c2 00 00 00 80 48 2b 15 78 9f 1f 01 48 01 d0 48 c1 e8 0c 48 c1 e0 06 48 03 05 56 9f 1f 01 &lt;48&gt; 8b 50 08 48 89 c7 f6 c2 01 0f 85 b0 00 00 00 66 90 48 8b 07 f6 [ 406.837810 ] RSP: 0018:ffffb9d641607e48 EFLAGS: 00010286 [ 406.838213 ] RAX: ffffe7b487148000 RBX: ffffb9d645200000 RCX: ffffb9d641607dc4 [ 406.838738 ] RDX: 000065bb00000000 RSI: ffffffffc0d88b84 RDI: ffffb9d645200000 [ 406.839217 ] RBP: ffff9a4625d00068 R08: 0000000000000001 R09: 0000000000000001 [ 406.839650 ] R10: 0000000000000001 R11: 000000000000001f R12: ffff9a4625d4da80 [ 406.840055 ] R13: ffff9a4625d00000 R14: ffffffffc0e2eb20 R15: 0000000000000000 [ 406.840451 ] FS: 00007f0a264ffb80(0000) GS:ffff9a4e2d500000(0000) knlGS:0000000000000000 [ 406.840851 ] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 406.841125 ] CR2: ffffe7b487148008 CR3: 000000018c4d2000 CR4: 00000000000006f0 [ 406.841464 ] Call Trace: [ 406.841583 ] &lt;TASK&gt; [ 406.841682 ] ? __die+0x1f/0x70 [ 406.841828 ] ? page_fault_oops+0x159/0x470 [ 406.842014 ] ? fixup_exception+0x22/0x310 [ 406.842198 ] ? exc_page_fault+0x1ed/0x200 [ 406.842382 ] ? asm_exc_page_fault+0x22/0x30 [ 406.842574 ] ? bch2_fs_release+0x54/0x280 [bcachefs] [ 406.842842 ] ? kfree+0x62/0x140 [ 406.842988 ] ? kfree+0x104/0x140 [ 406.843138 ] bch2_fs_release+0x54/0x280 [bcachefs] [ 406.843390 ] kobject_put+0xb7/0x170 [ 406.843552 ] deactivate_locked_super+0x2f/0xa0 [ 406.843756 ] cleanup_mnt+0xba/0x150 [ 406.843917 ] task_work_run+0x59/0xa0 [ 406.844083 ] exit_to_user_mode_prepare+0x197/0x1a0 [ 406.844302 ] syscall_exit_to_user_mode+0x16/0x40 [ 406.844510 ] do_syscall_64+0x4e/0xf0 [ 406.844675 ] entry_SYSCALL_64_after_hwframe+0x6e/0x76 [ 406.844907 ] RIP: 0033:0x7f0a2664e4fb</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35832" target="_blank">CVE-2024-35832</a><br><a href="https://git.kernel.org/stable/c/369acf97d6fd5da620d053d0f1878ffe32eff555" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/56590678791119b9a655202e49898edfb9307271" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dmaengine: fsl-qdma: Fix a memory leak related to the queue command DMA This dma_alloc_coherent() is undone neither in the remove function, nor in the error handling path of fsl_qdma_probe(). Switch to the managed version to fix both issues.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35833" target="_blank">CVE-2024-35833</a><br><a href="https://git.kernel.org/stable/c/15eb996d7d13cb72a16389231945ada8f0fef2c3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/198270de9d8eb3b5d5f030825ea303ef95285d24" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/1c75fe450b5200c78f4a102a0eb8e15d8f1ccda8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/25ab4d72eb7cbfa0f3d97a139a9b2bfcaa72dd59" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3aa58cb51318e329d203857f7a191678e60bb714" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5cd8a51517ce15edbdcea4fc74c4c127ddaa1bd6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ae6769ba51417c1c86fb645812d5bff455eee802" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: xsk: recycle buffer in case Rx queue was full Add missing xsk_buff_free() call when __xsk_rcv_zc() failed to produce descriptor to XSK Rx queue.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35834" target="_blank">CVE-2024-35834</a><br><a href="https://git.kernel.org/stable/c/269009893146c495f41e9572dd9319e787c2eba9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7b4d93d31aade99210d41cd9d4cbd2957c98bc8c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cce713664548284daf977739e7ff1cd59e84189c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix a double-free in arfs_create_groups When `in` allocated by kvzalloc fails, arfs_create_groups will free ft-&gt;g and return an error. However, arfs_create_table, the only caller of arfs_create_groups, will hold this error and call to mlx5e_destroy_flow_table, in which the ft-&gt;g will be freed again.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35835" target="_blank">CVE-2024-35835</a><br><a href="https://git.kernel.org/stable/c/2501afe6c4c9829d03abe9a368b83d9ea1b611b7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3c6d5189246f590e4e1f167991558bdb72a4738b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/42876db001bbea7558e8676d1019f08f9390addb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/66cc521a739ccd5da057a1cb3d6346c6d0e7619b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b21db3f1ab7967a81d6bbd328d28fe5a4c07a8a7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c57ca114eb00e03274dd38108d07a3750fa3c056" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cf116d9c3c2aebd653c2dfab5b10c278e9ec3ee5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e3d3ed8c152971dbe64c92c9ecb98fdb52abb629" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: dpll: fix pin dump crash for rebound module When a kernel module is unbound but the pin resources were not entirely freed (other kernel module instance of the same PCI device have had kept the reference to that pin), and kernel module is again bound, the pin properties would not be updated (the properties are only assigned when memory for the pin is allocated), prop pointer still points to the kernel module memory of the kernel module which was deallocated on the unbind. If the pin dump is invoked in this state, the result is a kernel crash. Prevent the crash by storing persistent pin properties in dpll subsystem, copy the content from the kernel module when pin is allocated, instead of using memory of the kernel module.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35836" target="_blank">CVE-2024-35836</a><br><a href="https://git.kernel.org/stable/c/5050a5b9d8b4d3c6f7e376e07670e437db7ccf9c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/830ead5fb0c5855ce4d70ba2ed4a673b5f1e7d9b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: clear BM pool before initialization Register value persist after booting the kernel using kexec which results in kernel panic. Thus clear the BM pool registers before initialisation to fix the issue.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35837" target="_blank">CVE-2024-35837</a><br><a href="https://git.kernel.org/stable/c/83f99138bf3b396f761600ab488054396fb5768f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/938729484cfa535e9987ed0f86f29a2ae3a8188b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9f538b415db862e74b8c5d3abbccfc1b2b6caa38" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/af47faa6d3328406038b731794e7cf508c71affa" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cec65f09c47d8c2d67f2bcad6cf05c490628d1ec" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dc77f6ab5c3759df60ff87ed24f4d45df0f3b4c4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix potential sta-link leak When a station is allocated, links are added but not set to valid yet (e.g. during connection to an AP MLD), we might remove the station without ever marking links valid, and leak them. Fix that.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35838" target="_blank">CVE-2024-35838</a><br><a href="https://git.kernel.org/stable/c/49aaeb8c539b1633b3bd7c2df131ec578aa1eae1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/587c5892976108674bbe61a8ff659de279318034" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b01a74b3ca6fd51b62c67733ba7c3280fa6c5d26" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e04bf59bdba0fa45d52160be676114e16be855a9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: replace physindev with physinif in nf_bridge_info An skb can be added to a neigh-&gt;arp_queue while waiting for an arp reply. Where original skb's skb-&gt;dev can be different to neigh's neigh-&gt;dev. For instance in case of bridging dnated skb from one veth to another, the skb would be added to a neigh-&gt;arp_queue of the bridge. As skb-&gt;dev can be reset back to nf_bridge-&gt;physindev and used, and as there is no explicit mechanism that prevents this physindev from been freed under us (for instance neigh_flush_dev doesn't cleanup skbs from different device's neigh queue) we can crash on e.g. this stack: arp_process neigh_update skb = __skb_dequeue(&amp;neigh-&gt;arp_queue) neigh_resolve_output(..., skb) ... br_nf_dev_xmit br_nf_pre_routing_finish_bridge_slow skb-&gt;dev = nf_bridge-&gt;physindev br_handle_frame_finish Let's use plain ifindex instead of net_device link. To peek into the original net_device we will use dev_get_by_index_rcu(). Thus either we get device and are safe to use it or we don't get it and drop skb.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35839" target="_blank">CVE-2024-35839</a><br><a href="https://git.kernel.org/stable/c/544add1f1cfb78c3dfa3e6edcf4668f6be5e730c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7ae19ee81ca56b13c50a78de6c47d5b8fdc9d97b" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9325e3188a9cf3f69fc6f32af59844bbc5b90547" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9874808878d9eed407e3977fd11fee49de1e1d86" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mptcp: use OPTION_MPTCP_MPJ_SYNACK in subflow_finish_connect() subflow_finish_connect() uses four fields (backup, join_id, thmac, none) that may contain garbage unless OPTION_MPTCP_MPJ_SYNACK has been set in mptcp_parse_option()</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35840" target="_blank">CVE-2024-35840</a><br><a href="https://git.kernel.org/stable/c/413b913507326972135d2977975dbff8b7f2c453" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/51e4cb032d49ce094605f27e45eabebc0408893c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/76e8de7273a22a00d27e9b8b7d4d043d6433416a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ad3e8f5c3d5c53841046ef7a947c04ad45a20721" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/be1d9d9d38da922bd4beeec5b6dd821ff5a1dfeb" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: tls, fix WARNIING in __sk_msg_free A splice with MSG_SPLICE_PAGES will cause tls code to use the tls_sw_sendmsg_splice path in the TLS sendmsg code to move the user provided pages from the msg into the msg_pl. This will loop over the msg until msg_pl is full, checked by sk_msg_full(msg_pl). The user can also set the MORE flag to hint stack to delay sending until receiving more pages and ideally a full buffer. If the user adds more pages to the msg than can fit in the msg_pl scatterlist (MAX_MSG_FRAGS) we should ignore the MORE flag and send the buffer anyways. What actually happens though is we abort the msg to msg_pl scatterlist setup and then because we forget to set 'full record' indicating we can no longer consume data without a send we fallthrough to the 'continue' path which will check if msg_data_left(msg) has more bytes to send and then attempts to fit them in the already full msg_pl. Then next iteration of sender doing send will encounter a full msg_pl and throw the warning in the syzbot report. To fix simply check if we have a full_record in splice code path and if not send the msg regardless of MORE flag.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35841" target="_blank">CVE-2024-35841</a><br><a href="https://git.kernel.org/stable/c/02e368eb1444a4af649b73cbe2edd51780511d86" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/294e7ea85f34748f04e5f3f9dba6f6b911d31aa8" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dc9dfc8dc629e42f2234e3327b75324ffc752bc9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: ASoC: mediatek: sof-common: Add NULL check for normal_link string It's not granted that all entries of struct sof_conn_stream declare a `normal_link` (a non-SOF, direct link) string, and this is the case for SoCs that support only SOF paths (hence do not support both direct and SOF usecases). For example, in the case of MT8188 there is no normal_link string in any of the sof_conn_stream entries and there will be more drivers doing that in the future. To avoid possible NULL pointer KPs, add a NULL check for `normal_link`.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35842" target="_blank">CVE-2024-35842</a><br><a href="https://git.kernel.org/stable/c/b1d3db6740d0997ffc6e5a0d96ef7cbd62b35fdd" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cad471227a37c0c7c080bfc9ed01b53750e82afe" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/cde6ca5872bf67744dffa875a7cb521ab007b7ef" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e3b3ec967a7d93b9010a5af9a2394c8b5c8f31ed" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Use device rbtree in iopf reporting path The existing I/O page fault handler currently locates the PCI device by calling pci_get_domain_bus_and_slot(). This function searches the list of all PCI devices until the desired device is found. To improve lookup efficiency, replace it with device_rbtree_find() to search the device within the probed device rbtree. The I/O page fault is initiated by the device, which does not have any synchronization mechanism with the software to ensure that the device stays in the probed device tree. Theoretically, a device could be released by the IOMMU subsystem after device_rbtree_find() and before iopf_get_dev_fault_param(), which would cause a use-after-free problem. Add a mutex to synchronize the I/O page fault reporting path and the IOMMU release device path. This lock doesn't introduce any performance overhead, as the conflict between I/O page fault reporting and device releasing is very rare.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35843" target="_blank">CVE-2024-35843</a><br><a href="https://git.kernel.org/stable/c/3d39238991e745c5df85785604f037f35d9d1b15" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/def054b01a867822254e1dda13d587f5c7a99e2a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix reserve_cblocks counting error when out of space When a file only needs one direct_node, performing the following operations will cause the file to be unrepairable: unisoc # ./f2fs_io compress test.apk unisoc #df -h | grep dm-48 /dev/block/dm-48 112G 112G 1.2M 100% /data unisoc # ./f2fs_io release_cblocks test.apk 924 unisoc # df -h | grep dm-48 /dev/block/dm-48 112G 112G 4.8M 100% /data unisoc # dd if=/dev/random of=file4 bs=1M count=3 3145728 bytes (3.0 M) copied, 0.025 s, 120 M/s unisoc # df -h | grep dm-48 /dev/block/dm-48 112G 112G 1.8M 100% /data unisoc # ./f2fs_io reserve_cblocks test.apk F2FS_IOC_RESERVE_COMPRESS_BLOCKS failed: No space left on device adb reboot unisoc # df -h | grep dm-48 /dev/block/dm-48 112G 112G 11M 100% /data unisoc # ./f2fs_io reserve_cblocks test.apk 0 This is because the file has only one direct_node. After returning to -ENOSPC, reserved_blocks += ret will not be executed. As a result, the reserved_blocks at this time is still 0, which is not the real number of reserved blocks. Therefore, fsck cannot be set to repair the file. After this patch, the fsck flag will be set to fix this problem. unisoc # df -h | grep dm-48 /dev/block/dm-48 112G 112G 1.8M 100% /data unisoc # ./f2fs_io reserve_cblocks test.apk F2FS_IOC_RESERVE_COMPRESS_BLOCKS failed: No space left on device adb reboot then fsck will be executed unisoc # df -h | grep dm-48 /dev/block/dm-48 112G 112G 11M 100% /data unisoc # ./f2fs_io reserve_cblocks test.apk 924</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35844" target="_blank">CVE-2024-35844</a><br><a href="https://git.kernel.org/stable/c/2f6d721e14b69d6e1251f69fa238b48e8374e25f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/569c198c9e2093fd29cc071856a4e548fda506bc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/889846dfc8ee2cf31148a44bfd2faeb2faadc685" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f0bf89e84c3afb79d7a3a9e4bc853ad6a3245c0a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fa3ac8b1a227d9b470b87972494293348b5839ee" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fc0aed88afbf6f606205129a7466eebdf528e3f3" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dbg-tlv: ensure NUL termination The iwl_fw_ini_debug_info_tlv is used as a string, so we must ensure the string is terminated correctly before using it.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35845" target="_blank">CVE-2024-35845</a><br><a href="https://git.kernel.org/stable/c/71d4186d470e9cda7cd1a0921b4afda737c6f641" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/783d413f332a3ebec916664b366c28f58147f82c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/96aa40761673da045a7774f874487cdb50c6a2f7" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c855a1a5b7e3de57e6b1b29563113d5e3bfdb89a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/ea1d166fae14e05d49ffb0ea9fcd4658f8d3dcea" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fabe2db7de32a881e437ee69db32e0de785a6209" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fec14d1cdd92f340b9ba2bd220abf96f9609f2a9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mm: zswap: fix shrinker NULL crash with cgroup_disable=memory Christian reports a NULL deref in zswap that he bisected down to the zswap shrinker. The issue also cropped up in the bug trackers of libguestfs [1] and the Red Hat bugzilla [2]. The problem is that when memcg is disabled with the boot time flag, the zswap shrinker might get called with sc-&gt;memcg == NULL. This is okay in many places, like the lruvec operations. But it crashes in memcg_page_state() - which is only used due to the non-node accounting of cgroup's the zswap memory to begin with. Nhat spotted that the memcg can be NULL in the memcg-disabled case, and I was then able to reproduce the crash locally as well. [1] https://github.com/libguestfs/libguestfs/issues/139 [2] https://bugzilla.redhat.com/show_bug.cgi?id=2275252</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35846" target="_blank">CVE-2024-35846</a><br><a href="https://git.kernel.org/stable/c/682886ec69d22363819a83ddddd5d66cb5c791e1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b0fdabc908a7f81d12382c87ca9e46a9c2e14042" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Prevent double free on error The error handling path in its_vpe_irq_domain_alloc() causes a double free when its_vpe_init() fails after successfully allocating at least one interrupt. This happens because its_vpe_irq_domain_free() frees the interrupts along with the area bitmap and the vprop_page and its_vpe_irq_domain_alloc() subsequently frees the area bitmap and the vprop_page again. Fix this by unconditionally invoking its_vpe_irq_domain_free() which handles all cases correctly and by removing the bitmap/vprop_page freeing from its_vpe_irq_domain_alloc(). [ tglx: Massaged change log ]</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35847" target="_blank">CVE-2024-35847</a><br><a href="https://git.kernel.org/stable/c/03170e657f62c26834172742492a8cb8077ef792" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5b012f77abde89bf0be8a0547636184fea618137" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5dbdbe1133911ca7d8466bb86885adec32ad9438" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/aa44d21574751a7d6bca892eb8e0e9ac68372e52" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b72d2b1448b682844f995e660b77f2a1fabc1662" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c26591afd33adce296c022e3480dea4282b7ef91" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/dd681710ab77c8beafe2e263064cb1bd0e2d6ca9" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f5417ff561b8ac9a7e53c747b8627a7ab58378ae" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: eeprom: at24: fix memory corruption race condition If the eeprom is not accessible, an nvmem device will be registered, the read will fail, and the device will be torn down. If another driver accesses the nvmem device after the teardown, it will reference invalid memory. Move the failure point before registering the nvmem device.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35848" target="_blank">CVE-2024-35848</a><br><a href="https://git.kernel.org/stable/c/26d32bec4c6d255a03762f33c637bfa3718be15a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2af84c46b9b8f2d6c0f88d09ee5c849ae1734676" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6d8b56ec0c8f30d5657382f47344a32569f7a9bc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c43e5028f5a35331eb25017f5ff6cc21735005c6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c850f71fca09ea41800ed55905980063d17e01da" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/f42c97027fb75776e2e9358d16bf4a99aeb04cf2" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: btrfs: fix information leak in btrfs_ioctl_logical_to_ino() Syzbot reported the following information leak for in btrfs_ioctl_logical_to_ino(): BUG: KMSAN: kernel-infoleak in instrument_copy_to_user include/linux/instrumented.h:114 [inline] BUG: KMSAN: kernel-infoleak in _copy_to_user+0xbc/0x110 lib/usercopy.c:40 instrument_copy_to_user include/linux/instrumented.h:114 [inline] _copy_to_user+0xbc/0x110 lib/usercopy.c:40 copy_to_user include/linux/uaccess.h:191 [inline] btrfs_ioctl_logical_to_ino+0x440/0x750 fs/btrfs/ioctl.c:3499 btrfs_ioctl+0x714/0x1260 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:904 [inline] __se_sys_ioctl+0x261/0x450 fs/ioctl.c:890 __x64_sys_ioctl+0x96/0xe0 fs/ioctl.c:890 x64_sys_call+0x1883/0x3b50 arch/x86/include/generated/asm/syscalls_64.h:17 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f Uninit was created at: __kmalloc_large_node+0x231/0x370 mm/slub.c:3921 __do_kmalloc_node mm/slub.c:3954 [inline] __kmalloc_node+0xb07/0x1060 mm/slub.c:3973 kmalloc_node include/linux/slab.h:648 [inline] kvmalloc_node+0xc0/0x2d0 mm/util.c:634 kvmalloc include/linux/slab.h:766 [inline] init_data_container+0x49/0x1e0 fs/btrfs/backref.c:2779 btrfs_ioctl_logical_to_ino+0x17c/0x750 fs/btrfs/ioctl.c:3480 btrfs_ioctl+0x714/0x1260 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:904 [inline] __se_sys_ioctl+0x261/0x450 fs/ioctl.c:890 __x64_sys_ioctl+0x96/0xe0 fs/ioctl.c:890 x64_sys_call+0x1883/0x3b50 arch/x86/include/generated/asm/syscalls_64.h:17 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f Bytes 40-65535 of 65536 are uninitialized Memory access of size 65536 starts at ffff888045a40000 This happens, because we're copying a 'struct btrfs_data_container' back to user-space. This btrfs_data_container is allocated in 'init_data_container()' via kvmalloc(), which does not zero-fill the memory. Fix this by using kvzalloc() which zeroes out the memory on allocation.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35849" target="_blank">CVE-2024-35849</a><br><a href="https://git.kernel.org/stable/c/2f7ef5bb4a2f3e481ef05fab946edb97c84f67cf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/30189e54ba80e3209d34cfeea87b848f6ae025e6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3a63cee1a5e14a3e52c19142c61dd5fcb524f6dc" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/689efe22e9b5b7d9d523119a9a5c3c17107a0772" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/73db209dcd4ae026021234d40cfcb2fb5b564b86" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8bdbcfaf3eac42f98e5486b3d7e130fa287811f6" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e58047553a4e859dafc8d1d901e1de77c9dd922d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fddc19631c51d9c17d43e9f822a7bc403af88d54" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NULL-deref on non-serdev setup Qualcomm ROME controllers can be registered from the Bluetooth line discipline and in this case the HCI UART serdev pointer is NULL. Add the missing sanity check to prevent a NULL-pointer dereference when setup() is called for a non-serdev controller.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35850" target="_blank">CVE-2024-35850</a><br><a href="https://git.kernel.org/stable/c/67459f1a707aae6d590454de07956c2752e21ea4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/7ddb9de6af0f1c71147785b12fd7c8ec3f06cc86" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/bec4d4c6fa5c6526409f582e4f31144e20c86c21" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix NULL-deref on non-serdev suspend Qualcomm ROME controllers can be registered from the Bluetooth line discipline and in this case the HCI UART serdev pointer is NULL. Add the missing sanity check to prevent a NULL-pointer dereference when wakeup() is called for a non-serdev controller during suspend. Just return true for now to restore the original behaviour and address the crash with pre-6.2 kernels, which do not have commit e9b3e5b8c657 ("Bluetooth: hci_qca: only assign wakeup with serial port support") that causes the crash to happen already at setup() time.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35851" target="_blank">CVE-2024-35851</a><br><a href="https://git.kernel.org/stable/c/52f9041deaca3fc5c40ef3b9cb943993ec7d2489" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/6b47cdeb786c38e4174319218db3fa6d7b4bba88" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/73e87c0a49fda31d7b589edccf4c72e924411371" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b64092d2f108f0cd1d7fd7e176f5fb2a67a2f189" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e60502b907be350c518819297b565007a94c706d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix memory leak when canceling rehash work The rehash delayed work is rescheduled with a delay if the number of credits at end of the work is not negative as supposedly it means that the migration ended. Otherwise, it is rescheduled immediately. After "mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash" the above is no longer accurate as a non-negative number of credits is no longer indicative of the migration being done. It can also happen if the work encountered an error in which case the migration will resume the next time the work is scheduled. The significance of the above is that it is possible for the work to be pending and associated with hints that were allocated when the migration started. This leads to the hints being leaked [1] when the work is canceled while pending as part of ACL region dismantle. Fix by freeing the hints if hints are associated with a work that was canceled while pending. Blame the original commit since the reliance on not having a pending work associated with hints is fragile. [1] unreferenced object 0xffff88810e7c3000 (size 256): comm "kworker/0:16", pid 176, jiffies 4295460353 hex dump (first 32 bytes): 00 30 95 11 81 88 ff ff 61 00 00 00 00 00 00 80 .0......a....... 00 00 61 00 40 00 00 00 00 00 00 00 04 00 00 00 ..a.@........... backtrace (crc 2544ddb9): [&lt;00000000cf8cfab3&gt;] kmalloc_trace+0x23f/0x2a0 [&lt;000000004d9a1ad9&gt;] objagg_hints_get+0x42/0x390 [&lt;000000000b143cf3&gt;] mlxsw_sp_acl_erp_rehash_hints_get+0xca/0x400 [&lt;0000000059bdb60a&gt;] mlxsw_sp_acl_tcam_vregion_rehash_work+0x868/0x1160 [&lt;00000000e81fd734&gt;] process_one_work+0x59c/0xf20 [&lt;00000000ceee9e81&gt;] worker_thread+0x799/0x12c0 [&lt;00000000bda6fe39&gt;] kthread+0x246/0x300 [&lt;0000000070056d23&gt;] ret_from_fork+0x34/0x70 [&lt;00000000dea2b93e&gt;] ret_from_fork_asm+0x1a/0x30</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35852" target="_blank">CVE-2024-35852</a><br><a href="https://git.kernel.org/stable/c/51cefc9da400b953fee749c9e5d26cd4a2b5d758" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/5bfe7bf9656ed2633718388f12b7c38b86414a04" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/63d814d93c5cce4c18284adc810028f28dca493f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/857ed800133ffcfcee28582090b63b0cbb8ba59d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d72dd6fcd7886d0523afbab8b4a4b22d17addd7d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/de1aaefa75be9d0ec19c9a3e0e2f9696de20c6ab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/fb4e2b70a7194b209fc7320bbf33b375f7114bd5" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix memory leak during rehash The rehash delayed work migrates filters from one region to another. This is done by iterating over all chunks (all the filters with the same priority) in the region and in each chunk iterating over all the filters. If the migration fails, the code tries to migrate the filters back to the old region. However, the rollback itself can also fail in which case another migration will be erroneously performed. Besides the fact that this ping pong is not a very good idea, it also creates a problem. Each virtual chunk references two chunks: The currently used one ('vchunk-&gt;chunk') and a backup ('vchunk-&gt;chunk2'). During migration the first holds the chunk we want to migrate filters to and the second holds the chunk we are migrating filters from. The code currently assumes - but does not verify - that the backup chunk does not exist (NULL) if the currently used chunk does not reference the target region. This assumption breaks when we are trying to rollback a rollback, resulting in the backup chunk being overwritten and leaked [1]. Fix by not rolling back a failed rollback and add a warning to avoid future cases. [1] WARNING: CPU: 5 PID: 1063 at lib/parman.c:291 parman_destroy+0x17/0x20 Modules linked in: CPU: 5 PID: 1063 Comm: kworker/5:11 Tainted: G W 6.9.0-rc2-custom-00784-gc6a05c468a0b #14 Hardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019 Workqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work RIP: 0010:parman_destroy+0x17/0x20 [...] Call Trace: &lt;TASK&gt; mlxsw_sp_acl_atcam_region_fini+0x19/0x60 mlxsw_sp_acl_tcam_region_destroy+0x49/0xf0 mlxsw_sp_acl_tcam_vregion_rehash_work+0x1f1/0x470 process_one_work+0x151/0x370 worker_thread+0x2cb/0x3e0 kthread+0xd0/0x100 ret_from_fork+0x34/0x50 ret_from_fork_asm+0x1a/0x30 &lt;/TASK&gt;</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35853" target="_blank">CVE-2024-35853</a><br><a href="https://git.kernel.org/stable/c/0ae8ff7b6d42e33943af462910bdcfa2ec0cb8cf" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/413a01886c3958d4b8aac23a3bff3d430b92093e" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/617e98ba4c50f4547c9eb0946b1cfc26937d70d1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/8ca3f7a7b61393804c46f170743c3b839df13977" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b3fd51f684a0711504f82de510da109ae639722d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b822644fd90992ee362c5e0c8d2556efc8856c76" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c6f3fa7f5a748bf6e5c4eb742686d6952f854e76" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash The rehash delayed work migrates filters from one region to another according to the number of available credits. The migrated from region is destroyed at the end of the work if the number of credits is non-negative as the assumption is that this is indicative of migration being complete. This assumption is incorrect as a non-negative number of credits can also be the result of a failed migration. The destruction of a region that still has filters referencing it can result in a use-after-free [1]. Fix by not destroying the region if migration failed. [1] BUG: KASAN: slab-use-after-free in mlxsw_sp_acl_ctcam_region_entry_remove+0x21d/0x230 Read of size 8 at addr ffff8881735319e8 by task kworker/0:31/3858 CPU: 0 PID: 3858 Comm: kworker/0:31 Tainted: G W 6.9.0-rc2-custom-00782-gf2275c2157d8 #5 Hardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019 Workqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work Call Trace: &lt;TASK&gt; dump_stack_lvl+0xc6/0x120 print_report+0xce/0x670 kasan_report+0xd7/0x110 mlxsw_sp_acl_ctcam_region_entry_remove+0x21d/0x230 mlxsw_sp_acl_ctcam_entry_del+0x2e/0x70 mlxsw_sp_acl_atcam_entry_del+0x81/0x210 mlxsw_sp_acl_tcam_vchunk_migrate_all+0x3cd/0xb50 mlxsw_sp_acl_tcam_vregion_rehash_work+0x157/0x1300 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30 &lt;/TASK&gt; Allocated by task 174: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 __kasan_kmalloc+0x8f/0xa0 __kmalloc+0x19c/0x360 mlxsw_sp_acl_tcam_region_create+0xdf/0x9c0 mlxsw_sp_acl_tcam_vregion_rehash_work+0x954/0x1300 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30 Freed by task 7: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 poison_slab_object+0x102/0x170 __kasan_slab_free+0x14/0x30 kfree+0xc1/0x290 mlxsw_sp_acl_tcam_region_destroy+0x272/0x310 mlxsw_sp_acl_tcam_vregion_rehash_work+0x731/0x1300 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35854" target="_blank">CVE-2024-35854</a><br><a href="https://git.kernel.org/stable/c/311eeaa7b9e26aba5b3d57b09859f07d8e9fc049" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/4c89642ca47fb620914780c7c51d8d1248201121" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/54225988889931467a9b55fdbef534079b665519" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/813e2ab753a8f8c243a39ede20c2e0adc15f3887" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a02687044e124f8ccb427cd3632124a4e1a7d7c1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/a429a912d6c779807f4d72a6cc0a1efaaa3613e1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e118e7ea24d1392878ef85926627c6bc640c4388" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix possible use-after-free during activity update The rule activity update delayed work periodically traverses the list of configured rules and queries their activity from the device. As part of this task it accesses the entry pointed by 'ventry-&gt;entry', but this entry can be changed concurrently by the rehash delayed work, leading to a use-after-free [1]. Fix by closing the race and perform the activity query under the 'vregion-&gt;lock' mutex. [1] BUG: KASAN: slab-use-after-free in mlxsw_sp_acl_tcam_flower_rule_activity_get+0x121/0x140 Read of size 8 at addr ffff8881054ed808 by task kworker/0:18/181 CPU: 0 PID: 181 Comm: kworker/0:18 Not tainted 6.9.0-rc2-custom-00781-gd5ab772d32f7 #2 Hardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019 Workqueue: mlxsw_core mlxsw_sp_acl_rule_activity_update_work Call Trace: &lt;TASK&gt; dump_stack_lvl+0xc6/0x120 print_report+0xce/0x670 kasan_report+0xd7/0x110 mlxsw_sp_acl_tcam_flower_rule_activity_get+0x121/0x140 mlxsw_sp_acl_rule_activity_update_work+0x219/0x400 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30 &lt;/TASK&gt; Allocated by task 1039: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 __kasan_kmalloc+0x8f/0xa0 __kmalloc+0x19c/0x360 mlxsw_sp_acl_tcam_entry_create+0x7b/0x1f0 mlxsw_sp_acl_tcam_vchunk_migrate_all+0x30d/0xb50 mlxsw_sp_acl_tcam_vregion_rehash_work+0x157/0x1300 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30 Freed by task 1039: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 kasan_save_free_info+0x3b/0x60 poison_slab_object+0x102/0x170 __kasan_slab_free+0x14/0x30 kfree+0xc1/0x290 mlxsw_sp_acl_tcam_vchunk_migrate_all+0x3d7/0xb50 mlxsw_sp_acl_tcam_vregion_rehash_work+0x157/0x1300 process_one_work+0x8eb/0x19b0 worker_thread+0x6c9/0xf70 kthread+0x2c9/0x3b0 ret_from_fork+0x4d/0x80 ret_from_fork_asm+0x1a/0x30</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35855" target="_blank">CVE-2024-35855</a><br><a href="https://git.kernel.org/stable/c/1b73f6e4ea770410a937a8db98f77e52594d23a0" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/79b5b4b18bc85b19d3a518483f9abbbe6d7b3ba4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b183b915beef818a25e3154d719ca015a1ae0770" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/b996e8699da810e4c915841d6aaef761007f933a" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c17976b42d546ee118ca300db559630ee96fb758" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e24d2487424779c02760ff50cd9021b8676e19ef" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/feabdac2057e863d0e140a2adf3d232eb4882db4" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: Fix double free of skb in coredump hci_devcd_append() would free the skb on error so the caller don't have to free it again otherwise it would cause the double free of skb. Reported-by : Dan Carpenter &lt;dan.carpenter@linaro.org&gt;</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35856" target="_blank">CVE-2024-35856</a><br><a href="https://git.kernel.org/stable/c/18bdb386a1a30e7a3d7732a98e45e69cf6b5710d" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/80dfef128cb9f1b1ef67c0fe8c8deb4ea7ad30c1" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/e20093c741d8da9f6390dd45d75b779861547035" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: icmp: prevent possible NULL dereferences from icmp_build_probe() First problem is a double call to __in_dev_get_rcu(), because the second one could return NULL. if (__in_dev_get_rcu(dev) &amp;&amp; __in_dev_get_rcu(dev)-&gt;ifa_list) Second problem is a read from dev-&gt;ip6_ptr with no NULL check: if (!list_empty(&amp;rcu_dereference(dev-&gt;ip6_ptr)-&gt;addr_list)) Use the correct RCU API to fix these. v2: add missing include &lt;net/addrconf.h&gt;</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35857" target="_blank">CVE-2024-35857</a><br><a href="https://git.kernel.org/stable/c/23b7ee4a8d559bf38eac7ce5bb2f6ebf76f9c401" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/3e2979bf080c40da4f7c93aff8575ab8bc62b767" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/599c9ad5e1d43f5c12d869f5fd406ba5d8c55270" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/c58e88d49097bd12dfcfef4f075b43f5d5830941" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/d68dc711d84fdcf698e5d45308c3ddeede586350" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix memory leak when bringing down interface When bringing down the TX rings we flush the rings but forget to reclaimed the flushed packets. This leads to a memory leak since we do not free the dma mapped buffers. This also leads to tx control block corruption when bringing down the interface for power management.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35858" target="_blank">CVE-2024-35858</a><br><a href="https://git.kernel.org/stable/c/09040baf8779ad880e0e0d0ea10e57aa929ef3ab" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/2389ad1990163d29cba5480d693b4c2e31cc545c" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9f898fc2c31fbf0ac5ecd289f528a716464cb005" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Linux--Linux<br> </td>
<td>In the Linux kernel, the following vulnerability has been resolved: block: fix module reference leakage from bdev_open_by_dev error path At the time bdev_may_open() is called, module reference is grabbed already, hence module reference should be released if bdev_may_open() failed. This problem is found by code review.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35859" target="_blank">CVE-2024-35859</a><br><a href="https://git.kernel.org/stable/c/0e9327c67410b129bf85e5c3a5aaea518328636f" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a><br><a href="https://git.kernel.org/stable/c/9617cd6f24b294552a817f80f5225431ef67b540" target="_blank">416baaa9-dc9f-4396-8d5f-8c081fb06d67</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4367" target="_blank">CVE-2024-4367</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1893645" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4764" target="_blank">CVE-2024-4764</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1879093" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4765" target="_blank">CVE-2024-4765</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1871109" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have lead to potential user confusion and spoofing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4766" target="_blank">CVE-2024-4766</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1871214" target="_blank">security@mozilla.org</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1871217" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4767" target="_blank">CVE-2024-4767</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1878577" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4768" target="_blank">CVE-2024-4768</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1886082" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4769" target="_blank">CVE-2024-4769</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1886108" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4770" target="_blank">CVE-2024-4770</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1893270" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4771" target="_blank">CVE-2024-4771</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1893891" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4772" target="_blank">CVE-2024-4772</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1870579" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4773" target="_blank">CVE-2024-4773</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1875248" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4774" target="_blank">CVE-2024-4774</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1886598" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4775" target="_blank">CVE-2024-4775</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1887332" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4776" target="_blank">CVE-2024-4776</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1887343" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &lt; 126, Firefox ESR &lt; 115.11, and Thunderbird &lt; 115.11.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4777" target="_blank">CVE-2024-4777</a><br><a href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=1878199%2C1893340" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-22/" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-23/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Firefox<br> </td>
<td>Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &lt; 126.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4778" target="_blank">CVE-2024-4778</a><br><a href="https://bugzilla.mozilla.org/buglist.cgi?bug_id=1838834%2C1889291%2C1889595%2C1890204%2C1891545" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-21/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>Mozilla--Focus for iOS<br> </td>
<td>The file scheme of URLs would be hidden, resulting in potential spoofing of a website's address in the location bar This vulnerability affects Focus for iOS &lt; 126.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5022" target="_blank">CVE-2024-5022</a><br><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1874560" target="_blank">security@mozilla.org</a><br><a href="https://www.mozilla.org/security/advisories/mfsa2024-24/" target="_blank">security@mozilla.org</a></td>
</tr>
<tr>
<td>NEC Platforms, Ltd--ITK-6DGS-1(BK) TEL<br> </td>
<td>NEC Platforms DT900 and DT900S Series 5.0.0.0 - v5.3.4.4, v5.4.0.0 - v5.6.0.20 allows an attacker to access a non-documented the system settings to change settings via local network with unauthenticated user.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3016" target="_blank">CVE-2024-3016</a><br><a href="https://jpn.nec.com/security-info/secinfo/nv24-002_en.html" target="_blank">psirt-info@cyber.jp.nec.com</a></td>
</tr>
<tr>
<td>Netflix--ConsoleMe<br> </td>
<td>Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe allows Command Injection.This issue affects ConsoleMe: before 1.4.0.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-5023" target="_blank">CVE-2024-5023</a><br><a href="https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2024-002.md" target="_blank">security-report@netflix.com</a></td>
</tr>
<tr>
<td>OpenSSL--OpenSSL<br> </td>
<td>Issue summary: Checking excessively long DSA keys or parameters may be very slow. Impact summary: Applications that use the functions EVP_PKEY_param_check() or EVP_PKEY_public_check() to check a DSA public key or DSA parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service. The functions EVP_PKEY_param_check() or EVP_PKEY_public_check() perform various checks on DSA parameters. Some of those computations take a long time if the modulus (`p` parameter) is too large. Trying to use a very large modulus is slow and OpenSSL will not allow using public keys with a modulus which is over 10,000 bits in length for signature verification. However the key and parameter check functions do not limit the modulus size when performing the checks. An application that calls EVP_PKEY_param_check() or EVP_PKEY_public_check() and supplies a key or parameters obtained from an untrusted source could be vulnerable to a Denial of Service attack. These functions are not called by OpenSSL itself on untrusted DSA keys so only applications that directly call these functions may be vulnerable. Also vulnerable are the OpenSSL pkey and pkeyparam command line applications when using the `-check` option. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are affected by this issue.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4603" target="_blank">CVE-2024-4603</a><br><a href="https://github.com/openssl/openssl/commit/3559e868e58005d15c6013a0c1fd832e51c73397" target="_blank">openssl-security@openssl.org</a><br><a href="https://github.com/openssl/openssl/commit/53ea06486d296b890d565fb971b2764fcd826e7e" target="_blank">openssl-security@openssl.org</a><br><a href="https://github.com/openssl/openssl/commit/9c39b3858091c152f52513c066ff2c5a47969f0d" target="_blank">openssl-security@openssl.org</a><br><a href="https://github.com/openssl/openssl/commit/da343d0605c826ef197aceedc67e8e04f065f740" target="_blank">openssl-security@openssl.org</a><br><a href="https://www.openssl.org/news/secadv/20240516.txt" target="_blank">openssl-security@openssl.org</a></td>
</tr>
<tr>
<td>Puneeth Reddy--Online Shopping System Advanced<br> </td>
<td>Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser. </td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3579" target="_blank">CVE-2024-3579</a><br><a href="https://cert.pl/en/posts/2024/05/CVE-2024-3579" target="_blank">cvd@cert.pl</a><br><a href="https://cert.pl/posts/2024/05/CVE-2024-3579" target="_blank">cvd@cert.pl</a></td>
</tr>
<tr>
<td>Rockwell Automation--FactoryTalk Remote Access<br> </td>
<td>An unquoted executable path exists in the Rockwell Automation FactoryTalkÂ® Remote Accessâ„¢ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a System user. A threat actor needs admin privileges to exploit this vulnerability.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3640" target="_blank">CVE-2024-3640</a><br><a href="https://www.rockwellautomation.com/en-us/support/advisory.SD1671.html" target="_blank">PSIRT@rockwellautomation.com</a></td>
</tr>
<tr>
<td>Rockwell Automation--FactoryTalk View SE<br> </td>
<td>A vulnerability exists in the Rockwell Automation FactoryTalkÂ® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack could result in information exposure, revealing sensitive information. Additionally, a threat actor could potentially modify and delete the data in a remote database. An attack would only affect the HMI design time, not runtime.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4609" target="_blank">CVE-2024-4609</a><br><a href="https://www.rockwellautomation.com/en-us/support/advisory.SD1670.html" target="_blank">PSIRT@rockwellautomation.com</a></td>
</tr>
<tr>
<td>The Document Foundation--LibreOffice<br> </td>
<td>Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3044" target="_blank">CVE-2024-3044</a><br><a href="https://www.libreoffice.org/about-us/security/advisories/CVE-2024-3044" target="_blank">security@documentfoundation.org</a></td>
</tr>
<tr>
<td>Unknown--Add Custom CSS and JS<br> </td>
<td>The Add Custom CSS and JS WordPress plugin through 1.20 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in as author and above add Stored XSS payloads via a CSRF attack</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3903" target="_blank">CVE-2024-3903</a><br><a href="https://wpscan.com/vulnerability/0a0e7bd4-948d-47c9-9219-380bda9f3034/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Base64 Encoder/Decoder<br> </td>
<td>The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3822" target="_blank">CVE-2024-3822</a><br><a href="https://wpscan.com/vulnerability/ff5411b1-9e04-4e72-a502-e431d774642a/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Base64 Encoder/Decoder<br> </td>
<td>The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3823" target="_blank">CVE-2024-3823</a><br><a href="https://wpscan.com/vulnerability/a138215c-4b8c-4182-978f-d21ce25070d3/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Base64 Encoder/Decoder<br> </td>
<td>The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3824" target="_blank">CVE-2024-3824</a><br><a href="https://wpscan.com/vulnerability/749ae334-b1d1-421e-a04c-35464c961a4a/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--HL Twitter<br> </td>
<td>The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3629" target="_blank">CVE-2024-3629</a><br><a href="https://wpscan.com/vulnerability/c1f6ed2c-0f84-4b13-b39e-5cb91443c2b1/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--HL Twitter<br> </td>
<td>The HL Twitter WordPress plugin through 2014.1.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3630" target="_blank">CVE-2024-3630</a><br><a href="https://wpscan.com/vulnerability/cbab7639-fdb2-4ee5-b5ca-9e30701a63b7/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--HL Twitter<br> </td>
<td>The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check when unlinking twitter accounts, which could allow attackers to make logged in admins perform such actions via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3631" target="_blank">CVE-2024-3631</a><br><a href="https://wpscan.com/vulnerability/c59a8b49-6f3e-452b-ba9b-50b80c522ee9/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--LetterPress <br> </td>
<td>The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks, such as delete arbitrary subscribers</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3590" target="_blank">CVE-2024-3590</a><br><a href="https://wpscan.com/vulnerability/829f4d40-e5b0-4009-b753-85ca2a5b3d25/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Newsletter Popup<br> </td>
<td>The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks against admins</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3641" target="_blank">CVE-2024-3641</a><br><a href="https://wpscan.com/vulnerability/f4047f1e-d5ea-425f-8def-76dd5e6a497e/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Newsletter Popup<br> </td>
<td>The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform such action via a CSRF attack</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3642" target="_blank">CVE-2024-3642</a><br><a href="https://wpscan.com/vulnerability/dc44d85f-afe8-4824-95b0-11b9abfb04d8/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Newsletter Popup<br> </td>
<td>The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3643" target="_blank">CVE-2024-3643</a><br><a href="https://wpscan.com/vulnerability/698277e6-56f9-4688-9a84-c2fa3ea9f7dc/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Newsletter Popup<br> </td>
<td>The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3644" target="_blank">CVE-2024-3644</a><br><a href="https://wpscan.com/vulnerability/10eb712a-d9c3-46c9-be6a-02811396fae8/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--NextGEN Gallery <br> </td>
<td>The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2744" target="_blank">CVE-2024-2744</a><br><a href="https://wpscan.com/vulnerability/a5579c15-50ba-4618-95e4-04b2033d721f/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Popup4Phone<br> </td>
<td>The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3231" target="_blank">CVE-2024-3231</a><br><a href="https://wpscan.com/vulnerability/81dbb5c0-ccdd-4af1-b2f2-71cb1b37fe93/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Popup4Phone<br> </td>
<td>The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3580" target="_blank">CVE-2024-3580</a><br><a href="https://wpscan.com/vulnerability/31f401c4-735a-4efb-b81f-ab98c00c526b/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Post Grid Gutenberg Blocks and WordPress Blog Plugin <br> </td>
<td>The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.0.2 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3239" target="_blank">CVE-2024-3239</a><br><a href="https://wpscan.com/vulnerability/dfa1421b-41b0-4b25-95ef-0843103e1f5e/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--SP Project &amp; Document Manager<br> </td>
<td>The SP Project &amp; Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a user to manipulate the `user_id` to make it appear that a file was uploaded by another user</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3748" target="_blank">CVE-2024-3748</a><br><a href="https://wpscan.com/vulnerability/01427cfb-5c51-4524-9b9d-e09a603bc34c/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--SP Project &amp; Document Manager<br> </td>
<td>The SP Project &amp; Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in user to view and download files belonging to another user</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3749" target="_blank">CVE-2024-3749</a><br><a href="https://wpscan.com/vulnerability/d14bb16e-ce1d-4c31-8791-bc63174897c0/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Save as PDF Plugin by Pdfcrowd<br> </td>
<td>The Save as PDF Plugin by Pdfcrowd WordPress plugin before 3.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-5971" target="_blank">CVE-2023-5971</a><br><a href="https://wpscan.com/vulnerability/03a201d2-535e-4574-afac-791dcf23e6e1/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--Ultimate Blocks <br> </td>
<td>The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3241" target="_blank">CVE-2024-3241</a><br><a href="https://wpscan.com/vulnerability/a645daee-42ea-43f8-9480-ef3be69606e0/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--UnGallery<br> </td>
<td>The UnGallery WordPress plugin through 2.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3582" target="_blank">CVE-2024-3582</a><br><a href="https://wpscan.com/vulnerability/5a348b5d-13aa-40c3-9d21-0554683f8019/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--VikBooking Hotel Booking Engine &amp; PMS<br> </td>
<td>The VikBooking Hotel Booking Engine &amp; PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, to bypass authorization and access settings of the VikBooking Hotel Booking Engine &amp; PMS WordPress plugin before 1.6.8's they shouldn't be allowed to.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2441" target="_blank">CVE-2024-2441</a><br><a href="https://wpscan.com/vulnerability/9647e273-5724-4a02-868d-9b79f4bb2b79/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--VikBooking Hotel Booking Engine &amp; PMS<br> </td>
<td>The VikBooking Hotel Booking Engine &amp; PMS WordPress plugin before 1.6.8's access control mechanism fails to properly restrict access to its settings, permitting any users that can access a menu to manipulate requests and perform unauthorized actions such as editing, renaming or deleting (categories for example) despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical VikBooking Hotel Booking Engine &amp; PMS WordPress plugin before 1.6.8 configurations.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2749" target="_blank">CVE-2024-2749</a><br><a href="https://wpscan.com/vulnerability/c0640d3a-80b3-4cad-a3cf-fb5d86558e91/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--WP Prayer<br> </td>
<td>The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3405" target="_blank">CVE-2024-3405</a><br><a href="https://wpscan.com/vulnerability/6968d43c-16ff-43a9-8451-71aabbe69014/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--WP Prayer<br> </td>
<td>The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3406" target="_blank">CVE-2024-3406</a><br><a href="https://wpscan.com/vulnerability/1bfab060-64d2-4c38-8bc8-a8f81c5a6e0d/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--WP Prayer<br> </td>
<td>The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3407" target="_blank">CVE-2024-3407</a><br><a href="https://wpscan.com/vulnerability/262348ab-a335-4acf-8e4d-229fc0b4972f/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--WP Shortcodes Plugin Shortcodes Ultimate<br> </td>
<td>The WP Shortcodes Plugin - Shortcodes Ultimate WordPress plugin before 7.1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3548" target="_blank">CVE-2024-3548</a><br><a href="https://wpscan.com/vulnerability/9eef8b29-2c62-4daa-ae90-467ff9be18d8/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--month name translation benaceur<br> </td>
<td>The month name translation benaceur WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3634" target="_blank">CVE-2024-3634</a><br><a href="https://wpscan.com/vulnerability/76e000e0-314f-4e39-8871-68bf8cc95b22/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--reCAPTCHA Jetpack<br> </td>
<td>The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3940" target="_blank">CVE-2024-3940</a><br><a href="https://wpscan.com/vulnerability/bb0245e5-8e94-4f11-9003-d6208945056c/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--reCAPTCHA Jetpack<br> </td>
<td>The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3941" target="_blank">CVE-2024-3941</a><br><a href="https://wpscan.com/vulnerability/6e09e922-983c-4406-8053-747d839995d1/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Unknown--socialdriver-framework<br> </td>
<td>The socialdriver-framework WordPress plugin before 2024.0.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2697" target="_blank">CVE-2024-2697</a><br><a href="https://wpscan.com/vulnerability/c430b30d-61db-45f5-8499-91b491503b9c/" target="_blank">contact@wpscan.com</a></td>
</tr>
<tr>
<td>Veeam--Service Provider Console<br> </td>
<td>Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication between the management agent and its components, under certain conditions, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29212" target="_blank">CVE-2024-29212</a><br><a href="https://www.veeam.com/kb4575" target="_blank">support@hackerone.com</a></td>
</tr>
<tr>
<td>Xen--Xen<br> </td>
<td>Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other modes. This in particular means that they may set registers used to pass 32-bit-mode hypercall arguments to values outside of the range 32-bit code would be able to set them to. When processing of hypercalls takes a considerable amount of time, the hypervisor may choose to invoke a hypercall continuation. Doing so involves putting (perhaps updated) hypercall arguments in respective registers. For guests not running in 64-bit mode this further involves a certain amount of translation of the values. Unfortunately internal sanity checking of these translated values assumes high halves of registers to always be clear when invoking a hypercall. When this is found not to be the case, it triggers a consistency check in the hypervisor and causes a crash.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46842" target="_blank">CVE-2023-46842</a><br><a href="https://xenbits.xenproject.org/xsa/advisory-454.html" target="_blank">security@xen.org</a></td>
</tr>
<tr>
<td>Xen--Xen<br> </td>
<td>Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted. For more details, see: https://xenbits.xen.org/xsa/advisory-407.html https://xenbits.xen.org/xsa/advisory-434.html</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31142" target="_blank">CVE-2024-31142</a><br><a href="https://xenbits.xenproject.org/xsa/advisory-455.html" target="_blank">security@xen.org</a></td>
</tr>
<tr>
<td>Xpdf--Xpdf<br> </td>
<td>Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4976" target="_blank">CVE-2024-4976</a><br><a href="https://www.xpdfreader.com/security-bug/CVE-2024-4976.html" target="_blank">xpdf@xpdfreader.com</a></td>
</tr>
<tr>
<td>alpitronic--Hypercharger EV Charger<br> </td>
<td>If misconfigured, alpitronic Hypercharger EV charging devices can expose a web interface protected by authentication. If the default credentials are not changed, an attacker can use public knowledge to access the device as an administrator.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4622" target="_blank">CVE-2024-4622</a><br><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-130-02" target="_blank">ics-cert@hq.dhs.gov</a></td>
</tr>
<tr>
<td>berriai--berriai/litellm<br> </td>
<td>A remote code execution (RCE) vulnerability exists in the berriai/litellm project due to improper control of the generation of code when using the `eval` function unsafely in the `litellm.get_secret()` method. Specifically, when the server utilizes Google KMS, untrusted data is passed to the `eval` function without any sanitization. Attackers can exploit this vulnerability by injecting malicious values into environment variables through the `/config/update` endpoint, which allows for the update of settings in `proxy_server_config.yaml`.</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4264" target="_blank">CVE-2024-4264</a><br><a href="https://huntr.com/bounties/a3221b0c-6e25-4295-ab0f-042997e8fc61" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>gaizhenbiao--gaizhenbiao/chuanhuchatgpt<br> </td>
<td>A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for uploading chat history. The vulnerability arises due to improper input validation when handling file paths during the chat history upload process. An attacker can exploit this vulnerability by intercepting requests and manipulating the 'name' parameter to specify arbitrary file paths. This allows the attacker to read sensitive files on the server, leading to information leakage, including API keys and private information. The issue affects version 20240310 of the application.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4321" target="_blank">CVE-2024-4321</a><br><a href="https://huntr.com/bounties/19a16f8e-3d92-498f-abc9-8686005f067e" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>imartinez--imartinez/privategpt<br> </td>
<td>imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read arbitrary files from the filesystem. By manipulating file upload functionality to ingest arbitrary local files, attackers can exploit the 'Search in Docs' feature or query the AI to retrieve or disclose the contents of any file on the system. This vulnerability could lead to various impacts, including but not limited to remote code execution by obtaining private SSH keys, unauthorized access to private files, source code disclosure facilitating further attacks, and exposure of configuration files.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3403" target="_blank">CVE-2024-3403</a><br><a href="https://huntr.com/bounties/7431d1dd-f014-4d4f-acb6-f97369ef3688" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>imartinez--imartinez/privategpt<br> </td>
<td>A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper validation of file uploads. Attackers can exploit this vulnerability by uploading malicious HTML files, such as those containing JavaScript payloads, which are then executed in the context of the victim's session when accessed. This could lead to the execution of arbitrary JavaScript code in the context of the user's browser session, potentially resulting in phishing attacks or other malicious actions. The vulnerability affects the latest version of the repository.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3851" target="_blank">CVE-2024-3851</a><br><a href="https://huntr.com/bounties/cae1a492-4e09-4d56-8e11-17703bdfe653" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>mlflow--mlflow/mlflow<br> </td>
<td>A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the application's handling of artifact URLs, where a '#' character can be used to insert a path into the fragment, effectively skipping validation. This allows an attacker to construct a URL that, when processed, ignores the protocol scheme and uses the provided path for filesystem access. As a result, an attacker can read arbitrary files, including sensitive information such as SSH and cloud keys, by exploiting the way the application converts the URL into a filesystem path. The issue stems from insufficient validation of the fragment portion of the URL, leading to arbitrary file read through path traversal.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3848" target="_blank">CVE-2024-3848</a><br><a href="https://github.com/mlflow/mlflow/commit/f8d51e21523238280ebcfdb378612afd7844eca8" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/8d5aadaa-522f-4839-b41b-d7da362dd610" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>mlflow--mlflow/mlflow<br> </td>
<td>A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with only EDIT permissions on an experiment can delete any artifacts. This issue arises due to the lack of proper validation for DELETE requests by users with EDIT permissions, allowing them to perform unauthorized deletions of artifacts. The vulnerability specifically affects the handling of artifact deletions within the application, as demonstrated by the ability of a low privilege user to delete a directory inside an artifact using a DELETE request, despite the official documentation stating that users with EDIT permission can only read and update artifacts, not delete them.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4263" target="_blank">CVE-2024-4263</a><br><a href="https://github.com/mlflow/mlflow/commit/b43e0e3de5b500554e13dc032ba2083b2d6c94b8" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/bfa116d3-2af8-4c4a-ac34-ccde7491ae11" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Extreme Networks EXOS before v.22.7 and before v.30.2 was discovered to contain an issue in its Web GUI which fails to restrict URL access, allowing attackers to access sensitive information or escalate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2020-18305" target="_blank">CVE-2020-18305</a><br><a href="https://gist.github.com/yasinyilmaz/1fe3fe58dd275edb77dcbe890fce2f2c" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers to access and manipulate the database through crafted requests. By exploiting this flaw, attackers can bypass authentication mechanisms, view sensitive information stored in the database, and potentially exfiltrate data.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-28132" target="_blank">CVE-2022-28132</a><br><a href="https://www.exploit-db.com/exploits/50939" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service that allows remote code execution. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32502" target="_blank">CVE-2022-32502</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect to the device and bypass both hardware and software security protections. This affects Nuki Keypad before 1.9.2 and Nuki Fob before 1.8.1.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32503" target="_blank">CVE-2022-32503</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. The code used to parse the JSON objects received from the WebSocket service provided by the device leads to a stack buffer overflow. An attacker would be able to exploit this to gain arbitrary code execution on a KeyTurner device. This affects Nuki Smart Lock 3.0 before 3.3.5 and 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32504" target="_blank">CVE-2022-32504</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. It is possible to send multiple BLE malformed packets to block some of the functionality and reboot the device. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32505" target="_blank">CVE-2022-32505</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to the circuit board could use the SWD debug features to control the execution of code on the processor and debug the firmware, as well as read or alter the content of the internal and external flash memory. This affects Nuki Smart Lock 3.0 before 3.3.5, Nuki Smart Lock 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32506" target="_blank">CVE-2022-32506</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, could also be called from unprivileged accounts. This demonstrates that no access controls were implemented for the different BLE commands across the different accounts. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32507" target="_blank">CVE-2022-32507</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. By sending a malformed HTTP verb, it is possible to force a reboot of the device. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32508" target="_blank">CVE-2022-32508</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. Lack of certificate validation on HTTP communications allows attackers to intercept and tamper data. This affects Nuki Smart Lock 3.0 before 3.3.5, Nuki Bridge v1 before 1.22.0 and Nuki Bridge v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32509" target="_blank">CVE-2022-32509</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the full set of API endpoints. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2022-32510" target="_blank">CVE-2022-32510</a><br><a href="https://latesthackingnews.com/2022/07/28/multiple-security-flaws-found-in-nuki-smart-locks/" target="_blank">cve@mitre.org</a><br><a href="https://nuki.io/en/security-updates/" target="_blank">cve@mitre.org</a><br><a href="https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/" target="_blank">cve@mitre.org</a><br><a href="https://www.hackread.com/nuki-smart-locks-vulnerabilities-plethora-attack-options/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-24203" target="_blank">CVE-2023-24203</a><br><a href="https://github.com/momo1239/CVE-2023-24203-and-CVE-2023-24204" target="_blank">cve@mitre.org</a><br><a href="https://momonguyen.com/2023/cve-2023-24203/" target="_blank">cve@mitre.org</a><br><a href="https://www.sourcecodester.com/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-24204" target="_blank">CVE-2023-24204</a><br><a href="https://github.com/momo1239/CVE-2023-24203-and-CVE-2023-24204" target="_blank">cve@mitre.org</a><br><a href="https://momonguyen.com/2023/cve-2023-24203/" target="_blank">cve@mitre.org</a><br><a href="https://www.sourcecodester.com/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make external and internal calls via HTTP and WebSocket requests sent to the API.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-26566" target="_blank">CVE-2023-26566</a><br><a href="https://qsecure.com.cy/resources/advisories/sangoma-freepbx-linux-hardcoded-credentials" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-29881" target="_blank">CVE-2023-29881</a><br><a href="https://gist.github.com/Northind/97522a49ae4bb0c8e6e2a49e75fd637a" target="_blank">cve@mitre.org</a><br><a href="https://github.com/qinggan/phpok/issues/15" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Stakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-40297" target="_blank">CVE-2023-40297</a><br><a href="https://github.com/sahar042/CVE-2023-40297" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers to do code execution via modified bash and python scripts.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-46870" target="_blank">CVE-2023-46870</a><br><a href="https://github.com/Chapoly1305/CVE-2023-46870" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Shrubbery tac_plus 2.x, 3.x. and 4.x through F4.0.4.28 allows unauthenticated Remote Command Execution. The product allows users to configure authorization checks as shell commands through the tac_plus.cfg configuration file. These are executed when a client sends an authorization request with a username that has pre-authorization directives configured. However, it is possible to inject additional commands into these checks because strings from TACACS+ packets are used as command-line arguments. If the installation lacks a a pre-shared secret (there is no pre-shared secret by default), then the injection can be triggered without authentication. (The attacker needs to know a username configured to use a pre-authorization command.) NOTE: this is related to CVE-2023-45239 but the issue is in the original Shrubbery product, not Meta's fork.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-48643" target="_blank">CVE-2023-48643</a><br><a href="https://github.com/takeshixx/tac_plus-pre-auth-rce" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>The IEEE 802.11 standard sometimes enables an adversary to trick a victim into connecting to an unintended or untrusted network with Home WEP, Home WPA3 SAE-loop. Enterprise 802.1X/EAP, Mesh AMPE, or FILS, aka an "SSID Confusion" issue. This occurs because the SSID is not always used to derive the pairwise master key or session keys, and because there is not a protected exchange of an SSID during a 4-way handshake.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2023-52424" target="_blank">CVE-2023-52424</a><br><a href="https://mentor.ieee.org/802.11/dcn/24/11-24-0938-03-000m-protect-ssid-in-4-way-handshake.docx" target="_blank">cve@mitre.org</a><br><a href="https://www.top10vpn.com/assets/2024/05/Top10VPN-x-Vanhoef-SSID-Confusion.pdf" target="_blank">cve@mitre.org</a><br><a href="https://www.top10vpn.com/research/wifi-vulnerability-ssid/" target="_blank">cve@mitre.org</a><br><a href="https://www.wi-fi.org/news-events/press-releases" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in Panoramic Corporation Digital Imaging Software v.9.1.2.7600 allows a local attacker to escalate privileges via the ccsservice.exe component.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22774" target="_blank">CVE-2024-22774</a><br><a href="https://blueteamalpha.com/blog/new-vulnerability-discovered-in-panoramic-x-ray-software/" target="_blank">cve@mitre.org</a><br><a href="https://github.com/Gray-0men/CVE-2024-22774" target="_blank">cve@mitre.org</a><br><a href="https://pancorp.com/index.html" target="_blank">cve@mitre.org</a><br><a href="https://pancorp.com/pdf/Panoramic-Dental-Imaging-%28GLAN%29-Windows-10x64-Setup-Rev3.pdf" target="_blank">cve@mitre.org</a><br><a href="https://pancorp.com/software/files/PANCORP_DENTAL_IMAGING_9.1.2.7600.exe" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payload.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-22910" target="_blank">CVE-2024-22910</a><br><a href="https://gist.github.com/cgnl/672ace3cbad1116fcd9ae633e54ea9f8" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-24157" target="_blank">CVE-2024-24157</a><br><a href="https://github.com/gnuboard/g6/issues/314" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB19130163 in 05.46.07, kernel 5.5: IB19130163 in 05.54.07, and kernel 5.6: IB19130163 in 05.61.07 could lead to escalating privileges in SMM.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25078" target="_blank">CVE-2024-25078</a><br><a href="https://www.insyde.com/security-pledge" target="_blank">cve@mitre.org</a><br><a href="https://www.insyde.com/security-pledge/SA-2024001" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A memory corruption vulnerability in HddPassword in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 before 05.54.09, and kernel 5.6 before 05.61.09 could lead to escalating privileges in SMM.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25079" target="_blank">CVE-2024-25079</a><br><a href="https://www.insyde.com/security-pledge" target="_blank">cve@mitre.org</a><br><a href="https://www.insyde.com/security-pledge/SA-2024001" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 and older are vulnerable to Cross-Site Scripting (XSS) for malicious URLs.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25662" target="_blank">CVE-2024-25662</a><br><a href="https://www.oxygenxml.com/security/advisory/SYNC-2024-020601.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and can trigger its handler. This affects AMD SEV-SNP and AMD SEV-ES.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25742" target="_blank">CVE-2024-25742</a><br><a href="https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.9" target="_blank">cve@mitre.org</a><br><a href="https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e3ef461af35a8c74f2f4ce6616491ddb355a208f" target="_blank">cve@mitre.org</a><br><a href="https://github.com/torvalds/linux/commit/e3ef461af35a8c74f2f4ce6616491ddb355a208f" target="_blank">cve@mitre.org</a><br><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3008.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-25743" target="_blank">CVE-2024-25743</a><br><a href="https://bugzilla.redhat.com/show_bug.cgi?id=2270836" target="_blank">cve@mitre.org</a><br><a href="https://bugzilla.suse.com/show_bug.cgi?id=1223307" target="_blank">cve@mitre.org</a><br><a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3008.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-26306" target="_blank">CVE-2024-26306</a><br><a href="https://downloads.es.net/pub/iperf/esnet-secadv-2024-0001.txt.asc" target="_blank">cve@mitre.org</a><br><a href="https://github.com/esnet/iperf/releases/tag/3.17" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting vulnerability in Evertz microsystems MViP-II Firmware 8.6.5, XPS-EDGE-* Build 1467, evEDGE-EO-* Build 0029, MMA10G-* Build 0498, 570IPG-X19-10G Build 0691 allows a remote attacker to execute arbitrary code via a crafted payload to the login parameters.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-26367" target="_blank">CVE-2024-26367</a><br><a href="http://cc.com/" target="_blank">cve@mitre.org</a><br><a href="http://evertz.com/" target="_blank">cve@mitre.org</a><br><a href="https://wiki.notveg.ninja/blog/CVE-2024-26367/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the delete-task.php component.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-26517" target="_blank">CVE-2024-26517</a><br><a href="https://github.com/unrealjbr/CVE-2024-26517" target="_blank">cve@mitre.org</a><br><a href="https://www.sourcecodester.com/php/16877/school-task-manager-using-php-source-code.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.3 is the main fixed version; however, for Ruby 3.0 users, a fixed version is stringio 3.0.1.1, and for Ruby 3.1 users, a fixed version is stringio 3.0.1.2.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27280" target="_blank">CVE-2024-27280</a><br><a href="https://hackerone.com/reports/1399856" target="_blank">cve@mitre.org</a><br><a href="https://www.ruby-lang.org/en/news/2024/03/21/buffer-overread-cve-2024-27280/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27281" target="_blank">CVE-2024-27281</a><br><a href="https://hackerone.com/reports/1187477" target="_blank">cve@mitre.org</a><br><a href="https://www.ruby-lang.org/en/news/2024/03/21/rce-rdoc-cve-2024-27281/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27282" target="_blank">CVE-2024-27282</a><br><a href="https://hackerone.com/reports/2122624" target="_blank">cve@mitre.org</a><br><a href="https://www.ruby-lang.org/en/news/2024/04/23/arbitrary-memory-address-read-regexp-cve-2024-27282/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A memory corruption vulnerability in SdHost and SdMmcDevice in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 before 05.54.09, and kernel 5.6 before 05.61.09 could lead to escalating privileges in SMM.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27353" target="_blank">CVE-2024-27353</a><br><a href="https://www.insyde.com/security-pledge" target="_blank">cve@mitre.org</a><br><a href="https://www.insyde.com/security-pledge/SA-2024001" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A stored cross-site scripting (XSS) vulnerability in the Filter function of Eramba Version 3.22.3 Community Edition allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the filter name field. This vulnerability has been fixed in version 3.23.0.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-27593" target="_blank">CVE-2024-27593</a><br><a href="https://blog.smarttecs.com/posts/2024-002-cve-2024-27593/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS.</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28063" target="_blank">CVE-2024-28063</a><br><a href="https://www.objectif-securite.ch/advisories/totemomail-reflected-xss.txt" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Kiteworks Totemomail 7.x and 8.x before 8.3.0 allows /responsiveUI/EnvelopeOpenServlet messageId directory traversal for unauthenticated file read and delete operations (with displayLoginChunkedImages) and write operations (with storeLoginChunkedImages).</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28064" target="_blank">CVE-2024-28064</a><br><a href="https://www.objectif-securite.ch/advisories/totemomail-path-traversal.txt" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In Bonitasoft runtime Community edition, the lack of dynamic permissions causes IDOR vulnerability. Dynamic permissions existed only in Subscription edition and have now been restored in Community edition, where they are not custmizable.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28087" target="_blank">CVE-2024-28087</a><br><a href="https://documentation.bonitasoft.com/bonita/latest/release-notes#_fixes_in_bonita_2024_1_2024_04_11" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28276" target="_blank">CVE-2024-28276</a><br><a href="https://github.com/unrealjbr/CVE-2024-28276" target="_blank">cve@mitre.org</a><br><a href="https://www.sourcecodester.com/download-code?nid=16877&amp;title=School+Task+Manager+Using+PHP+with+Source+Code" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In Sourcecodester School Task Manager v1.0, a vulnerability was identified within the subject_name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to manipulate the subject's name, potentially leading to the execution of malicious JavaScript payloads.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28277" target="_blank">CVE-2024-28277</a><br><a href="https://github.com/unrealjbr/CVE-2024-28277" target="_blank">cve@mitre.org</a><br><a href="https://www.sourcecodester.com/download-code?nid=16877&amp;title=School+Task+Manager+Using+PHP+with+Source+Code" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28279" target="_blank">CVE-2024-28279</a><br><a href="https://code-projects.org/computer-book-store-in-php-with-source-code/" target="_blank">cve@mitre.org</a><br><a href="https://github.com/unrealjbr/CVE-2024-28279" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-28285" target="_blank">CVE-2024-28285</a><br><a href="https://gist.github.com/liang-junkai/3e91f58070812ea76c1b8c126c3e28c7" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29157" target="_blank">CVE-2024-29157</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29158" target="_blank">CVE-2024-29158</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29159" target="_blank">CVE-2024-29159</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29160" target="_blank">CVE-2024-29160</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_release_table, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29161" target="_blank">CVE-2024-29161</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read, resulting in denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29162" target="_blank">CVE-2024-29162</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29163" target="_blank">CVE-2024-29163</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29164" target="_blank">CVE-2024-29164</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29165" target="_blank">CVE-2024-29165</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29166" target="_blank">CVE-2024-29166</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Forensics before 3.3 allows a local attacker to execute arbitrary code within the driver and create a local denial-of-service condition due to an improper DACL being applied to the device the driver creates.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29513" target="_blank">CVE-2024-29513</a><br><a href="https://github.com/dru1d-foofus/briscKernelDriver" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m parameters can lead to excessive CPU consumption during the evaluation of the curve parameters.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-29857" target="_blank">CVE-2024-29857</a><br><a href="https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9029857" target="_blank">cve@mitre.org</a><br><a href="https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9029857" target="_blank">cve@mitre.org</a><br><a href="https://www.bouncycastle.org/latest_releases.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30171" target="_blank">CVE-2024-30171</a><br><a href="https://github.com/bcgit/bc-csharp/wiki/CVE%E2%80%902024%E2%80%9030171" target="_blank">cve@mitre.org</a><br><a href="https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902024%E2%80%9030171" target="_blank">cve@mitre.org</a><br><a href="https://www.bouncycastle.org/latest_releases.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and public key.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30172" target="_blank">CVE-2024-30172</a><br><a href="https://www.bouncycastle.org/latest_releases.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp component.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30801" target="_blank">CVE-2024-30801</a><br><a href="http://cloud.com/" target="_blank">cve@mitre.org</a><br><a href="http://www.minipacs.com/ylqxrj" target="_blank">cve@mitre.org</a><br><a href="https://github.com/WarmBrew/web_vul/blob/main/Cloud%20based%20customer%20service/SQLi.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in Vehicle Management System 7.31.0.3_20230412 allows an attacker to escalate privileges via the login.html component.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-30802" target="_blank">CVE-2024-30802</a><br><a href="https://github.com/WarmBrew/web_vul/blob/main/TTX.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive information via the sessionid function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31556" target="_blank">CVE-2024-31556</a><br><a href="https://github.com/reportico-web/reportico/issues/53" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Insecure Permission vulnerability in TotalAV v.6.0.740 allows a local attacker to escalate privileges via a crafted file</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31771" target="_blank">CVE-2024-31771</a><br><a href="https://github.com/restdone/CVE-2024-31771" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Buffer Overflow vulnerability in emp-ot v.0.2.4 allows a remote attacker to execute arbitrary code via the FerretCOT&lt;T&gt;::read_pre_data128_from_file function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31803" target="_blank">CVE-2024-31803</a><br><a href="https://github.com/FudanMPL/Vulnerabilities-in-MPC-Framework/tree/main/emp-ot/stack-buffer-overflow-ferret_cot" target="_blank">cve@mitre.org</a><br><a href="https://github.com/emp-toolkit/emp-ot/issues/89" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31810" target="_blank">CVE-2024-31810</a><br><a href="https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/EX200/HardCode/HardCode.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>The com.solarized.firedown (aka Solarized FireDown Browser &amp; Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. com.solarized.firedown.IntentActivity uses a WebView component to display web content and doesn't adequately sanitize the URI or any extra data passed in the intent by any installed application (with no permissions).</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-31974" target="_blank">CVE-2024-31974</a><br><a href="https://github.com/actuator/com.solarized.firedown/blob/main/CVE-2024-31974" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32349" target="_blank">CVE-2024-32349</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" parameter in the "cstecgi.cgi" binary.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32350" target="_blank">CVE-2024-32350</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mru" parameter in the "cstecgi.cgi" binary.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32351" target="_blank">CVE-2024-32351</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecL2tpEnable" parameter in the "cstecgi.cgi" binary.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32352" target="_blank">CVE-2024-32352</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32353" target="_blank">CVE-2024-32353</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32354" target="_blank">CVE-2024-32354</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32355" target="_blank">CVE-2024-32355</a><br><a href="https://github.com/1s1and123/Vulnerabilities/blob/main/device/ToToLink/X5000R/TOTOLink_X5000R_RCE.md" target="_blank">cve@mitre.org</a><br><a href="https://www.totolink.net/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32605" target="_blank">CVE-2024-32605</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 may attempt to dereference uninitialized values in h5tools_str_sprint in tools/lib/h5tools_str.c (called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32606" target="_blank">CVE-2024-32606</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32607" target="_blank">CVE-2024-32607</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32609" target="_blank">CVE-2024-32609</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, resulting in a corrupted instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32610" target="_blank">CVE-2024-32610</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32611" target="_blank">CVE-2024-32611</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c, resulting in the corruption of the instruction pointer, a different vulnerability than CVE-2024-32613.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32612" target="_blank">CVE-2024-32612</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerability than CVE-2024-32612.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32613" target="_blank">CVE-2024-32613</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32614" target="_blank">CVE-2024-32614</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused by the earlier use of an initialized pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32615" target="_blank">CVE-2024-32615</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32616" target="_blank">CVE-2024-32616</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32617" target="_blank">CVE-2024-32617</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32618" target="_blank">CVE-2024-32618</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32619" target="_blank">CVE-2024-32619</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32620" target="_blank">CVE-2024-32620</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c), resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32621" target="_blank">CVE-2024-32621</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_extent_simple in H5S.c).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32622" target="_blank">CVE-2024-32622</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5VM_array_fill in H5VM.c (called from H5S_select_elements in H5Spoint.c).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32623" target="_blank">CVE-2024-32623</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__ref_mem_setnull in H5Tref.c (called from H5T__conv_ref in H5Tconv.c), resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-32624" target="_blank">CVE-2024-32624</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in Open-Source Technology Committee SRS real-time video server RS/4.0.268(Leo) and SRS/4.0.195(Leo) allows a remote attacker to execute arbitrary code via a crafted request.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33250" target="_blank">CVE-2024-33250</a><br><a href="https://github.com/hacker2004/cccccckkkkkk/blob/main/CVE-2024-33250.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33263" target="_blank">CVE-2024-33263</a><br><a href="https://github.com/bellard/quickjs/issues/277" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the Wireless Page.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33433" target="_blank">CVE-2024-33433</a><br><a href="https://github.com/4hsien/CVE-vulns/blob/main/TOTOLINK/X2000R/XSS_2_Guest_Access_Control/README.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33454" target="_blank">CVE-2024-33454</a><br><a href="https://gist.github.com/Zakary-D/30f565c4266c02c62aa9089c363e78e9" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the login.php component</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33485" target="_blank">CVE-2024-33485</a><br><a href="https://github.com/CveSecLook/cve/issues/17" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via goform/formWPS, allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33771" target="_blank">CVE-2024-33771</a><br><a href="https://github.com/YuboZhaoo/IoT/blob/main/D-Link/DIR-619L/20240424.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "curTime."</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33772" target="_blank">CVE-2024-33772</a><br><a href="https://github.com/YuboZhaoo/IoT/blob/main/D-Link/DIR-619L/20240424.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanGuestSetup allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33773" target="_blank">CVE-2024-33773</a><br><a href="https://github.com/YuboZhaoo/IoT/blob/main/D-Link/DIR-619L/20240424.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authenticated users to trigger a denial of service (DoS) through the parameter "webpage."</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33774" target="_blank">CVE-2024-33774</a><br><a href="https://github.com/YuboZhaoo/IoT/blob/main/D-Link/DIR-619L/20240424.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33818" target="_blank">CVE-2024-33818</a><br><a href="https://medium.com/%40rajput.thakur/insecure-direct-object-references-cve-2024-33818-86785aa8c969" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Globitel KSA SpeechLog v8.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Save Query function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33819" target="_blank">CVE-2024-33819</a><br><a href="https://medium.com/%40rajput.thakur/speechlog-v-8-1-stored-cross-site-scripting-cve-2024-33819-1b1164fb0ecd" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33863" target="_blank">CVE-2024-33863</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via remote images in process creation, file inclusion, and PDF document generation via malicious JavaScript.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33864" target="_blank">CVE-2024-33864</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GUID] endpoints.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33865" target="_blank">CVE-2024-33865</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33866" target="_blank">CVE-2024-33866</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33867" target="_blank">CVE-2024-33867</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33868" target="_blank">CVE-2024-33868</a><br><a href="https://linqi.help/Updates/en#/SecurityUpdates" target="_blank">cve@mitre.org</a><br><a href="https://www.linqi.de/de-DE/blog.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33873" target="_blank">CVE-2024-33873</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33874" target="_blank">CVE-2024-33874</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruction pointer.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33875" target="_blank">CVE-2024-33875</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33876" target="_blank">CVE-2024-33876</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-33877" target="_blank">CVE-2024-33877</a><br><a href="https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>The WebTop package for NethServer 7 and 8 allows stored XSS (for example, via the Subject field if an e-mail message).</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34058" target="_blank">CVE-2024-34058</a><br><a href="https://www.openwall.com/lists/oss-security/2024/05/16/3" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.php. This vulnerability allows attackers to delete arbitrary files via a crafted request.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34191" target="_blank">CVE-2024-34191</a><br><a href="https://chmod744.super.site/htmly-cve" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Totolink AC1200 Wireless Dual Band Gigabit Router A3002RU_V3 Firmware V3.0.0-B20230809.1615 is vulnerable to Buffer Overflow. The "boa" program allows attackers to modify the value of the "vwlan_idx" field via "formMultiAP". This can lead to a stack overflow through the "formWlEncrypt" CGI function by constructing malicious HTTP requests and passing a WLAN SSID value exceeding the expected length, potentially resulting in command execution or denial of service attacks.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34196" target="_blank">CVE-2024-34196</a><br><a href="https://gist.github.com/Swind1er/1ec2fde42254598a72f1d716f9cfe2a1" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34199" target="_blank">CVE-2024-34199</a><br><a href="https://github.com/DMCERTCE/PoC_Tiny_Overflow" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQosRules function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34200" target="_blank">CVE-2024-34200</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setIpQosRules" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the getSaveConfig function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34201" target="_blank">CVE-2024-34201</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/getSaveConfig" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilterRules function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34202" target="_blank">CVE-2024-34202</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setMacFilterRules" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setLanguageCfg function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34203" target="_blank">CVE-2024-34203</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setLanguageCfg" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34204" target="_blank">CVE-2024-34204</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setUpgradeFW" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the download_firmware function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34205" target="_blank">CVE-2024-34205</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/download_firmware" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34206" target="_blank">CVE-2024-34206</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setWebWlanIdx" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setStaticDhcpConfig function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34207" target="_blank">CVE-2024-34207</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setStaticDhcpConfig" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFilterRules function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34209" target="_blank">CVE-2024-34209</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/setIpPortFilterRules" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the CloudACMunualUpdate function via the FileName parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34210" target="_blank">CVE-2024-34210</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/CloudACMunualUpdate_injection" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34211" target="_blank">CVE-2024-34211</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/HardCodeRoot" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34212" target="_blank">CVE-2024-34212</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/CloudACMunualUpdate_overflow" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the SetPortForwardRules function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34213" target="_blank">CVE-2024-34213</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/SetPortForwardRules" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilterRules function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34215" target="_blank">CVE-2024-34215</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/SetUrlFilterRules" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfileClientMode function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34217" target="_blank">CVE-2024-34217</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/addWlProfileClientMode" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34218" target="_blank">CVE-2024-34218</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/NTPSyncWithHost" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34219" target="_blank">CVE-2024-34219</a><br><a href="https://github.com/n0wstr/IOTVuln/tree/main/CP450/SetTelnetCfg" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34220" target="_blank">CVE-2024-34220</a><br><a href="https://github.com/dovankha/CVE-2024-34220" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34221" target="_blank">CVE-2024-34221</a><br><a href="https://github.com/dovankha/CVE-2024-34221" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34222" target="_blank">CVE-2024-34222</a><br><a href="https://github.com/dovankha/CVE-2024-34222" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow attackers to approve or reject leave ticket.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34223" target="_blank">CVE-2024-34223</a><br><a href="https://github.com/dovankha/CVE-2024-34223" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34224" target="_blank">CVE-2024-34224</a><br><a href="https://github.com/dovankha/CVE-2024-34224" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34225" target="_blank">CVE-2024-34225</a><br><a href="https://github.com/dovankha/CVE-2024-34225" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&amp;id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34226" target="_blank">CVE-2024-34226</a><br><a href="https://github.com/dovankha/CVE-2024-34226" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Information parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34230" target="_blank">CVE-2024-34230</a><br><a href="https://github.com/Amrita2000/CVES/blob/main/CVE-2024-34230.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Short Name parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34231" target="_blank">CVE-2024-34231</a><br><a href="https://github.com/Amrita2000/CVES/blob/main/CVE-2024-34231.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript payload using the admin web interface when creating new courses and new course notifications.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34241" target="_blank">CVE-2024-34241</a><br><a href="https://grumpz.net/cve-2024-34241-a-step-by-step-discovery-guide" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34243" target="_blank">CVE-2024-34243</a><br><a href="https://github.com/JByteL/CVE/tree/main/CVE-2024-34243" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in makehtml_js_action.php.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34245" target="_blank">CVE-2024-34245</a><br><a href="https://github.com/Stoocea/Vulnerability-analysis-Notes/blob/main/cms/DedeCMS-V5.7.114%20%20Arbitrary%20file%20read%20vulnerability.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34256" target="_blank">CVE-2024-34256</a><br><a href="https://github.com/ZackSecurity/VulnerReport/blob/cve/ofcms/1.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34273" target="_blank">CVE-2024-34273</a><br><a href="https://github.com/chrisandoryan/vuln-advisory/blob/main/nJwt/CVE-2024-34273.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34308" target="_blank">CVE-2024-34308</a><br><a href="https://github.com/s4ndw1ch136/IOT-vuln-reports/blob/main/totolink%20LR350/README.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34310" target="_blank">CVE-2024-34310</a><br><a href="https://github.com/3309899621/CVE-2024-34310" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A Blind command injection vulnerability in Tenda O3V2 V1.0.0.12 and earlier allows remote attackers to execute operating system commands via dest parameter in /goform/getTraceroute</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34338" target="_blank">CVE-2024-34338</a><br><a href="http://exzettabyte.me/blind-command-injection-in-tenda-o3v2" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with xmllint --htmlout can result in a buffer over-read in xmlHTMLPrintFileContext in xmllint.c.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34459" target="_blank">CVE-2024-34459</a><br><a href="https://gitlab.gnome.org/GNOME/libxml2/-/issues/720" target="_blank">cve@mitre.org</a><br><a href="https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.11.8" target="_blank">cve@mitre.org</a><br><a href="https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.12.7" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Sunhillo SureLine through 8.10.0 on RICI 5000 devices allows cgi/usrPasswd.cgi userid_change XSS within the Forgot Password feature.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34582" target="_blank">CVE-2024-34582</a><br><a href="https://github.com/silent6trinity/CVE-2024-34582" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34899" target="_blank">CVE-2024-34899</a><br><a href="https://hackerdna.com/courses/cve/cve-2024-34899" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>FlyFish v3.0.0 was discovered to contain a buffer overflow via the password parameter on the login page. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34905" target="_blank">CVE-2024-34905</a><br><a href="https://github.com/CloudWise-OpenSource/FlyFish/issues/191" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a crafted PDF file.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34906" target="_blank">CVE-2024-34906</a><br><a href="https://github.com/kuaifan/dootask/issues/210" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file upload vulnerability in KYKMS v1.0.1 and below allows attackers to execute arbitrary code via uploading a crafted PDF file.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34909" target="_blank">CVE-2024-34909</a><br><a href="https://github.com/Joying-C/Cross-site-scripting-vulnerability/tree/main/KYKMS_Cross_site%20_scripting%20_vulnerability" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file upload vulnerability in r-pan-scaffolding v5.0 and below allows attackers to execute arbitrary code via uploading a crafted PDF file.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34913" target="_blank">CVE-2024-34913</a><br><a href="https://github.com/Joying-C/Cross-site-scripting-vulnerability/tree/main/r-pan-scaffolding_Cross_site%20_scripting%20_vulnerability" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>php-censor v2.1.4 and fixed in v.2.1.5 was discovered to utilize a weak hashing algorithm for its remember_key value. This allows attackers to bruteforce to bruteforce the remember_key value to gain access to accounts that have checked "remember me" when logging in.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34914" target="_blank">CVE-2024-34914</a><br><a href="https://chmod744.super.site/redacted-vulnerability" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay Online E-Learning System using PHP/MySQL v1.0 allows attackers to execute arbitrary code via uploading a crafted file.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34919" target="_blank">CVE-2024-34919</a><br><a href="https://github.com/CveSecLook/cve/issues/20" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34921" target="_blank">CVE-2024-34921</a><br><a href="https://github.com/cainiao159357/x5000r_poc/blob/main/README.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/exeCommand.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34942" target="_blank">CVE-2024-34942</a><br><a href="https://palm-vertebra-fe9.notion.site/formexeCommand-200db77a90d34c708b903c935c7c65c0" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34943" target="_blank">CVE-2024-34943</a><br><a href="https://palm-vertebra-fe9.notion.site/fromNatStaticSetting-fae26e1bfbe64b49a46230a629b6d198" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34944" target="_blank">CVE-2024-34944</a><br><a href="https://www.tendacn.com/hk/download/detail-2344.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW parameter at ip/goform/WizardHandle.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34945" target="_blank">CVE-2024-34945</a><br><a href="https://palm-vertebra-fe9.notion.site/fromWizardHandle-98e188c072984620a907ea5df0d80ad5" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34946" target="_blank">CVE-2024-34946</a><br><a href="https://palm-vertebra-fe9.notion.site/fromDhcpListClient_page-c9ee71f670534555a5ef2d99320da48e" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>D-Link DIR-822+ v1.0.5 was discovered to contain a stack-based buffer overflow vulnerability in the SetNetworkTomographySettings module.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34950" target="_blank">CVE-2024-34950</a><br><a href="https://dear-sunshine-ba5.notion.site/D-Link-DIR-822-v1-0-5-Stack-Overflow-e77ff3d9c31f4a98bfa0fa71eca54000" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Code-projects Budget Management 1.0 is vulnerable to Cross Site Scripting (XSS) via the budget parameter.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34954" target="_blank">CVE-2024-34954</a><br><a href="https://github.com/ethicalhackerNL/CVEs/blob/main/Budget%20Management/XSS/XSS.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34955" target="_blank">CVE-2024-34955</a><br><a href="https://github.com/ethicalhackerNL/CVEs/blob/main/Budget%20Management/SQLi.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/sysImages_deal.php?mudi=infoSet.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34957" target="_blank">CVE-2024-34957</a><br><a href="https://github.com/Gr-1m/cms/blob/main/1.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/banner_deal.php?mudi=add</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34958" target="_blank">CVE-2024-34958</a><br><a href="https://github.com/Gr-1m/cms/blob/main/2.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34959" target="_blank">CVE-2024-34959</a><br><a href="https://gitee.com/upgogo/s123/issues/I9MARO" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34974" target="_blank">CVE-2024-34974</a><br><a href="https://github.com/hunzi0/Vullnfo/tree/main/Tenda/AC18/formSetPPTPServer" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploading a crafted file.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34982" target="_blank">CVE-2024-34982</a><br><a href="https://github.com/n2ryx/CVE/blob/main/Lylme_pagev1.9.5.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>joblib v1.4.2 was discovered to contain a deserialization vulnerability via the component joblib.numpy_pickle::NumpyArrayWrapper().read_array().</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-34997" target="_blank">CVE-2024-34997</a><br><a href="https://github.com/joblib/joblib/issues/1582" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&amp;dataType=&amp;fieldName=state&amp;fieldName2=state&amp;tabName=banner&amp;dataID=6.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35009" target="_blank">CVE-2024-35009</a><br><a href="https://github.com/Thirtypenny77/cms/blob/main/5.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/banner_deal.php?mudi=del&amp;dataType=&amp;dataTypeCN=%E5%9B%BE%E7%89%87%E5%B9%BF%E5%91%8A&amp;theme=cs&amp;dataID=6.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35010" target="_blank">CVE-2024-35010</a><br><a href="https://github.com/Thirtypenny77/cms/blob/main/6.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=rev&amp;nohrefStr=close.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35011" target="_blank">CVE-2024-35011</a><br><a href="https://github.com/Thirtypenny77/cms/blob/main/8.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mudi=add&amp;nohrefStr=close.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35012" target="_blank">CVE-2024-35012</a><br><a href="https://github.com/Thirtypenny77/cms/blob/main/7.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/tplSys_deal.php?mudi=area.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35039" target="_blank">CVE-2024-35039</a><br><a href="https://github.com/ywf7678/cms/blob/main/1.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35048" target="_blank">CVE-2024-35048</a><br><a href="https://github.com/javahuang/SurveyKing/issues/56" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35049" target="_blank">CVE-2024-35049</a><br><a href="https://github.com/javahuang/SurveyKing/issues/55" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was deleted by an Admin.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35050" target="_blank">CVE-2024-35050</a><br><a href="https://github.com/javahuang/SurveyKing/issues/57" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35099" target="_blank">CVE-2024-35099</a><br><a href="https://github.com/s4ndw1ch136/IOT-vuln-reports/blob/main/V9.3.5u.6698_B20230810/README.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Insecure Permissions vulnerability in VITEC AvediaServer (Model avsrv-m8105) 8.6.2-1 allows a remote attacker to escalate privileges via a crafted script.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35102" target="_blank">CVE-2024-35102</a><br><a href="https://vuln2you.blogspot.com/2024/05/avediaserver-unauthorised-api-access.html" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/homePro_deal.php?mudi=del&amp;dataType=&amp;dataTypeCN.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35108" target="_blank">CVE-2024-35108</a><br><a href="https://github.com/FirstLIF/cms/blob/main/1.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /homePro_deal.php?mudi=add&amp;nohrefStr=close.</td>
<td>2024-05-15</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35109" target="_blank">CVE-2024-35109</a><br><a href="https://github.com/FirstLIF/cms/blob/main/2.md" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35110" target="_blank">CVE-2024-35110</a><br><a href="https://github.com/yzmcms/yzmcms/issues/68" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Veritas System Recovery before 23.2_Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus low-privileged users can conduct attacks.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35204" target="_blank">CVE-2024-35204</a><br><a href="https://www.veritas.com/content/support/en_US/article.100065391" target="_blank">cve@mitre.org</a><br><a href="https://www.veritas.com/support/en_US/security/VTS24-005" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them through external application interactions, leading to a form of path traversal. This potentially enables any application to dispatch a crafted library file, aiming to overwrite an existing native library utilized by WPS Office. Successful exploitation could result in the execution of arbitrary commands under the guise of WPS Office's application ID.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35205" target="_blank">CVE-2024-35205</a><br><a href="https://www.microsoft.com/en-us/security/blog/2024/05/01/dirty-stream-attack-discovering-and-mitigating-a-common-vulnerability-pattern-in-android-apps/" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In Tor Arti before 1.2.3, STUB circuits incorrectly have a length of 2 (with lite vanguards), aka TROVE-2024-003.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35312" target="_blank">CVE-2024-35312</a><br><a href="https://gitlab.torproject.org/tpo/core/arti/-/issues/1409" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>In Tor Arti before 1.2.3, circuits sometimes incorrectly have a length of 3 (with full vanguards), aka TROVE-2024-004.</td>
<td>2024-05-17</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-35313" target="_blank">CVE-2024-35313</a><br><a href="https://gitlab.torproject.org/tpo/core/arti/-/issues/1400" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>question_image.ts in SurveyJS Form Library before 1.10.4 allows contentMode=youtube XSS via the imageLink property.</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-36043" target="_blank">CVE-2024-36043</a><br><a href="https://github.com/surveyjs/survey-library/commit/b25fbf0efd4486dc55f836240bebc2305803b96d" target="_blank">cve@mitre.org</a><br><a href="https://github.com/surveyjs/survey-library/issues/8286" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-36048" target="_blank">CVE-2024-36048</a><br><a href="https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560317" target="_blank">cve@mitre.org</a><br><a href="https://codereview.qt-project.org/c/qt/qtnetworkauth/+/560368" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>n/a--n/a<br> </td>
<td>Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current source code with attacker-controlled source code by luring a maintainer into accepting a malicious pull request.</td>
<td>2024-05-18</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-36050" target="_blank">CVE-2024-36050</a><br><a href="https://github.com/NixOS/nix/issues/969" target="_blank">cve@mitre.org</a><br><a href="https://github.com/NixOS/ofborg/issues/68#issuecomment-2082789441" target="_blank">cve@mitre.org</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A stored Cross-Site Scripting (XSS) vulnerability exists in the parisneo/lollms-webui application due to improper validation of uploaded files in the profile picture upload functionality. Attackers can exploit this vulnerability by uploading malicious HTML files containing JavaScript code, which is executed when the file is accessed. This vulnerability is remotely exploitable via Cross-Site Request Forgery (CSRF), allowing attackers to perform actions on behalf of authenticated users and potentially leading to unauthorized access to sensitive information within the Lollms-webui application.</td>
<td>2024-05-14</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2299" target="_blank">CVE-2024-2299</a><br><a href="https://huntr.com/bounties/f1adaac0-b9ed-4093-a0f3-2d0a4ecba398" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary code. The vulnerability arises due to insufficient sanitization of user-supplied input in the configuration settings, specifically within the 'extensions' parameter. Attackers can exploit this by crafting a payload that includes relative path traversal sequences ('../../../'), enabling them to navigate to arbitrary directories. This flaw subsequently allows the server to load and execute a malicious '__init__.py' file, leading to remote code execution. The issue affects the latest version of parisneo/lollms-webui.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2358" target="_blank">CVE-2024-2358</a><br><a href="https://huntr.com/bounties/b2771df3-be50-45bd-93c4-0974ce38bc22" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization of user-supplied input. Specifically, the issue resides in the `install_model()` function within `lollms_core/lollms/binding.py`, where the application fails to properly sanitize the `file://` protocol and other inputs, leading to arbitrary read and upload capabilities. Attackers can exploit this vulnerability by manipulating the `path` and `variant_name` parameters to achieve path traversal, allowing for the reading of arbitrary files and uploading files to arbitrary locations on the server. This vulnerability affects the latest version of parisneo/lollms-webui.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2361" target="_blank">CVE-2024-2361</a><br><a href="https://huntr.com/bounties/cd383817-924a-445a-838e-d0c867c6a176" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding functionality in lollms_core/lollms/server/endpoints/lollms_binding_infos.py of the latest version. The vulnerability arises due to insufficient path sanitization, allowing an attacker to exploit path traversal to navigate to arbitrary directories. By manipulating the binding_path to point to a controlled directory and uploading a malicious __init__.py file, an attacker can execute arbitrary code on the server.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-2366" target="_blank">CVE-2024-2366</a><br><a href="https://huntr.com/bounties/63266c77-408b-45ff-962c-8163db50a864" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A command injection vulnerability exists in the 'run_xtts_api_server' function of the parisneo/lollms-webui application, specifically within the 'lollms_xtts.py' script. The vulnerability arises due to the improper neutralization of special elements used in an OS command. The affected function utilizes 'subprocess.Popen' to execute a command constructed with a Python f-string, without adequately sanitizing the 'xtts_base_url' input. This flaw allows attackers to execute arbitrary commands remotely by manipulating the 'xtts_base_url' parameter. The vulnerability affects versions up to and including the latest version before 9.5. Successful exploitation could lead to arbitrary remote code execution (RCE) on the system where the application is deployed.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3126" target="_blank">CVE-2024-3126</a><br><a href="https://github.com/parisneo/lollms-webui/commit/41dbb1b3f2e78ea276e5269544e50514252c0c25" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/0e2bec70-826e-4c24-8015-31921e23fd12" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest release before 9.5. The vulnerability arises due to insufficient sanitization of the 'config' parameter in the 'apply_settings' function, allowing an attacker to manipulate the application's configuration by sending specially crafted JSON payloads. This could lead to remote code execution (RCE) by bypassing existing patches designed to mitigate such vulnerabilities.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-3435" target="_blank">CVE-2024-3435</a><br><a href="https://github.com/parisneo/lollms-webui/commit/bb99b59e710d00c4f2598faa5e183fa30fbd3bc2" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/494f349a-8650-4d30-a0bd-4742fda44ce5" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. By manipulating the `category` parameter, an attacker can traverse the directory structure and list any directory on the system. This issue affects the latest version of the application. The vulnerability is due to improper handling of user-supplied input in the `list_personalities` function, where the `category` parameter can be controlled to specify arbitrary directories for listing. Successful exploitation of this vulnerability could allow an attacker to list all folders in the drive on the system, potentially leading to information disclosure.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4322" target="_blank">CVE-2024-4322</a><br><a href="https://huntr.com/bounties/5116d858-ce00-418c-a5a5-851c5608c209" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms-webui<br> </td>
<td>A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and `/execute_code` endpoints. Attackers can bypass protections by setting the host to localhost, enabling code execution, and disabling code validation through the `/apply_settings` endpoint. Subsequently, arbitrary commands can be executed remotely via the `/execute_code` endpoint, exploiting the delay in settings enforcement. This issue was addressed in version 9.5.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4326" target="_blank">CVE-2024-4326</a><br><a href="https://github.com/parisneo/lollms-webui/commit/abb4c6d495a95a3ef5b114ffc57f85cd650b905e" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/2ab9f03d-0538-4317-be21-0748a079cbdd" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>parisneo--parisneo/lollms<br> </td>
<td>A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code execution due to insufficient sanitization of user input. The issue arises from the lack of path sanitization when handling the `name` parameter in the `unInstall_binding` function, allowing an attacker to traverse directories and execute arbitrary code by loading a malicious `__init__.py` file. This vulnerability affects the latest version of the software. The exploitation of this vulnerability could lead to remote code execution on the system where parisneo/lollms is deployed.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4078" target="_blank">CVE-2024-4078</a><br><a href="https://github.com/parisneo/lollms/commit/7ebe08da7e0026b155af4f7be1d6417bc64cf02f" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/a55a8c04-df44-49b2-bcfa-2a2b728a299d" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>run-llama--run-llama/llama_index<br> </td>
<td>A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI to connect to Language Learning Models (LLMs). The vulnerability arises from the improper use of the eval function, allowing a malicious or compromised LLM hosting provider to execute arbitrary commands on the client's machine. This issue was fixed in version 0.10.13. The exploitation of this vulnerability could lead to a hosting provider gaining full control over client machines.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4181" target="_blank">CVE-2024-4181</a><br><a href="https://github.com/run-llama/llama_index/commit/d73715eaf0642705583e7897c78b9c8dd2d3a7ba" target="_blank">security@huntr.dev</a><br><a href="https://huntr.com/bounties/1a204520-598a-434e-b13d-0d34f2a5ddc1" target="_blank">security@huntr.dev</a></td>
</tr>
<tr>
<td>wandb--wandb/wandb<br> </td>
<td>A Server-Side Request Forgery (SSRF) vulnerability exists in the wandb/wandb repository due to improper handling of HTTP 302 redirects. This issue allows team members with access to the 'User settings -&gt; Webhooks' function to exploit this vulnerability to access internal HTTP(s) servers. In severe cases, such as on AWS instances, this could potentially be abused to achieve remote code execution on the victim's machine. The vulnerability is present in the latest version of the repository.</td>
<td>2024-05-16</td>
<td>not yet calculated</td>
<td><a href="https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-4642" target="_blank">CVE-2024-4642</a><br><a href="https://huntr.com/bounties/055eb540-57f8-46d6-b858-3a9e22d347d9" target="_blank">security@huntr.dev</a></td>
</tr>
</tbody>
</table>
<p><a href="https://www.cisa.gov/#top">Back to top</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Entwicklertagebuch MyLife #3: Was’n Blazor WASM?]]></title>
<description><![CDATA[In den ersten beiden Teilen dieser Reihe haben wir uns mit der Generierung der Datenstruktur unseres digitalen Lebens beschäftigt. Nun ist es am der Zeit, uns an die Anzeige dieser zu machen. Als erstes hierfür versuchen wir uns an Blazor WebAssembly, kurz Blazor WASM. Für alle, denen diese Artik...]]></description>
<link>https://tsecurity.de/de/2140658/it-nachrichten/entwicklertagebuch-mylife-3-wasn-blazor-wasm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2140658/it-nachrichten/entwicklertagebuch-mylife-3-wasn-blazor-wasm/</guid>
<pubDate>Thu, 09 May 2024 23:46:49 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img src="https://www.drwindows.de/news/wp-content/uploads/2025/05/MyLife.Net-SoMe-720x360.png" class="attachment-single-thumb size-single-thumb wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.drwindows.de/news/wp-content/uploads/2025/05/MyLife.Net-SoMe-720x360.png 720w, https://www.drwindows.de/news/wp-content/uploads/2025/05/MyLife.Net-SoMe-300x150.png 300w, https://www.drwindows.de/news/wp-content/uploads/2025/05/MyLife.Net-SoMe-1024x512.png 1024w, https://www.drwindows.de/news/wp-content/uploads/2025/05/MyLife.Net-SoMe-768x384.png 768w, https://www.drwindows.de/news/wp-content/uploads/2025/05/MyLife.Net-SoMe-643x322.png 643w, https://www.drwindows.de/news/wp-content/uploads/2025/05/MyLife.Net-SoMe.png 1280w" sizes="(max-width: 720px) 100vw, 720px"></div>In den ersten beiden Teilen dieser Reihe haben wir uns mit der Generierung der Datenstruktur unseres digitalen Lebens beschäftigt. Nun ist es am der Zeit, uns an die Anzeige dieser zu machen. Als erstes hierfür versuchen wir uns an Blazor WebAssembly, kurz Blazor WASM. Für alle, denen diese Artikelreihe noch unbekannt ist – das habt […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Android Support for Kotlin Multiplatform to Share Business Logic Across Mobile, Web, Server, and Desktop Platforms]]></title>
<description><![CDATA[Posted by Maru Ahues Bouza – Director, Product Management, and Jeffrey van Gogh – Director, Engineering




Traditionally, developers must either write code individually for each platform they want to target, or make a number of compromises in order to reuse code across platforms.  Android has be...]]></description>
<link>https://tsecurity.de/de/2136944/android-tipps/android-support-for-kotlin-multiplatform-to-share-business-logic-across-mobile-web-server-and-desktop-platforms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2136944/android-tipps/android-support-for-kotlin-multiplatform-to-share-business-logic-across-mobile-web-server-and-desktop-platforms/</guid>
<pubDate>Mon, 06 May 2024 16:14:25 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<img src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEghr-7IZVE8USRGsSdWW2t6B8XPpcRtpq32qzgTS2h-nER09-_zUGP3YMtZszJwOLeyNVufbJZNqryAMmt-7fS5kUOX6D09WrbxmAMwyFj8hOrgWaPE-E-fyryL7tNQSW163L9FqQFWGv_OtGDS95yves1cV3bpkQXAy77gIsm0u2sZPeJK78fEdQCMlac/s1600/Kotlin-Android-KMP-support-metacard-3.png">

<em>Posted by Maru Ahues Bouza – Director, Product Management, and Jeffrey van Gogh – Director, Engineering</em>

<a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgaziKHPDi-lU9XBgPSwip4VGn66K9Nh9NTiX3NVBieZWINs3IFqmu1bTJGojxSVktO7U2mVp6KjtcNTMWVUN8jBBDb7-7r5oJpoWJX6uRluGQot0OPKPDQVQjH3KDPKo1A6hMfYuAdBJgF4W6Fjbvi7LzR6cY8ps2s2yLgsVYi7e36cHC8n40Z20A8DI4/s1600/Kotlin-Android-KMP-support-banner-3.png"><img border="0" data-original-height="800" data-original-width="100%" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgaziKHPDi-lU9XBgPSwip4VGn66K9Nh9NTiX3NVBieZWINs3IFqmu1bTJGojxSVktO7U2mVp6KjtcNTMWVUN8jBBDb7-7r5oJpoWJX6uRluGQot0OPKPDQVQjH3KDPKo1A6hMfYuAdBJgF4W6Fjbvi7LzR6cY8ps2s2yLgsVYi7e36cHC8n40Z20A8DI4/s1600/Kotlin-Android-KMP-support-banner-3.png"></a>

<p>
Traditionally, developers must either write code individually for each platform they want to target, or make a number of compromises in order to reuse code across platforms.  Android has been actively supporting Kotlin since 2017, and today we are excited to announce <strong>we are supporting Kotlin Multiplatform on Android</strong>, which enables sharing code across mobile, web, server, and desktop platforms.  This helps increase productivity for developers, and fits great with Android's <a href="https://developer.android.com/kotlin/first" target="_blank">Kotlin-first</a> approach, resulting in higher quality Android apps.  Our focus is to support sharing business logic (the parts that are most agnostic to the user interfaces) because we've seen Android developers get the most value in not having to maintain duplicate copies of this code.
</p>

<p>
Kotlin Multiplatform (KMP) has been a long-standing investment for the team behind Google Workspace, allowing for flexibility and speed in delivering valuable cross-platform experiences. The Google Workspace team is enthusiastic about KMP's potential as the direction for its multi-platform architecture investment, confident in its ability to meet performance expectations for various workloads.
</p>

<p>
The initial step in this journey is the rollout of the Google Docs app for Android, iOS, and Web, which leverages KMP for shared business logic, validating its readiness for production use at Google scale. The Google Workspace team is thrilled to continue exploring the possibilities of KMP across its product suite, aiming to enhance productivity and deliver seamless experiences to users on all platforms.
</p>

<p>
We see a lot of companies successfully leveraging Kotlin Multiplatform for cross-platform development of their apps, learn how they apply different code-sharing strategies <a href="https://www.jetbrains.com/help/kotlin-multiplatform-dev/case-studies.html" target="_blank">here</a>.</p>

<p>
Kotlin Multiplatform, developed by JetBrains, provides a novel approach to sharing code across platforms by compiling Kotlin to platform-native binaries. Kotlin is able to provide the full, modern, memory managed language to native platforms enabling native interoperability and incremental adoption. Kotlin on Android, combined with Kotlin Multiplatform on other platforms, provides a great way to increase productivity and quality, without compromising on performance or interoperability.
</p>

<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAZ35Bb74cH_YV_sUjFwh2qsiMCpG-P-YV4S8DQon88Gs9nF3kiX_57ubTLCcx-B_gDAS2w8o_9layOVtFohOJRSW_o_PNN_x-9IDOpHWRiNXRIbjF9h7ca9uRyZ0E6k914DtGZNhouU2yY7-bL0FHJX4D5mawqEluxMotvLYgM68ouddlrEatZXzmbs/s1600/image1.png"><img alt="Architecture overview for Kotlin Multiplatform (KMP)" border="0" data-original-height="959" data-original-width="1999" height="307" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdAZ35Bb74cH_YV_sUjFwh2qsiMCpG-P-YV4S8DQon88Gs9nF3kiX_57ubTLCcx-B_gDAS2w8o_9layOVtFohOJRSW_o_PNN_x-9IDOpHWRiNXRIbjF9h7ca9uRyZ0E6k914DtGZNhouU2yY7-bL0FHJX4D5mawqEluxMotvLYgM68ouddlrEatZXzmbs/w640-h307/image1.png" width="640"></a></div>
<i><div><i>Kotlin Multiplatform Architecture</i></div></i>
<br>

<h3>Current Status of Support</h3>

<p>
Many widely-used libraries offer built-in support for Kotlin Multiplatform, streamlining your cross-platform development experience. These libraries work seamlessly together. For example, <a href="https://ktor.io/" target="_blank">Ktor</a> simplifies networking tasks by handling REST service consumption, while <a href="https://kotlinlang.org/docs/serialization.html" target="_blank">kotlinx.serialization</a> converts data to formats like JSON, and <a href="https://square.github.io/okio/" target="_blank">Okio</a> manages essential file I/O. Additionally, <a href="https://skie.touchlab.co/" target="_blank">SKIE</a> facilitates the use of modern types and coroutines on iOS, and <a href="https://cocoapods.org/" target="_blank">CocoaPods</a> integration enables the use of iOS-specific dependencies.
</p>

<p>
We've worked with JetBrains and the Kotlin developer community to add Kotlin Multiplatform support to a number of Jetpack libraries and in some cases provide the iOS platform targets, while in others, JetBrains and the community provide the multiplatform distributions.  
</p>

<p>
Today, the Annotations, Collections, and DataStore libraries all have support for Kotlin Multiplatform in stable versions. We are also adding support to validate binary compatibility for the iOS platform targets, bringing them on a par with the quality standards for Android. In addition to the libraries above, we've also begun working on Kotlin Multiplatform support for <a href="https://developer.android.com/kotlin/multiplatform/room" target="_blank">Room</a>, Lifecycle, and ViewModels with alpha versions now available. To better understand which classes and functions are available where, the library <a href="https://developer.android.com/reference/kotlin/androidx/collection/package-summary" target="_blank">reference documentation</a> now indicates "common" and platform support.
</p>

<div class="separator"><a href="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7S0CEVMRfrsVshYB_BYPiTNmfGiHBfUQXN5fY1JTAXwNwYo_bF1SnUGlw7ZmZ3L9EoM2DjHbHiBLo4kY78aomUT8perVMXBp-bMfDwiJ303kPI1MX-G5rocJSVfLhfP49YsYw166vaBMBwXazQyyKrx0ksym1rJXEuobymiutxeOkEzeWW5ny4Pw718k/s1600/image3.png"><img alt="Indication of Common, Native and Android support in documentation" border="0" data-original-height="959" data-original-width="1999" height="307" src="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7S0CEVMRfrsVshYB_BYPiTNmfGiHBfUQXN5fY1JTAXwNwYo_bF1SnUGlw7ZmZ3L9EoM2DjHbHiBLo4kY78aomUT8perVMXBp-bMfDwiJ303kPI1MX-G5rocJSVfLhfP49YsYw166vaBMBwXazQyyKrx0ksym1rJXEuobymiutxeOkEzeWW5ny4Pw718k/s1600/image3.png" width="640"></a></div>
<i><div><i>Indication of Common, Native and Android support in documentation</i></div></i>
<br>

<p>
Android engineers have collaborated with JetBrains on the Kotlin compiler to improve runtime performance in Kotlin/Native (for iOS &amp; native desktop operating systems), showing 18% runtime performance improvements in compiler benchmarks.  In addition the Android team contributed to build time performance improvements for the Kotlin Native Compiler of up to 2x speed ups.
</p>

<p>
The Android Gradle Plugin now has official support for Kotlin Multiplatform, enabling a concise build definition for setting up Android as a platform target for shared code as shown below:
</p>

<div><pre><span>plugins {
    id(<span>"org.jetbrains.kotlin.multiplatform"</span>)
    id(<span>"com.android.library"</span>)
}

kotlin {
    androidTarget {
        compilations.all {
            kotlinOptions {
                jvmTarget = <span>"11"</span>
            }
        }
    }  
    listOf(
        iosX64(),
        iosArm64(),
        iosSimulatorArm64()
    ).forEach { iosTarget -&gt;
        iosTarget.binaries.framework {
            baseName = <span>"Shared"</span>
            isStatic = <span>true</span>
        }
    }    
    sourceSets {
        commonMain.dependencies {
            <span>// put your Multiplatform dependencies here</span>
        }
    }
}</span>
</pre></div>
<i><div><i>KMP Support in the Android Gradle Plugin DSL</i></div></i>
<br>

<p>
As Android Studio is based on the IntelliJ Platform from JetBrains, it inherits support for Kotlin Multiplatform code editing and many other development features. Other Android development tools like Android Lint and Kotlin Symbol Processing (KSP) are also beginning to add more Kotlin Multiplatform support as well. 
</p>

<p>
Google Chrome now has official support for <a href="https://developer.chrome.com/blog/wasmgc/" target="_blank">WasmGC</a> which is used by Kotlin Multiplatform's WebAssembly platform target to enable code sharing with the browser in an efficient and performant way.
</p>

<p>
Latest details on these projects are available on the updated <a href="http://developer.android.com/kotlin/multiplatform" target="_blank">Android Kotlin Multiplatform page</a>.
</p>

<h3>Future Areas of Work</h3>

<p>
We've heard from many Android developers and Google engineering teams that they want expanded support for Kotlin Multiplatform so they can more easily share code with other platforms.  Android plans to continue collaborating with JetBrains, Google engineering teams, and the community on a variety of projects, including:
</p>

<ul><ul>
<li>Expanding and stabilizing Jetpack libraries with Kotlin Multiplatform support

</li><li>Wasm platform target support in Jetpack libraries

</li><li>Kotlin/Native build performance

</li><li>Kotlin/Native debugging

</li><li>Expanding Kotlin Multiplatform support in Android Studio
  </li></ul></ul>

<h3>Learn More and Try It Out</h3>

<p>
Sharing code with Kotlin Multiplatform between Android and other platforms enables higher developer productivity and quality so we hope you will give it a try!  You can use the <a href="https://kmp.jetbrains.com/?_gl=1*5pa7yg*_ga*NjYyMTIyNjYzLjE2NDYxNzI4MTQ.*_ga_9J976DJZ68*MTcxMjI2ODc4MC42OC4xLjE3MTIyNjkxMzQuNTAuMC4w&amp;_ga=2.19854524.527082860.1712264637-662122663.1646172814" target="_blank">Kotlin Multiplatform wizard</a> to create a new KMP project.  Learn more in the <a href="http://developer.android.com/kotlin/multiplatform" target="_blank">documentation</a>.
</p>

<p>
Alternatively, explore one of these sample projects showcasing how to use some of the Jetpack libraries with Kotlin Multiplatform:
</p>

<ul><ul>
<li><a href="https://github.com/android/kotlin-multiplatform-samples/tree/main/DiceRoller" target="_blank">DiceRoller</a> - DataStore on Android and iOS

</li><li><a href="https://github.com/android/kotlin-multiplatform-samples/tree/main/Fruitties" target="_blank">Fruitties</a> - Room, Datastore on Android and iOS
  </li></ul></ul>

<p>
If there are additional areas you would like Android to work on <a href="https://issuetracker.google.com/issues/new?component=1337890&amp;template=1803002" target="_blank">let us know</a> and also be a part of our vibrant Android Developer community on <a href="https://www.linkedin.com/showcase/androiddev/posts/?feedView=all" target="_blank">LinkedIn</a>, <a href="https://medium.com/androiddevelopers">Medium</a>, <a href="https://www.youtube.com/c/AndroidDevelopers/videos" target="_blank">YouTube</a>, and <a href="https://twitter.com/AndroidDev" target="_blank">X</a>.
</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-2887: A Pwn2Own Winning Bug in Google Chrome]]></title>
<description><![CDATA[In this guest blog from Master of Pwn winner Manfred Paul, he details CVE-2024-2887 – a type confusion bug that occurs in both Google Chrome and Microsoft Edge (Chromium). He used this bug as a part of his winning exploit that led to code execution in the renderer of both browsers. This bug was q...]]></description>
<link>https://tsecurity.de/de/2117468/hacking/cve-2024-2887-a-pwn2own-winning-bug-in-google-chrome/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2117468/hacking/cve-2024-2887-a-pwn2own-winning-bug-in-google-chrome/</guid>
<pubDate>Sat, 20 Apr 2024 20:49:05 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class=""><em>In this guest blog from Master of Pwn winner Manfred Paul, he details CVE-2024-2887 – a type confusion bug that occurs in both Google Chrome and Microsoft Edge (Chromium). He used this bug as a part of his winning exploit that led to code execution in the renderer of both browsers. This bug was quickly patched by both </em><a href="https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop_26.html"><em>Google</em></a><em> and </em><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-2887"><em>Microsoft</em></a><em>. Manfred has graciously provided this detailed write-up of the vulnerability and how ghe exploited it at the contest.</em></p>





















  
  



<hr><p>In this blog, I describe a means of exploiting the V8 JavaScript and WebAssembly engine to gain execution of arbitrary shellcode inside the renderer process. This includes a bypass of the V8 memory sandbox (<a href="https://docs.google.com/document/d/1FM4fQmIhEqPG8uGp5o9A-mnPB5BOeScZYpkHjo0KKA8/edit#heading=h.xzptrog8pyxf">Ubercage</a>), though code execution is still constrained by the process isolation-based browser sandbox. For demonstration purposes, this limitation can be removed by running the browser with the <code>--no- sandbox</code> flag. </p>
<p><b data-preserve-html-node="true">Root Cause of the WebAssembly Universal Type Confusion</b></p>
<p>A WebAssembly module may contain a <code>type</code> section that defines a list of custom “heap types”. In the base specification, this is used only to declare function types, but with the adoption of the garbage collection (GC) <a href="https://webassembly.github.io/gc/core/_download/WebAssembly.pdf">proposal</a> [PDF], this section can additionally define struct types, allowing for the use of composite, heap-allocated types in WebAssembly. </p>
<p>Normally, a struct declared in this section may only reference structs that precede it  (structs with a lower type index). To support mutually recursive data structures, a feature called recursive type groups is available. Instead of declaring the (potentially) mutually recursive types as individual entries in the type section, a recursive group is declared as a single type section entry. Within this group, individual types are declared, which are thereby allowed to reference each other.</p>
<p>With this in mind, consider the function responsible for parsing the <code>type</code> section from the binary WebAssembly format in <code>v8/src/wasm/module-decoder-impl.h</code>: </p>

<p>At (1), the limit <code>kV8MaxWasmTypes</code> (currently equal to 1,000,000) is passed as a maximum to <code>consume_count()</code>, ensuring that at most this many entries are read from the <code>type</code> section. When recursive type groups were added, this check became insufficient. While this code will permit only <code>kV8MaxWasmTypes</code> entries of the <code>type</code> section to be read, each of those can potentially be a recursive type group containing more than one individual type definition. </p>
<p>This insufficiency was clearly noticed at the time of this change, as together with recursive type groups a second check was added at (2). Here, for each recursive type group, it is checked that the addition of the constituent types would not exceed the <code>kV8MaxWasmTypes</code> limit. </p>
<p>However, this second check is still not enough. While it protects the indices of each type allocated inside a recursive group, the presence of those groups also has implications for types declared outside this group, as each recursive group adds to the total count of declared types. </p>
<p>To make this clearer, imagine a type section consisting of two entries: one recursive group containing<code>kV8MaxWasmTypes</code> entries, and following that group, one non-recursive type. The check at (1) is passed, as the section only has two entries. While processing the recursive group, the check at (2) is also passed, as the section has exactly <code>kV8MaxWasmTypes</code> entries. For the following single type, there is no further check: at (3) the type is simply allocated at the next free index. In this case, the index will be  <code>kV8MaxWasmTypes</code>, exceeding the usual maximum of <code>kV8MaxWasmTypes-1</code>. If there were more than one non-recursive type at the end of the <code>type</code> section, they would similarly get assigned <code>kV8MaxWasmTypes+1</code>, <code>kV8MaxWasmTypes+2</code>, and so forth, as type indices. </p>
<p><b data-preserve-html-node="true">Impact of the Root Cause</b></p>
<p>Exceeding the maximal number of declared heap types might seem like a very harmless resource exhaustion bug at first. However, due to some internal details of how V8 handles WebAssembly heap types, it directly allows constructing some very powerful exploit primitives. </p>
<p>In <code>v8/src/wasm/value-type.h</code>, the encoding of heap types is defined: </p>

<p>Here, V8 assumes that all user-defined heap types will be assigned indices smaller than <code>kV8MaxWasmTypes</code>. Larger indices are reserved for fixed, internal heap types (beginning with <code>kFunc</code>). This results in our own type declarations aliasing one of these internal types, leading to many opportunities for type confusion. </p>
<p><b data-preserve-html-node="true">Universal WebAssembly Type Confusion</b></p>
<p>To leverage this encoding ambiguity into a full type confusion, let’s first consider the <code>struct.new</code> opcode, which produces a reference to a new struct created from fields given on the stack. The caller specifies the desired struct type by passing its type index. The relevant check on the type index can be found in <code>v8/src/wasm/function-body-decoder-impl.h</code>:</p>

<p>Following the validation logic into the <code>has_struct()</code> method from <code>v8/src/wasm/wasm-module.h</code>: </p>

<p>Since we can make <code>types.size()</code>  exceed the usual limit of <code>kV8MaxWasmTypes</code>, we can make the check pass even if when passing an index larger than this value. This allows us to create a reference of an arbitrary internal type that points to the struct we can freely define. </p>
<p>On the other hand, consider now the handling of the <code>ref.cast</code> instruction: </p>

<p>Here, a <code>type</code> check elimination is performed. If <code>TypeCheckAlwaysSucceeds</code> returns true, then no actual <code>type</code> check is emitted and the value is simply reinterpreted as the target <code>type</code>.</p>
<p>The function <code>TypeCheckAlwaysSucceeds</code> ultimately calls <code>IsHeapSubtypeOfImpl</code> defined in <code>v8/src/wasm/wasm-subtyping.cc</code>:</p>

<p>This means that if our declared type index aliases the constant <code>HeapType::kNone</code>, the type check will always be elided if we cast to any non-function, non-external reference. In combination, we can use this to turn any reference type into any other by the following steps: </p>
<ol>
<li><p>   In the type section, define a structure type with a single field of type <code>anyref</code>, and make this struct have a type index equal to <code>HeapType::kNone</code> using the bug described above. </p>
</li>
<li><p>   Place a non-null reference value of any type on the top of the stack and call <code>struct.new</code> with the type index set to <code>HeapType::kNone</code>. This will succeed, as <code>has_struct()</code> validates the index against the index established via the previous step. </p>
</li>
<li><p>   Also, declare a struct with a normal type index lower than <code>kV8MaxWasmTypes</code> with a single field of the target reference type. Call <code>ref.cast</code> with this  this struct’s type index. The engine will not perform any type check, as the input value is at this point understood to be reference type <code>HeapType::kNone</code>.</p>
</li>
<li><p>   Finally, read back the reference stored in the struct by executing <code>struct.get</code>.</p>
</li>
</ol>
<p>This arbitrary casting of reference types allows transmuting any value type into any other by referencing it, changing the reference type, and then dereferencing it – a universal type confusion. </p>
<p>In particular, this directly contains nearly all usual JavaScript engine exploitation primitives as special cases:</p>
<p>•	Transmuting <code>int</code> to <code>int*</code> and then dereferencing results in an arbitrary read.</p>
<p>•	Transmuting <code>int</code> to <code>int*</code> and then writing to that reference results in an arbitrary write.</p>
<p>•	Transmuting <code>externref</code>to <code>int</code> is the <code>addrOf()</code> primitive, obtaining the address of a JavaScript object.</p>
<p>•	Transmuting <code>int</code> to <code>externref</code> is the <code>fakeObj()</code> primitive, forcing the engine to treat an arbitrary value as a pointer to a JavaScript object. </p>
<p>While casting from <code>HeapType::kNone</code> to an <code>externref</code> is not allowed, remember that we are actually operating on one more level of indirection - transmuting to <code>externref</code> involves casting to a reference to a struct containing one <code>externref</code> member.</p>
<p>Note however that these “arbitrary” reads and writes are still contained in the V8 memory sandbox, as all involved pointers to heap-allocated structures are tagged, compressed pointers inside the heap cage, not full 64-bit raw pointers. </p>
<p><b data-preserve-html-node="true">Integer Underflow Leading to V8 Sandbox Escape</b> </p>
<p>The primitives described above allow for freely manipulating and faking most JavaScript objects. However, all of this happens inside the limited memory space of the V8 sandbox. “Trusted” objects such as WebAssembly instance data cannot yet be manipulated. We will now turn our attention to a bug that can be used to escape the memory sandbox.</p>
<p>An often-used object for JavaScript engine exploits is <code>ArrayBuffer</code> and its corresponding views, (i.e. typed arrays), as it allows for direct, untagged access to some region of memory. </p>
<p>To prevent access to pointers outside the V8 sandbox, sandboxed pointers are used to designate a typed array’s corresponding backing store. Similarly, an ArrayBuffer’s length field is always loaded as a “bounded size access”, inherently limiting its value to a maximum of 235 − 1. </p>
<p>However, in modern JavaScript, the handling of typed arrays has become quite complex due to the introduction of resizable ArrayBuffers (RABs) and their sharable variant, growable SharedArrayBuffers (GSABs). Both variants feature the ability to change their length after the object has been created with the shared variant being restricted to never shrink. In particular, for typed arrays with these kinds of buffers, the array length can never be cached and must be recomputed on each access.</p>
<p>Additionally, ArrayBuffers also feature an offset field, describing the start of the data in the 
actual underlying backing store. This offset must be taken into account when computing the length. </p>
<p>Let’s now look at the code responsible for building a TypedArray’s length access in the optimizing Turbofan compiler. It can be found in <code>v8/src/compiler/graph-assembler.cc</code>. Note that most non-RAB/GSAB cases and the code responsible for dispatching are omitted for simplicity: </p>

<p>For arrays backed by a resizable ArrayBuffer, we can see at (1) that the length is computed as <code>floor((byte_length - byte_offset) / element_size)</code>. Crucially, there is an underflow check. If <code>byte_offset</code> exceeds <code>byte_length</code>, then 0 is returned instead. </p>
<p>Curiously though, in the case of a GSAB-backed array, the corresponding underflow check is missing. Thus, if <code>byte_offset</code> is larger than <code>byte_length</code>, an underflow occurs and the subtraction wraps around to something close to the maximum unsigned 64-bit integer 264. As both of these fields are found in the (by now) attacker-controlled array object, we can easily trigger this using the sandboxed arbitrary read/write primitives discussed previously. This results in access to the whole 64-bit address space, as the length computed by this function is used to bound any typed array accesses (in JIT-compiled code). </p>
<p><b data-preserve-html-node="true">Exploitation for Arbitrary Shellcode Execution</b></p>
<p>Using the two bugs described above, exploitation becomes fairly straightforward. The primitives described in the Universal WebAssembly Type Confusion section directly give arbitrary reads and writes within the V8 memory sandbox. This can then be used to manipulate a growable <code>SharedArrayBuffer</code> to have an offset greater than its length. A previously JIT-compiled read/write function can then be used to access and overwrite data anywhere in the process’s address space. An appropriate target for overwrite is the compiled code of a <code>WebAssembly</code> module, since that resides in an RWX (read-write-execute) page and can be overwritten with shellcode.</p>

<hr>


  <p class=""><em>Thanks again to Manfred for providing this thorough write-up. He has contributed multiple bugs to the ZDI program over the last few years, and we certainly hope to see more submissions from him in the future. Until then, follow the team on </em><a href="https://www.twitter.com/thezdi"><em>Twitter</em></a><em>, </em><a href="https://infosec.exchange/@thezdi"><em>Mastodon</em></a><em>, </em><a href="https://www.linkedin.com/company/zerodayinitiative"><em>LinkedIn</em></a><em>, or </em><a href="https://www.instagram.com/thezdi"><em>Instagram</em></a><em> for the latest in exploit techniques and security patches.</em></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-6747-2: Firefox regressions]]></title>
<description><![CDATA[USN-6747-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.

Original advisory details:

 Multiple security issues were discovered in Firefox. If a user were
 tricked into opening a specially crafted website, an attacker could
 pote...]]></description>
<link>https://tsecurity.de/de/2116263/unix-server/usn-6747-2-firefox-regressions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2116263/unix-server/usn-6747-2-firefox-regressions/</guid>
<pubDate>Sat, 20 Apr 2024 08:44:51 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[USN-6747-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.

Original advisory details:

 Multiple security issues were discovered in Firefox. If a user were
 tricked into opening a specially crafted website, an attacker could
 potentially exploit these to cause a denial of service, obtain sensitive
 information across domains, or execute arbitrary code. (CVE-2024-3852,
 CVE-2024-3864, CVE-2024-3865)
 
 Bartek Nowotarski discovered that Firefox did not properly limit HTTP/2
 CONTINUATION frames. An attacker could potentially exploit this issue to
 cause a denial of service. (CVE-2024-3302)
 
 Gary Kwong discovered that Firefox did not properly manage memory when
 running garbage collection during realm initialization. An attacker could
 potentially exploit this issue to cause a denial of service, or execute
 arbitrary code. (CVE-2024-3853)
 
 Lukas Bernhard discovered that Firefox did not properly manage memory
 during JIT optimisations, leading to an out-of-bounds read vulnerability.
 An attacker could possibly use this issue to cause a denial of service or
 expose sensitive information. (CVE-2024-3854, CVE-2024-3855)
 
 Nan Wang discovered that Firefox did not properly manage memory during
 WASM garbage collection. An attacker could potentially exploit this issue
 to cause a denial of service, or execute arbitrary code. (CVE-2024-3856)
 
 Lukas Bernhard discovered that Firefox did not properly manage memory
 when handling JIT created code during garbage collection. An attacker
 could potentially exploit this issue to cause a denial of service, or
 execute arbitrary code. (CVE-2024-3857)
 
 Lukas Bernhard discovered that Firefox did not properly manage memory when
 tracing in JIT. An attacker could potentially exploit this issue to cause
 a denial of service. (CVE-2024-3858)
 
 Ronald Crane discovered that Firefox did not properly manage memory in the
 OpenType sanitizer on 32-bit devices, leading to an out-of-bounds read 
 vulnerability. An attacker could possibly use this issue to cause a denial
 of service or expose sensitive information. (CVE-2024-3859)
 
 Garry Kwong discovered that Firefox did not properly manage memory when
 tracing empty shape lists in JIT. An attacker could potentially exploit 
 this issue to cause a denial of service. (CVE-2024-3860)
 
 Ronald Crane discovered that Firefox did not properly manage memory when
 handling an AlignedBuffer. An attacker could potentially exploit this 
 issue to cause denial of service, or execute arbitrary code. 
 (CVE-2024-3861)
 
 Ronald Crane discovered that Firefox did not properly manage memory when
 handling code in MarkStack. An attacker could possibly use this issue to
 cause a denial of service or execute arbitrary code. (CVE-2024-3862)]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux is dying; systemd and Kubernetes are both arguing/competing over who gets to kill it]]></title>
<description><![CDATA[What are you even on about, OP? The biggest problem with Linux as-is in this day and age is lack of Infrastructure as Code (IaC). Case in point, people are doing so much with their systems nowadays that they need some way to track and reverse all changes, and Linux (on its own) isn't built for th...]]></description>
<link>https://tsecurity.de/de/2114698/linux-tipps/linux-is-dying-systemd-and-kubernetes-are-both-arguingcompeting-over-who-gets-to-kill-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2114698/linux-tipps/linux-is-dying-systemd-and-kubernetes-are-both-arguingcompeting-over-who-gets-to-kill-it/</guid>
<pubDate>Thu, 18 Apr 2024 20:49:43 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><strong>What are you even on about, OP?</strong></p> <p>The biggest problem with Linux as-is in this day and age is lack of Infrastructure as Code (IaC). Case in point, people are doing so much with their systems nowadays that they need some way to track and reverse all changes, and Linux (on its own) isn't built for that... Now, everyone's looking to tack something onto Linux that makes it easier to automate, i.e., basically more dev-friendly.</p> <p><strong>Why is this even a problem?</strong></p> <p>In the old days, each server would be responsible for running only one or a handful of services, so it was fine for a sysadmin to ssh in and manually run whatever is needed. Obviously, this doesn't work at scale, so the first step was basic tools like Ansible and Chef to automate this process over an array of servers.</p> <p>However, as anyone who's ever worked with these knows, the problem with those is dealing with atomicity and state. Particularly, Ansible (as an example) has a procedural programming model, so you can't exactly <em>define</em> your desired state; you can only give a list of steps that you <em>think</em> will get it to said desired state, and you can only really find out in prod whether or not it's working as intended.</p> <p><strong>What have we tried so far?</strong></p> <p>The obvious solution to <em>this</em> problem is an inherently stateful system with an HTTP/s API (like <strong>Kubernetes</strong>), but the problem there is that most DevOps engineers don't want to deal with the complexity. There's quite a bit of "jerry-rigging" involved in getting stuff to work in Kubernetes that wasn't intended for it (although that's decreased over time), not to mention that YAML is meant for machines and therefore often hard for humans to audit.</p> <p>Some people like to tack on a programming language to all this and use Pulumi or something, which is one way to go, but then you're shifting the onus of deployment onto your developers (i.e., the only ones who <em>actually</em> know how to write code). Those guys usually have enough on their plate and generally don't appreciate the added responsibilities.</p> <p><strong>What's the alternative?</strong></p> <p>This gave rise to a whole class of DevOps engineers who believe that the stateless approach is the way to go. Modern-day <strong>systemd</strong> is intended for these people; basically, all they want is an init system for their processes on each server, and they're more than fine with systemd becoming bloated enough where it eventually subsumes the kernel as long as it helps them avoid containers and K8s.</p> <p>This is the line of thinking that also led to the creation of Nix/OS. The idea is to have a thin layer of programmability around systemd and other kernel subsystems so you can build a declarative init process. However, it remains here that NixOS is stateless, so you still need a separate solution to manage your state and especially secrets like TLS keys and so on.</p> <p><strong>I've heard enough, OP; it all sounds well and good, but where are you headed with all this?</strong></p> <p>Eventually, Linux itself is going to be subsumed or entirely replaced by a declarative application runtime that hides away all the actual infra (meaning the kernel, bootloader, etc.) so that everything happens automatically and no tech company has to actually look at it. You can look at <a href="https://talos.dev/">Talos Linux</a> as an example; it's basically a distribution of Linux, except it's designed only for running Kubernetes, and thus strips out systemd, ssh console, and other such "bloatware". As a developer, you should be able to use it to boot into Kubernetes itself and program the rest through an API rather than having to actually run Kubernetes with systemd or similar.</p> <p>Talos Linux, particularly, goes in the direction of turning Linux and K8s into one thing where your organization doesn't have to deal with Linux <em>separately</em> from K8s; everything gets done through a K8s or K8s-<em>like</em> API.</p> <p>Additionally, there's also a very convenient container image for NixOS, so you could also use Nix <em>within</em> a container to provide hermetically reproducible binary builds. This will also help <em>a lot</em> in becoming <em>truly</em> serverless and vendor-neutral.</p> <p><strong>So what does this all mean for me?</strong></p> <p>K8s is the future, which unfortunately most of us knew all along, but that doesn't mean that the past has already become irrelevant (or will become so in the near future). Rust/WASM is also a stakeholder in this, b/c you can probably use it to get rid of some K8s subsystems like runc or even containerd and replace it with smaller, more secure, and more performant code.</p> <p><strong>TL;DR:</strong> The past is fucking depressing, but the future is bright, folks! </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/tldrthestoryofmylife"> /u/tldrthestoryofmylife </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ch1xch/linux_is_dying_systemd_and_kubernetes_are_both/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ch1xch/linux_is_dying_systemd_and_kubernetes_are_both/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-6747-1: Firefox vulnerabilities]]></title>
<description><![CDATA[Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-3852,
CVE-2024-3864, CV...]]></description>
<link>https://tsecurity.de/de/2105296/unix-server/usn-6747-1-firefox-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2105296/unix-server/usn-6747-1-firefox-vulnerabilities/</guid>
<pubDate>Thu, 11 Apr 2024 18:24:09 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-3852,
CVE-2024-3864, CVE-2024-3865)

Bartek Nowotarski discovered that Firefox did not properly limit HTTP/2
CONTINUATION frames. An attacker could potentially exploit this issue to
cause a denial of service. (CVE-2024-3302)

Gary Kwong discovered that Firefox did not properly manage memory when
running garbage collection during realm initialization. An attacker could
potentially exploit this issue to cause a denial of service, or execute
arbitrary code. (CVE-2024-3853)

Lukas Bernhard discovered that Firefox did not properly manage memory
during JIT optimisations, leading to an out-of-bounds read vulnerability.
An attacker could possibly use this issue to cause a denial of service or
expose sensitive information. (CVE-2024-3854, CVE-2024-3855)

Nan Wang discovered that Firefox did not properly manage memory during
WASM garbage collection. An attacker could potentially exploit this issue
to cause a denial of service, or execute arbitrary code. (CVE-2024-3856)

Lukas Bernhard discovered that Firefox did not properly manage memory
when handling JIT created code during garbage collection. An attacker
could potentially exploit this issue to cause a denial of service, or
execute arbitrary code. (CVE-2024-3857)

Lukas Bernhard discovered that Firefox did not properly manage memory when
tracing in JIT. An attacker could potentially exploit this issue to cause
a denial of service. (CVE-2024-3858)

Ronald Crane discovered that Firefox did not properly manage memory in the
OpenType sanitizer on 32-bit devices, leading to an out-of-bounds read 
vulnerability. An attacker could possibly use this issue to cause a denial
of service or expose sensitive information. (CVE-2024-3859)

Garry Kwong discovered that Firefox did not properly manage memory when
tracing empty shape lists in JIT. An attacker could potentially exploit 
this issue to cause a denial of service. (CVE-2024-3860)

Ronald Crane discovered that Firefox did not properly manage memory when
handling an AlignedBuffer. An attacker could potentially exploit this 
issue to cause denial of service, or execute arbitrary code. 
(CVE-2024-3861)

Ronald Crane discovered that Firefox did not properly manage memory when
handling code in MarkStack. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2024-3862)]]></content:encoded>
</item>
<item>
<title><![CDATA[Für die Kubernetes-Community - SpinKube und Fermyon Platform]]></title>
<description><![CDATA[Zwei bahnbrechende Projekte bieten erstklassige Unterstützung für Spin-WebAssembly-(Wasm)-Anwendungen in Kubernetes, SpinKube und die Fermyon-Plattform.]]></description>
<link>https://tsecurity.de/de/2080028/android-tipps/fuer-die-kubernetes-community-spinkube-und-fermyon-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2080028/android-tipps/fuer-die-kubernetes-community-spinkube-und-fermyon-platform/</guid>
<pubDate>Thu, 21 Mar 2024 12:15:43 +0100</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Zwei bahnbrechende Projekte bieten erstklassige Unterstützung für Spin-WebAssembly-(Wasm)-Anwendungen in Kubernetes, SpinKube und die Fermyon-Plattform.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Chrome Zero-Day Patched Post-Pwn2Own March Exploits]]></title>
<description><![CDATA[Google Chrome Zero-Day Patched Post-Pwn2Own March Exploits
				
				
			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
				
				 Post Views: 1
			
			
				
				
				
				
				



			
			
				
				
				
				
			
				
				
				
				
				
				
				
				
				
				
		...]]></description>
<link>https://tsecurity.de/de/2079293/hacking/google-chrome-zero-day-patched-post-pwn2own-march-exploits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2079293/hacking/google-chrome-zero-day-patched-post-pwn2own-march-exploits/</guid>
<pubDate>Thu, 21 Mar 2024 04:03:16 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="et_pb_section et_pb_section_0 et_section_specialty">
				
				
				
				
				
				<div class="et_pb_row">
				<div class="et_pb_column et_pb_column_3_4 et_pb_column_0   et_pb_specialty_column  et_pb_css_mix_blend_mode_passthrough">
				
				
				
				
				<div class="et_pb_row_inner et_pb_row_inner_0">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_0 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_post_title et_pb_post_title_0 et_pb_bg_layout_light  et_pb_text_align_left">
				
				
				
				
				
				<div class="et_pb_title_container">
					<h1 class="entry-title">Google Chrome Zero-Day Patched Post-Pwn2Own March Exploits</h1>
				</div>
				
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_1">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_1 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_0  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong><div class="post-views content-post post-278364 entry-meta">
				<span class="post-views-icon dashicons dashicons-chart-bar"></span> <span class="post-views-label">Post Views:</span> <span class="post-views-count">1</span>
			</div></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_1  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_2 patreon-row">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_2 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_2  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h3 class="premium-content">Join our <a class="green_color" href="https://www.patreon.com/posts/maximizing-your-87671900" target="_blank" rel="noopener sponsored">Patreon</a> Channel and Gain access to 70+ Exclusive Walkthrough Videos.</h3></div>
			</div><div class="et_pb_module et_pb_image et_pb_image_0">
				
				
				
				
				<a href="https://www.patreon.com/posts/maximizing-your-87671900" target="_blank"><span class="et_pb_image_wrap "><img fetchpriority="high" decoding="async" width="800" height="120" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Patreon.png" alt="Patreon" title="Patreon" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Patreon.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Patreon-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw" class="wp-image-275956"></span></a>
			</div><div class="et_pb_module et_pb_divider et_pb_divider_0 et_pb_divider_position_ et_pb_space"><div class="et_pb_divider_internal"></div></div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_3">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_3 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_3  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner">Reading Time: 3 Minutes</div>
			</div>
			</div>
				
				
				
				
			</div><div class="et_pb_row_inner et_pb_row_inner_4">
				<div class="et_pb_column et_pb_column_4_4 et_pb_column_inner et_pb_column_inner_4 et-last-child">
				
				
				
				
				<div class="et_pb_module et_pb_text et_pb_text_4  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>Google has successfully addressed another zero-day vulnerability discovered in the Chrome browser. Tracked as CVE-2024-3159, this high-severity flaw, exploited by security researchers during the recent Pwn2Own hacking contest, posed significant risks to user data and system integrity.</p>
<p>The vulnerability, attributed to an out-of-bounds read weakness in the Chrome V8 JavaScript engine, allowed remote attackers to execute arbitrary code via crafted HTML pages. By exploiting heap corruption, attackers could gain unauthorized access to data beyond the memory buffer, potentially exposing sensitive information or triggering browser crashes.</p>
<p>During the Pwn2Own Vancouver 2024 event, Palo Alto Networks security researchers Edouard Bochin and Tao Yan showcased a double-tap exploit leveraging CVE-2024-3159 to execute arbitrary code on both Google Chrome and Microsoft Edge browsers. Their demonstration earned them a notable $42,500 award and underscored the urgency of addressing such vulnerabilities.</p>
<p><span class="4WvxsZwVLetkNTq54nXmEFw8t6AAIkSflCs810dHbPTpYOdzujKB7o3VlQGraIYah"></span></p>
<blockquote class="twitter-tweet" data-width="550" data-dnt="true">
<p lang="en" dir="ltr">Confirmed! <a href="https://twitter.com/le_douds?ref_src=twsrc%5Etfw">@le_douds</a> and <a href="https://twitter.com/ga1ois?ref_src=twsrc%5Etfw">@Ga1ois</a> from Palo Alto used an OOB Read plus a novel technique for defeating V8 hardening to get arbitrary code execution in the renderer. The were aboe to exploit <a href="https://twitter.com/hashtag/Chrome?src=hash&amp;ref_src=twsrc%5Etfw">#Chrome</a> and <a href="https://twitter.com/hashtag/Edge?src=hash&amp;ref_src=twsrc%5Etfw">#Edge</a> with the same bugs, earning $42,500 and 9 Master of Pwn points. <a href="https://twitter.com/hashtag/Pwn2Own?src=hash&amp;ref_src=twsrc%5Etfw">#Pwn2Own</a> <a href="https://t.co/EhFIEntnPw">pic.twitter.com/EhFIEntnPw</a></p>
<p>— Zero Day Initiative (@thezdi) <a href="https://twitter.com/thezdi/status/1770927914831274115?ref_src=twsrc%5Etfw">March 21, 2024</a></p></blockquote>
<p></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_5 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>See Also: So, you want to be a hacker?<br>
</strong><strong><a href="https://www.blackhatethicalhacking.com/courses/" target="_blank" rel="noopener noreferrer">Offensive Security, Bug Bounty Courses</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_6  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News_Horizontal_smaller --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_7  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><h4><span><strong>Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.</strong></span></h4>
<p><a href="https://www.blackhatethicalhacking.com/solutions/"><img decoding="async" class="alignnone wp-image-276050 size-full" src="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png" alt="" width="800" height="120" srcset="https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions.png 800w, https://www.blackhatethicalhacking.com/wp-content/uploads/2023/11/Solutions-480x72.png 480w" sizes="(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) 800px, 100vw"></a></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_8  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p>Google swiftly <a href="https://chromereleases.googleblog.com/2024/04/stable-channel-update-for-desktop.html" target="_blank" rel="noopener">patched</a> the zero-day in the Chrome stable channel, releasing version 123.0.6312.105/.106/.107 for Windows and Mac, and version 123.0.6312.105 for Linux. These updates are set to roll out globally in the coming days, ensuring users are protected against potential exploitation.</p>
<p>This latest fix follows Google’s recent efforts to address vulnerabilities exploited at Pwn2Own Vancouver 2024, including two additional zero-days: a type confusion weakness (CVE-2024-2887) in the WebAssembly (Wasm) standard and a use-after-free (UAF) weakness in the WebCodecs API (CVE-2024-2886). By swiftly releasing patches, Google demonstrates its commitment to enhancing browser security and safeguarding users from emerging threats.</p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_9 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/articles/understanding-ptaas-and-soc/" target="_blank" rel="noopener noreferrer">Understanding PTaaS and SOC<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_10  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><br>
<!-- News Adsense Adcode Horizontal --><br>
<ins class="adsbygoogle" data-ad-client="ca-pub-6620833063853657" data-ad-slot="8337846400"></ins><br>
</div>
			</div><div class="et_pb_module et_pb_text et_pb_text_11 see-also-text  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><p><strong>Trending: <a href="https://www.blackhatethicalhacking.com/tools/waf-bypass/" target="_blank" rel="noopener noreferrer">Offensive Security Tool: WAF Bypass<br>
</a></strong></p></div>
			</div><div class="et_pb_module et_pb_text et_pb_text_12  et_pb_text_align_left et_pb_bg_layout_light">
				
				
				
				
				<div class="et_pb_text_inner"><div class="group w-full text-gray-800 dark:text-gray-100 border-b border-black/10 dark:border-gray-900/50 bg-gray-50 dark:bg-[#444654]">
<div class="group final-completion w-full text-token-text-primary border-b border-black/10 gizmo:border-0 dark:border-gray-900/50 gizmo:dark:border-0 bg-gray-50 gizmo:bg-transparent dark:bg-[#444654] gizmo:dark:bg-transparent" data-testid="conversation-turn-747">
<div class="p-4 gizmo:py-2 justify-center text-base md:gap-6 md:py-6 m-auto">
<div class="flex flex-1 gap-4 text-base mx-auto md:gap-6 gizmo:gap-3 gizmo:md:px-5 gizmo:lg:px-1 gizmo:xl:px-5 md:max-w-2xl lg:max-w-[38rem] gizmo:md:max-w-3xl gizmo:lg:max-w-[40rem] gizmo:xl:max-w-[48rem] xl:max-w-3xl }">
<div class="relative flex w-[calc(100%-50px)] flex-col gizmo:w-full lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col gap-3 max-w-full">
<div class="min-h-[20px] flex flex-col items-start gap-3 whitespace-pre-wrap break-words overflow-x-auto">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="group w-full text-token-text-primary border-b border-black/10 gizmo:border-0 dark:border-gray-900/50 gizmo:dark:border-0 bg-gray-50 gizmo:bg-transparent dark:bg-[#444654] gizmo:dark:bg-transparent" data-testid="conversation-turn-753">
<div class="p-4 gizmo:py-2 justify-center text-base md:gap-6 md:py-6 m-auto">
<div class="flex flex-1 gap-4 text-base mx-auto md:gap-6 gizmo:gap-3 gizmo:md:px-5 gizmo:lg:px-1 gizmo:xl:px-5 md:max-w-2xl lg:max-w-[38rem] gizmo:md:max-w-3xl gizmo:lg:max-w-[40rem] gizmo:xl:max-w-[48rem] xl:max-w-3xl }">
<div class="relative flex w-[calc(100%-50px)] flex-col gizmo:w-full lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col gap-3 max-w-full">
<div class="min-h-[20px] flex flex-col items-start gap-3 whitespace-pre-wrap break-words overflow-x-auto" data-message-author-role="assistant" data-message-id="65fa1689-f693-474e-9b01-d95d43c0e8ce">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="group w-full text-token-text-primary border-b border-black/10 gizmo:border-0 dark:border-gray-900/50 gizmo:dark:border-0 bg-gray-50 gizmo:bg-transparent dark:bg-[#444654] gizmo:dark:bg-transparent" data-testid="conversation-turn-755">
<div class="p-4 gizmo:py-2 justify-center text-base md:gap-6 md:py-6 m-auto">
<div class="flex flex-1 gap-4 text-base mx-auto md:gap-6 gizmo:gap-3 gizmo:md:px-5 gizmo:lg:px-1 gizmo:xl:px-5 md:max-w-2xl lg:max-w-[38rem] gizmo:md:max-w-3xl gizmo:lg:max-w-[40rem] gizmo:xl:max-w-[48rem] xl:max-w-3xl }">
<div class="relative flex w-[calc(100%-50px)] flex-col gizmo:w-full lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col gap-3 max-w-full">
<div class="min-h-[20px] flex flex-col items-start gap-3 whitespace-pre-wrap break-words overflow-x-auto" data-message-author-role="assistant" data-message-id="d33538bc-9615-4240-bf50-698bb2a457b9">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="group w-full text-token-text-primary border-b border-black/10 gizmo:border-0 dark:border-gray-900/50 gizmo:dark:border-0 bg-gray-50 gizmo:bg-transparent dark:bg-[#444654] gizmo:dark:bg-transparent" data-testid="conversation-turn-757">
<div class="p-4 gizmo:py-2 justify-center text-base md:gap-6 md:py-6 m-auto">
<div class="flex flex-1 gap-4 text-base mx-auto md:gap-6 gizmo:gap-3 gizmo:md:px-5 gizmo:lg:px-1 gizmo:xl:px-5 md:max-w-2xl lg:max-w-[38rem] gizmo:md:max-w-3xl gizmo:lg:max-w-[40rem] gizmo:xl:max-w-[48rem] xl:max-w-3xl }">
<div class="relative flex w-[calc(100%-50px)] flex-col gizmo:w-full lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col gap-3 max-w-full">
<div class="min-h-[20px] flex flex-col items-start gap-3 whitespace-pre-wrap break-words overflow-x-auto" data-message-author-role="assistant" data-message-id="2f33df58-a011-4f4a-afd7-21485ea24079">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="min-h-[20px] flex flex-col items-start gap-3 whitespace-pre-wrap break-words overflow-x-auto" data-message-author-role="assistant" data-message-id="36ac21e9-7899-4ff1-8ada-00143751d5ff">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="whitespace-pre-wrap text-th-primary-dark antialiased break-words ">
<div class="group w-full text-token-text-primary border-b border-black/10 gizmo:border-0 dark:border-gray-900/50 gizmo:dark:border-0 bg-gray-50 gizmo:bg-transparent dark:bg-[#444654] gizmo:dark:bg-transparent" data-testid="conversation-turn-779">
<div class="p-4 gizmo:py-2 justify-center text-base md:gap-6 md:py-6 m-auto">
<div class="flex flex-1 gap-4 text-base mx-auto md:gap-6 gizmo:gap-3 gizmo:md:px-5 gizmo:lg:px-1 gizmo:xl:px-5 md:max-w-2xl lg:max-w-[38rem] gizmo:md:max-w-3xl gizmo:lg:max-w-[40rem] gizmo:xl:max-w-[48rem] xl:max-w-3xl }">
<div class="relative flex w-[calc(100%-50px)] flex-col gizmo:w-full lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full gap-3 gizmo:gap-0">
<div class="min-h-[20px] text-message peer flex flex-col items-start gap-3 whitespace-pre-wrap break-words peer-[.text-message]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="a2176b25-fb22-4587-9755-c6cbb37e431e">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-nfkhx-79elbk h-full">
<div class="react-scroll-to-bottom--css-nfkhx-1n7m0yu">
<div class="flex flex-col text-sm gizmo:pb-9 dark:bg-gray-800 gizmo:dark:bg-transparent">
<div class="w-full text-token-text-primary border-b border-black/10 gizmo:border-0 dark:border-gray-900/50 gizmo:dark:border-0 bg-gray-50 gizmo:bg-transparent dark:bg-[#444654] gizmo:dark:bg-transparent" data-testid="conversation-turn-783">
<div class="p-4 gizmo:py-2 justify-center text-base md:gap-6 md:py-6 m-auto">
<div class="flex flex-1 gap-4 text-base mx-auto md:gap-6 gizmo:gap-3 gizmo:md:px-5 gizmo:lg:px-1 gizmo:xl:px-5 md:max-w-2xl lg:max-w-[38rem] gizmo:md:max-w-3xl gizmo:lg:max-w-[40rem] gizmo:xl:max-w-[48rem] xl:max-w-3xl } group final-completion">
<div class="relative flex w-[calc(100%-50px)] flex-col gizmo:w-full lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full gap-3 gizmo:gap-0">
<div class="min-h-[20px] text-message peer flex flex-col items-start gap-3 whitespace-pre-wrap break-words peer-[.text-message]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="dc4244d8-8f27-47dc-8a06-4aa5a2b7f2d9">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex flex-grow flex-col max-w-full gap-3 gizmo:gap-0">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="7d817417-80f8-4ab6-b7f9-217ceffa93f9">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-ucjik-79elbk h-full">
<div class="react-scroll-to-bottom--css-ucjik-1n7m0yu">
<div class="flex flex-col text-sm gizmo:pb-9 dark:bg-gray-800 gizmo:dark:bg-transparent">
<div class="w-full text-token-text-primary border-b border-black/10 gizmo:border-0 dark:border-gray-900/50 gizmo:dark:border-0 bg-gray-50 gizmo:bg-transparent dark:bg-[#444654] gizmo:dark:bg-transparent" data-testid="conversation-turn-805">
<div class="p-4 gizmo:py-2 justify-center text-base md:gap-6 md:py-6 m-auto">
<div class="flex flex-1 gap-4 text-base mx-auto md:gap-6 gizmo:gap-3 gizmo:md:px-5 gizmo:lg:px-1 gizmo:xl:px-5 md:max-w-2xl lg:max-w-[38rem] gizmo:md:max-w-3xl gizmo:lg:max-w-[40rem] gizmo:xl:max-w-[48rem] xl:max-w-3xl } group final-completion">
<div class="relative flex w-[calc(100%-50px)] flex-col gizmo:w-full lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full gap-3 gizmo:gap-0">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="6c397562-526f-416d-9ff2-245c9b32fbbf">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-lidff-79elbk h-full">
<div class="react-scroll-to-bottom--css-lidff-1n7m0yu">
<div class="flex flex-col pb-9 text-sm">
<div class="w-full text-token-text-primary" data-testid="conversation-turn-817">
<div class="px-4 py-2 justify-center text-base md:gap-6 md:py-6 m-auto">
<div class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] } group final-completion">
<div class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="8d91526d-74a2-46c0-bda8-a4e97dd42a2f">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-vmgwv-79elbk h-full">
<div class="react-scroll-to-bottom--css-vmgwv-1n7m0yu">
<div class="flex flex-col pb-9 text-sm">
<div class="w-full text-token-text-primary" data-testid="conversation-turn-819">
<div class="px-4 py-2 justify-center text-base md:gap-6 m-auto">
<div class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] } group final-completion">
<div class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="b99694d9-22a2-4f54-bd37-07ebe9412d16">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-szfwt-79elbk h-full">
<div class="react-scroll-to-bottom--css-szfwt-1n7m0yu">
<div class="flex flex-col pb-9 text-sm">
<div class="w-full text-token-text-primary" data-testid="conversation-turn-825">
<div class="px-4 py-2 justify-center text-base md:gap-6 m-auto">
<div class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] } group final-completion">
<div class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="3ac06f76-10ea-4781-be1b-a67d74cafea3">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-bdqhz-79elbk h-full">
<div class="react-scroll-to-bottom--css-bdqhz-1n7m0yu">
<div class="flex flex-col pb-9 text-sm">
<div class="w-full text-token-text-primary" data-testid="conversation-turn-827">
<div class="px-4 py-2 justify-center text-base md:gap-6 m-auto">
<div class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] } group final-completion">
<div class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="28a8f0b3-99af-485d-bc0f-d6536b6ca1d1">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-wigza-79elbk h-full">
<div class="react-scroll-to-bottom--css-wigza-1n7m0yu">
<div class="flex flex-col pb-9 text-sm">
<div class="w-full text-token-text-primary" data-testid="conversation-turn-847">
<div class="px-4 py-2 justify-center text-base md:gap-6 m-auto">
<div class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] } group final-completion">
<div class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="fe2b5776-f866-4aa4-ab7e-1cb049416b1a">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-ecpmz-79elbk h-full">
<div class="react-scroll-to-bottom--css-ecpmz-1n7m0yu">
<div class="flex flex-col pb-9 text-sm">
<div class="w-full text-token-text-primary" data-testid="conversation-turn-849">
<div class="px-4 py-2 justify-center text-base md:gap-6 m-auto">
<div class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] } group final-completion">
<div class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="6de91082-0f57-40bb-b889-876ab7033b2b">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-ofqdg-79elbk h-full">
<div class="react-scroll-to-bottom--css-ofqdg-1n7m0yu">
<div class="flex flex-col pb-9 text-sm">
<div class="w-full text-token-text-primary" data-testid="conversation-turn-851">
<div class="px-4 py-2 justify-center text-base md:gap-6 m-auto">
<div class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] group final-completion">
<div class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="2075d2a5-71fd-41c8-abee-b0b95fb91434">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="whitespace-pre-wrap text-th-primary-dark antialiased break-words ">
<div class="whitespace-pre-wrap text-th-primary-dark antialiased break-words ">
<div class="whitespace-pre-wrap text-th-primary-dark antialiased break-words ">
<div class="whitespace-pre-wrap text-th-primary-dark antialiased break-words ">
<div class="post-markdown flex flex-col gap-4 text-th-primary-dark text-base ">
<div class="whitespace-pre-wrap text-th-primary-dark antialiased break-words ">
<div class="post-markdown flex flex-col gap-4 text-th-primary-dark text-base ">
<div class="whitespace-pre-wrap text-th-primary-dark antialiased break-words ">
<div class="whitespace-pre-wrap text-th-primary-dark antialiased break-words ">
<div class="w-full text-token-text-primary" data-testid="conversation-turn-5">
<div class="px-4 py-2 justify-center text-base md:gap-6 m-auto">
<div class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] group">
<div class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="adb3be11-1779-438d-b815-630efb375690">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="w-full text-token-text-primary" data-testid="conversation-turn-9">
<div class="px-4 py-2 justify-center text-base md:gap-6 m-auto">
<div class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] group final-completion">
<div class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="fbb8383c-c08e-4a78-8a1a-c7efc29f0fe1">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-pbynu-79elbk h-full">
<div class="react-scroll-to-bottom--css-pbynu-1n7m0yu">
<div class="flex flex-col pb-9 text-sm">
<div class="w-full text-token-text-primary" data-testid="conversation-turn-33">
<div class="px-4 py-2 justify-center text-base md:gap-6 m-auto">
<div class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] group final-completion">
<div class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="5f046076-7557-413d-a217-9399e565ab49">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-dgwoq-79elbk h-full">
<div class="react-scroll-to-bottom--css-dgwoq-1n7m0yu">
<div class="flex flex-col pb-9 text-sm">
<div class="w-full text-token-text-primary" data-testid="conversation-turn-45">
<div class="px-4 py-2 justify-center text-base md:gap-6 m-auto">
<div class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] group final-completion">
<div class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="d1da203a-5d44-4f34-a066-ac060d8606da">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-fgwwz-79elbk h-full">
<div class="react-scroll-to-bottom--css-fgwwz-1n7m0yu">
<div class="flex flex-col pb-9 text-sm">
<div class="w-full text-token-text-primary" data-testid="conversation-turn-47">
<div class="px-4 py-2 justify-center text-base md:gap-6 m-auto">
<div class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] group final-completion">
<div class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="f54440fc-f704-424c-8d00-9f10c33800f5">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-vmcws-79elbk h-full">
<div class="react-scroll-to-bottom--css-vmcws-1n7m0yu">
<div class="flex flex-col pb-9 text-sm">
<div class="w-full text-token-text-primary" data-testid="conversation-turn-55">
<div class="px-4 py-2 justify-center text-base md:gap-6 m-auto">
<div class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] group final-completion">
<div class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="c829e0be-9741-451a-b366-e789afad7d0d">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-vfxrr-79elbk h-full">
<div class="react-scroll-to-bottom--css-vfxrr-1n7m0yu">
<div class="flex flex-col pb-9 text-sm">
<div class="w-full text-token-text-primary" data-testid="conversation-turn-63">
<div class="px-4 py-2 justify-center text-base md:gap-6 m-auto">
<div class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] group final-completion">
<div class="relative flex w-full flex-col lg:w-[calc(100%-115px)] agent-turn">
<div class="flex-col gap-1 md:gap-3">
<div class="flex flex-grow flex-col max-w-full">
<div class="min-h-[20px] text-message flex flex-col items-start gap-3 whitespace-pre-wrap break-words [.text-message+&amp;]:mt-5 overflow-x-auto" data-message-author-role="assistant" data-message-id="41d27cd2-e52e-47d3-bac3-d25fa783ae7d">
<div class="markdown prose w-full break-words dark:prose-invert dark">
<div class="flex-1 overflow-hidden">
<div class="react-scroll-to-bottom--css-opbuo-79elbk h-full">
<div class="react-scroll-to-bottom--css-opbuo-1n7m0yu">
<div class="flex flex-col pb-9 text-sm">
<div class="w-full text-token-text-primary" data-testid="conversation-turn-69">
<div class="px-4 py-2 justify-center text-base md:gap-6 m-auto">
<div class="flex flex-1 text-base mx-auto gap-3 md:px-5 lg:px-1 xl:px-5 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] group final-completion">
</div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SUSE’s WebAssembly report from KubeCon EU]]></title>
<description><![CDATA[It is not the first time that the SUSE blog has featured WebAssembly – an emerging technology that is fast gaining traction inside the Cloud Native ecosystem. As a matter of fact, Wasm, as it is commonly known, seems to have created quite the buzz at the recently concluded KubeCon, with it being ...]]></description>
<link>https://tsecurity.de/de/2072763/unix-server/suses-webassembly-report-from-kubecon-eu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2072763/unix-server/suses-webassembly-report-from-kubecon-eu/</guid>
<pubDate>Thu, 14 Mar 2024 03:39:56 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>It is not the first time that the SUSE blog has featured WebAssembly – an emerging technology that is fast gaining traction inside the Cloud Native ecosystem. As a matter of fact, Wasm, as it is commonly known, seems to have created quite the buzz at the recently concluded KubeCon, with it being one of […]</p>
<p>The post <a rel="nofollow" href="https://www.suse.com/c/suses-webassembly-report-from-kubecon-eu/">SUSE’s WebAssembly report from KubeCon EU</a> appeared first on <a rel="nofollow" href="https://www.suse.com/c">SUSE Communities</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[March '24: faster Flutter web apps, more App Check,＆range conditions on multiple fields in Firestore]]></title>
<description><![CDATA[Author: Firebase - Bewertung: 129x - Views:2003 Welcome to the March 2024 edition of Firebase Release Notes. In this video, Puf discusses updates to the FlutterFire CLI and SDKs, improvements to App Check, cache-only listeners for Firestore, more ways to schedule Firestore backups, a brand new qu...]]></description>
<link>https://tsecurity.de/de/2071791/it-security-video/march-24-faster-flutter-web-apps-more-app-checkrange-conditions-on-multiple-fields-in-firestore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2071791/it-security-video/march-24-faster-flutter-web-apps-more-app-checkrange-conditions-on-multiple-fields-in-firestore/</guid>
<pubDate>Thu, 14 Mar 2024 03:18:23 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/eTArV4Z3Caw/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Firebase - Bewertung: 129x - Views:2003 <br/></p><p><iframe id="ytplayer" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/eTArV4Z3Caw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Welcome to the March 2024 edition of Firebase Release Notes. In this video, Puf discusses updates to the FlutterFire CLI and SDKs, improvements to App Check, cache-only listeners for Firestore, more ways to schedule Firestore backups, a brand new query feature for Firestore, and more!

Chapters:
0:00 - Introduction
00:10 - Send verification before updating email address in C++ and Unity
00:29 - Flutter Firebase CLI updates
00:54 - App Check and Functions SDK for Flutter support WASM builds
1:11 - Terraform support for App Check
1:36 - Protect your user's Google Identity on iOS with App Check
2:04 - Listen to local cache data only with Firestore
2:37 - Manage and restore Firestore backups from the Firebase CLI
2:52 - Range and inequality conditions on multiple fields in Firestore

Resources:
App Check comes to Google Identity for iOS → https://goo.gle/3IVeg9f
[Terraform] Protect an API resource with Firebase App Check → https://goo.gle/4au3Qcs
Query with range and inequality filters on multiple fields → https://goo.gle/3TCfgE5


Watch more Firebase Release Notes → https://goo.gle/firebase-release-notes   
Subscribe to Firebase → https://goo.gle/Firebase  

#FirebaseReleaseNotes #Firebase 

Speaker: Frank van Puffelen
Products Mentioned: Firebase, Firebase CLI, App Check, Firestore<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[February 2024: Auto-testing in App Distro, Flutter speedups, Firestore GA＆Crashlytics improvements]]></title>
<description><![CDATA[Author: Firebase - Bewertung: 78x - Views:1202 Welcome to the February 2024 edition of Firebase Release Notes. In this video, puf discusses updates to automated smoke tests for Android apps in App Distribution, Flutter SDKs, building optimization fix for Flutter iOS/macOS, Crashlytics, and much m...]]></description>
<link>https://tsecurity.de/de/2048875/it-security-video/february-2024-auto-testing-in-app-distro-flutter-speedups-firestore-gacrashlytics-improvements/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2048875/it-security-video/february-2024-auto-testing-in-app-distro-flutter-speedups-firestore-gacrashlytics-improvements/</guid>
<pubDate>Wed, 28 Feb 2024 10:10:31 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/5haj49KicJw/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Firebase - Bewertung: 78x - Views:1202 <br/></p><p><iframe id="ytplayer" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/5haj49KicJw?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Welcome to the February 2024 edition of Firebase Release Notes. In this video, puf discusses updates to automated smoke tests for Android apps in App Distribution, Flutter SDKs, building optimization fix for Flutter iOS/macOS, Crashlytics, and much more!

Chapters:
0:00 - Introduction
0:12 - Run automated smoke tests for Android apps in App Distribution
0:53 - Flutter SDKs moving to js_interop for better Wasm performance
1:31 - Build optimization fix for Flutter iOS/macOS apps that use Firestore
2:00 - Eventarc for Firestore now generally available
2:41 - Crashlytics shows trend line for each issue
2:53 - Crashlytics shows more and better crash-free metrics
3:24 - Crashlytics release monitoring experience rolling out

Resources:
Run an automated test for Android apps → https://goo.gle/3wpalOV 
Firestore iOS SDK Binary Distribution (for Flutter) → https://goo.gle/42SquZx 
Extend Firestore with Cloud Functions (2nd gen) →  https://goo.gle/49IDYZS 
Flutter for Firebase SDKs → https://goo.gle/3OTbkgC  

Watch more Firebase Release Notes → https://goo.gle/firebase-release-notes   
Subscribe to Firebase → https://goo.gle/Firebase  

#FirebaseReleaseNotes #Firebase


Speaker: Frank van Puffelen
Products Mentioned: Firebase, Cloud Firestore, Cloud Functions, Flutter, EventArc<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-0754 | Mozilla Firefox up to 121 WASM Source File denial of service]]></title>
<description><![CDATA[A vulnerability was found in Mozilla Firefox up to 121. It has been classified as problematic. This affects an unknown part of the component WASM Source File Handler. The manipulation leads to denial of service.

This vulnerability is uniquely identified as CVE-2024-0754. It is possible to initia...]]></description>
<link>https://tsecurity.de/de/2035659/sicherheitsluecken/cve-2024-0754-mozilla-firefox-up-to-121-wasm-source-file-denial-of-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2035659/sicherheitsluecken/cve-2024-0754-mozilla-firefox-up-to-121-wasm-source-file-denial-of-service/</guid>
<pubDate>Sat, 17 Feb 2024 10:07:47 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.mozilla:firefox">Mozilla Firefox up to 121</a>. It has been classified as <a href="https://vuldb.com/?kb.risk">problematic</a>. This affects an unknown part of the component <em>WASM Source File Handler</em>. The manipulation leads to denial of service.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.251853">CVE-2024-0754</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[3 years of work and 1 million users later, I'm gradually open-sourcing my "Internet OS"!]]></title>
<description><![CDATA[Hi all! I'm slowly open-sourcing every part of my "internet OS", under real, non-modified OSS licenses -- absolutely no "open core" or "source available" fake OSS crap. I was wondering if there is anyone here interested in joining us. Puter has become a very big and super interesting project touc...]]></description>
<link>https://tsecurity.de/de/2029234/linux-tipps/3-years-of-work-and-1-million-users-later-im-gradually-open-sourcing-my-internet-os/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2029234/linux-tipps/3-years-of-work-and-1-million-users-later-im-gradually-open-sourcing-my-internet-os/</guid>
<pubDate>Tue, 13 Feb 2024 09:16:42 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi all!</p> <p>I'm slowly open-sourcing every part of my "<a href="https://puter.com/">internet OS</a>", under real, non-modified OSS licenses -- absolutely no "open core" or "source available" fake OSS crap.</p> <p>I was wondering if there is anyone here interested in joining us. Puter has become a very big and super interesting project touching many different areas in programming (web, graphics, wasm, distributed systems,...) and both <strong>beginners</strong> and <strong>advanced</strong> users/programmers are very welcome to join :)</p> <p>Our projects</p> <ul> <li><strong>Terminal</strong> (AGPL): <a href="https://github.com/HeyPuter/terminal">https://github.com/HeyPuter/terminal</a> [released today] - moving toward POSIX compliance.</li> <li><strong>Phoenix Shell</strong> (AGPL): <a href="https://github.com/HeyPuter/phoenix">https://github.com/HeyPuter/phoenix</a> [released today]</li> <li><strong>KV.JS</strong> (MIT), i.e. "Redis in the browser!": <a href="https://github.com/HeyPuter/kv.js">https://github.com/HeyPuter/kv.js</a> [1,300 stars &lt;3 ]</li> <li><strong>SDK</strong> (Apache 2.0): our SDK which is currently in production but not published yet [coming this or next week]</li> <li><strong>GUI</strong> (AGPL): the GUI (Desktop Environment) for <a href="https://puter.com/">puter.com</a>, biggest challenge right now is finding/designing open-source icons. [~ coming next month]</li> <li><strong>Office</strong> (AGPL): VERY encouraging discussion on <a href="https://www.reddit.com/r/opensource/comments/1ak1wa2/whos_down_to_build_a_truly_opensource_webbased/">another subreddit a few day ago</a> [coming soon]</li> <li><strong>Apps</strong> such as <a href="https://puter.com/app/editor">Notepad</a>, etc. [coming soon]</li> </ul> <p>Last but not least: we don't know how to make money yet but it's really fun working on this project lol</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/mitousa"> /u/mitousa </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1apoc6n/3_years_of_work_and_1_million_users_later_im/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1apoc6n/3_years_of_work_and_1_million_users_later_im/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Using WebAssembly to run, extend, and secure your application!]]></title>
<description><![CDATA[Author: OWASP Foundation - Bewertung: 1x - Views:7 Slides: https://static.sched.com/hosted_files/owasp2023globalappsecwashin/55/AppSecDC2023-Wasm.pdf

WebAssembly (WASM) has come a long way since its first release in 2017. As a technology stack running inside the web browser, it even allows produ...]]></description>
<link>https://tsecurity.de/de/2012307/it-security-video/using-webassembly-to-run-extend-and-secure-your-application/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2012307/it-security-video/using-webassembly-to-run-extend-and-secure-your-application/</guid>
<pubDate>Wed, 31 Jan 2024 07:38:27 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/-4pVadK8ru8/hqdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: OWASP Foundation - Bewertung: 1x - Views:7 <br/></p><p><iframe id="ytplayer" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/-4pVadK8ru8?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Slides: https://static.sched.com/hosted_files/owasp2023globalappsecwashin/55/AppSecDC2023-Wasm.pdf

WebAssembly (WASM) has come a long way since its first release in 2017. As a technology stack running inside the web browser, it even allows products like Adobe Photoshop to run in that context, and with for example Blazor WebAssembly .NET runs inside of the browser as well. Now, WASM is expanding beyond the browser to run in a server-based context. With the introduction of WebAssembly System Interface (WASI), the technology leverages a standardized API that allows it to run on any system that supports it, for example to support cloud-based workloads.
Had WASM and WASI been around in 2009, Docker would not have existed according to one of its founders, Solomon Hykes. WASM has a strong security posture given how it works with linear memory space and how it supports a sandboxed-based environment called “nano-process”, which uses a capabilities-based security model. Users can even take any language that targets WASM and, with the help of WASI, run it on a Trusted Execution Environment (TEE) to add an additional layer of security.

In this session we'll start out with going through some of the basic security features of WASM and then move to running and extending an application it with WASM. After that we'll focus on the security features and run on a TEE and use the sandbox and the capabilities based security model to limit what it's allowed to do in both in resources and compute.

Niels Tanis
Veracode
Sr. Principal Security Researcher

Niels Tanis has got a background in .NET development, pentesting and security consultancy. He is Microsoft MVP and has been involved in breaking, defending and building secure applications. He joined Veracode in 2015 and right now he works as a security researcher on a variant of languages and technologies related to Veracode’s Binary Static Analysis service. He is married, father of two and lives in a small village just outside Amersfoort, The Netherlands.

Managed by the OWASP® Foundation
https://owasp.org/<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-52284 | Bytecode Alliance wasm-micro-runtime up to 1.2.x Module push_pop_frame_ref_offset double free (Issue 2586)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Bytecode Alliance wasm-micro-runtime up to 1.2.x. This affects the function push_pop_frame_ref_offset of the component Module Handler. The manipulation leads to double free.

This vulnerability is uniquely identified as CVE-2023-5...]]></description>
<link>https://tsecurity.de/de/2000021/sicherheitsluecken/cve-2023-52284-bytecode-alliance-wasm-micro-runtime-up-to-12x-module-pushpopframerefoffset-double-free-issue-2586/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2000021/sicherheitsluecken/cve-2023-52284-bytecode-alliance-wasm-micro-runtime-up-to-12x-module-pushpopframerefoffset-double-free-issue-2586/</guid>
<pubDate>Mon, 22 Jan 2024 10:11:17 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">problematic</a>, was found in <a href="https://vuldb.com/?product.bytecode_alliance:wasm-micro-runtime">Bytecode Alliance wasm-micro-runtime up to 1.2.x</a>. This affects the function <code>push_pop_frame_ref_offset</code> of the component <em>Module Handler</em>. The manipulation leads to double free.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.249411">CVE-2023-52284</a>. The attack can only be done within the local network. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-48105 | Bytecode Alliance wasm-micro-runtime 1.2.3 wasm_loader.c wasm_loader_prepare_bytecode heap-based overflow (Issue 2726)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Bytecode Alliance wasm-micro-runtime 1.2.3. This affects the function wasm_loader_prepare_bytecode of the file core/iwasm/interpreter/wasm_loader.c. The manipulation leads to heap-based buffer overflow.

This vulnerability is uniquely ident...]]></description>
<link>https://tsecurity.de/de/1960129/sicherheitsluecken/cve-2023-48105-bytecode-alliance-wasm-micro-runtime-123-wasmloaderc-wasmloaderpreparebytecode-heap-based-overflow-issue-2726/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1960129/sicherheitsluecken/cve-2023-48105-bytecode-alliance-wasm-micro-runtime-123-wasmloaderc-wasmloaderpreparebytecode-heap-based-overflow-issue-2726/</guid>
<pubDate>Sat, 16 Dec 2023 11:00:04 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/?kb.risk">critical</a> has been found in <a href="https://vuldb.com/?product.bytecode_alliance:wasm-micro-runtime">Bytecode Alliance wasm-micro-runtime 1.2.3</a>. This affects the function <code>wasm_loader_prepare_bytecode</code> of the file <em>core/iwasm/interpreter/wasm_loader.c</em>. The manipulation leads to heap-based buffer overflow.

This vulnerability is uniquely identified as <a href="https://vuldb.com/?source_cve.246033">CVE-2023-48105</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to apply a patch to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2023-12-08 - Kernels, KDE Gear, LibreOffice]]></title>
<description><![CDATA[Hello community,
Another testing branch update with some usual package updates for you.

Get the lastest SoftMaker Office with ChatGPT buillt-in. You will find our Special Offer here!
Recent News:

Manjaro, like many other open-source projects, relies on the generosity of its community through do...]]></description>
<link>https://tsecurity.de/de/1955764/unix-server/testing-update-2023-12-08-kernels-kde-gear-libreoffice/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1955764/unix-server/testing-update-2023-12-08-kernels-kde-gear-libreoffice/</guid>
<pubDate>Sat, 09 Dec 2023 20:53:32 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello community,</p>
<p>Another <strong>testing</strong> branch update with some usual package updates for you.</p>
<p><img src="https://forum.manjaro.org/uploads/default/original/3X/4/2/42e8550ce72aa8ff000d704ed0fa0a698556b13e.jpeg" alt="image" data-base62-sha1="9xThw8e1scYGHvHqifKkf1T8ODQ" width="580" height="326"><br>
<em>Get the lastest <a href="https://www.softmaker.com/en/products/softmaker-office">SoftMaker Office with ChatGPT buillt-in</a>. You will find our <a href="https://softmaker.com/go/manjaro">Special Offer here</a>!</em></p>
<p><strong>Recent News:</strong></p>
<ul>
<li>Manjaro, like many other open-source projects, relies on the generosity of its community through <a href="https://manjaro.org/donate/">donations</a> and corporate sponsorships to support its growth and development. These <a href="https://manjaro.org/donate/">donations</a> are essential in covering the various expenses incurred in the operations of the project such as server costs, software development tools, infrastructure expenses, training, flying people to events or <a href="https://blog.manjaro.org/fosdem-2023/">conferences</a> and the salaries of key developers. With the help of these donations, Manjaro is able to secure the necessary financial stability that allows the project to continuously improve and remain active. If you love Manjaro, consider to <a href="https://manjaro.org/donate/">donate</a>!</li>
</ul>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2023-12-08-kernels-kde-gear-libreoffice/152963/1">(click for more details)</a>
<p><strong>Notable Package Updates:</strong></p>
<ul>
<li>Most <strong>Kernels</strong> got updated</li>
<li><strong>KDE Gear</strong> <a href="https://kde.org/announcements/gear/23.08.4/">23.08.4</a> got added</li>
<li><strong>LibreOffice</strong> got updated to <a href="https://blog.documentfoundation.org/blog/2023/12/07/libreoffice-764-and-759/">7.6.4 and 7.5.9</a></li>
<li>Usual <strong>KDE-git</strong>, <strong>Haskell</strong> and <strong>Python</strong> updates</li>
</ul>
<h2><a name="additional-info-1" class="anchor" href="https://forum.manjaro.org/#additional-info-1"></a>Additional Info</h2>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2023-12-08-kernels-kde-gear-libreoffice/152963/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux419 4.19.301</li>
<li>linux54 5.4.263</li>
<li>linux510 5.10.203</li>
<li>linux515 5.15.142</li>
<li>linux61 6.1.66</li>
<li>linux65 6.5.13 [EOL]</li>
<li>linux66 6.6.5</li>
<li>linux67 6.7-rc4</li>
<li>linux61-rt 6.1.64_rt17</li>
<li>linux65-rt 6.5.2_rt8</li>
<li>linux66-rt 6.6.0_rt15</li>
</ul>
<p><strong>Package Changes</strong> (Fri Dec 8 15:26:29 CET 2023)</p>
<ul>
<li>testing core x86_64:  20 new and 20 removed package(s)</li>
<li>testing extra x86_64:  499 new and 500 removed package(s)</li>
<li>testing kde-unstable x86_64:  112 new and 112 removed package(s)</li>
<li>testing multilib x86_64:  4 new and 4 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023-12-05           2023-12-08
-------------------------------------------------------------------------------
                            linux419           4.19.300-1           4.19.301-1
                    linux419-headers           4.19.300-1           4.19.301-1
                            linux510           5.10.202-1           5.10.203-1
                    linux510-headers           5.10.202-1           5.10.203-1
                            linux515           5.15.141-1           5.15.142-1
                    linux515-headers           5.15.141-1           5.15.142-1
                             linux54            5.4.262-1            5.4.263-1
                     linux54-headers            5.4.262-1            5.4.263-1
                             linux61             6.1.65-1             6.1.66-1
                     linux61-headers             6.1.65-1             6.1.66-1
                             linux66              6.6.4-6              6.6.5-1
                     linux66-headers              6.6.4-6              6.6.5-1
                             linux67           6.7.0rc4-5           6.7.0rc4-6
                     linux67-headers           6.7.0rc4-5           6.7.0rc4-6


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023-12-05           2023-12-08
-------------------------------------------------------------------------------
                                curl              8.4.0-2              8.5.0-1
                               glib2             2.78.1-1             2.78.3-1
                          glib2-docs             2.78.1-1             2.78.3-1
                      libcurl-compat              8.4.0-2              8.5.0-1
                      libcurl-gnutls              8.4.0-2              8.5.0-1
             thin-provisioning-tools              1.0.7-1              1.0.8-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023-12-05           2023-12-08
-------------------------------------------------------------------------------
                            chromium      120.0.6099.71-1                    -
                gnome-control-center               45.1-1               45.2-1
    gnome-control-center-x11-scaling               45.1-1               45.2-1
                  linux419-acpi_call            1.2.2-100            1.2.2-101
                   linux419-bbswitch              0.8-313              0.8-314
                linux419-broadcom-wl     6.30.223.271-313     6.30.223.271-314
               linux419-nvidia-390xx           390.157-45           390.157-46
               linux419-nvidia-470xx         470.223.02-5         470.223.02-6
                     linux419-nvidia          545.29.06-2          545.29.06-3
                   linux419-nvidiabl             0.88-312             0.88-313
                      linux419-r8168           8.052.01-6           8.052.01-7
                  linux419-rtl8723bu          20220818-55          20220818-56
                   linux419-tp_smapi               0.44-7               0.44-8
                linux419-vhba-module          20211218-96          20211218-97
    linux419-virtualbox-host-modules             7.0.12-5             7.0.12-6
                        linux419-zfs              2.2.2-0              2.2.2-1
                  linux510-acpi_call            1.2.2-136            1.2.2-137
                   linux510-bbswitch              0.8-237              0.8-238
                linux510-broadcom-wl     6.30.223.271-237     6.30.223.271-238
               linux510-nvidia-390xx           390.157-60           390.157-61
               linux510-nvidia-470xx         470.223.02-5         470.223.02-6
                     linux510-nvidia          545.29.06-2          545.29.06-3
                      linux510-r8168           8.052.01-6           8.052.01-7
                  linux510-rtl8723bu          20220818-75          20220818-76
                   linux510-tp_smapi               0.44-9              0.44-10
                linux510-vhba-module         20211218-132         20211218-133
    linux510-virtualbox-host-modules             7.0.12-5             7.0.12-6
                        linux510-zfs              2.2.2-1              2.2.2-2
                  linux515-acpi_call            1.2.2-151            1.2.2-152
                   linux515-bbswitch              0.8-166              0.8-167
                linux515-broadcom-wl     6.30.223.271-166     6.30.223.271-167
               linux515-nvidia-390xx           390.157-72           390.157-73
               linux515-nvidia-470xx         470.223.02-6         470.223.02-7
                     linux515-nvidia          545.29.06-3          545.29.06-4
                      linux515-r8168           8.052.01-9          8.052.01-10
                  linux515-rtl8723bu          20220818-88          20220818-89
                   linux515-tp_smapi              0.44-11              0.44-12
                linux515-vhba-module         20211218-148         20211218-149
    linux515-virtualbox-host-modules             7.0.12-7             7.0.12-8
                        linux515-zfs              2.2.2-1              2.2.2-2
                   linux54-acpi_call            1.2.2-115            1.2.2-116
                    linux54-bbswitch              0.8-289              0.8-290
                 linux54-broadcom-wl     6.30.223.271-288     6.30.223.271-289
                linux54-nvidia-390xx           390.157-47           390.157-48
                linux54-nvidia-470xx         470.223.02-5         470.223.02-6
                      linux54-nvidia          545.29.06-2          545.29.06-3
                    linux54-nvidiabl             0.88-289             0.88-290
                       linux54-r8168           8.052.01-6           8.052.01-7
                   linux54-rtl8723bu          20220818-63          20220818-64
                    linux54-tp_smapi               0.44-7               0.44-8
                 linux54-vhba-module         20211218-111         20211218-112
     linux54-virtualbox-host-modules             7.0.12-5             7.0.12-6
                         linux54-zfs              2.2.2-1              2.2.2-2
                   linux61-acpi_call             1.2.2-75             1.2.2-76
                    linux61-bbswitch               0.8-75               0.8-76
                 linux61-broadcom-wl      6.30.223.271-75      6.30.223.271-76
                linux61-nvidia-390xx           390.157-75           390.157-76
                linux61-nvidia-470xx         470.223.02-7         470.223.02-8
                      linux61-nvidia          545.29.06-3          545.29.06-4
                       linux61-r8168          8.052.01-11          8.052.01-12
                   linux61-rtl8723bu          20220818-75          20220818-76
                    linux61-tp_smapi              0.44-14              0.44-15
                 linux61-vhba-module          20211218-75          20211218-76
     linux61-virtualbox-host-modules             7.0.12-8             7.0.12-9
                         linux61-zfs              2.2.2-1              2.2.2-2
                   linux66-acpi_call             1.2.2-19             1.2.2-22
                    linux66-bbswitch               0.8-19               0.8-22
                 linux66-broadcom-wl      6.30.223.271-19      6.30.223.271-22
                linux66-nvidia-390xx           390.157-18           390.157-21
                linux66-nvidia-470xx        470.223.02-19        470.223.02-22
                      linux66-nvidia         545.29.06-14         545.29.06-17
                       linux66-r8168          8.052.01-19          8.052.01-22
                   linux66-rtl8723bu          20220818-19          20220818-22
                    linux66-tp_smapi              0.44-19              0.44-22
                 linux66-vhba-module          20211218-19          20211218-22
     linux66-virtualbox-host-modules            7.0.12-19            7.0.12-22
                         linux66-zfs              2.2.2-6              2.2.2-9
                   linux67-acpi_call            1.2.2-0.8            1.2.2-0.9
                    linux67-bbswitch              0.8-0.8              0.8-0.9
                 linux67-broadcom-wl     6.30.223.271-0.8     6.30.223.271-0.9
                linux67-nvidia-390xx          390.157-0.8          390.157-0.9
                linux67-nvidia-470xx       470.223.02-0.7       470.223.02-0.8
                      linux67-nvidia        545.29.06-0.7        545.29.06-0.8
                       linux67-r8168         8.052.01-0.8         8.052.01-0.9
                   linux67-rtl8723bu         20231204-0.2         20231204-0.3
                    linux67-tp_smapi             0.44-0.8             0.44-0.9
                 linux67-vhba-module         20211218-0.8         20211218-0.9
     linux67-virtualbox-host-modules           7.0.12-0.8           7.0.12-0.9


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023-12-05           2023-12-08
-------------------------------------------------------------------------------
                             akonadi            23.08.3-2            23.08.4-1
                    akonadi-calendar            23.08.3-1            23.08.4-1
                    akonadi-contacts            23.08.3-2            23.08.4-1
               akonadi-import-wizard            23.08.3-1            23.08.4-1
                        akonadi-mime            23.08.3-1            23.08.4-1
                       akonadi-notes            23.08.3-2            23.08.4-1
                      akonadi-search            23.08.3-1            23.08.4-1
                           analitza5            23.08.3-4            23.08.4-1
                                 aom              3.7.1-1              3.8.0-1
                            aom-docs              3.7.1-1              3.8.0-1
                                apko             0.11.3-1             0.12.0-1
                              awxkit             23.5.0-1             23.5.1-1
                       baloo-widgets            23.08.3-1            23.08.4-1
                      bitcoin-daemon               25.1-1               26.0-1
                          bitcoin-qt               25.1-1               26.0-1
                          bitcoin-tx               25.1-1               26.0-1
                     calendarsupport            23.08.3-1            23.08.4-1
                      cargo-depgraph              1.5.0-2              1.6.0-1
                       cargo-modules             0.11.2-1             0.12.0-1
                       cargo-shuttle             0.34.1-1             0.35.0-1
                              catch2            2.13.10-1              3.4.0-2
                            chromium      120.0.6099.62-2      120.0.6099.71-1
                          cloud-init             23.3.3-1               23.4-1
                                code             1.84.2-1             1.85.0-1
                   containers-common           1:0.57.0-1           1:0.57.1-1
                                deno             1.38.4-1             1.38.5-1
                          diffoscope                252-1                253-2
                                dolt             1.29.0-1             1.29.2-1
                                 dra              0.4.8-1              0.5.0-1
                          emscripten             3.1.48-1             3.1.50-1
                              erlang             26.1.2-1             26.1.2-2
                          erlang-nox             26.1.2-1             26.1.2-2
                     erlang-unixodbc             26.1.2-1             26.1.2-2
                          eventviews            23.08.3-2            23.08.4-1
                                 eza             0.16.2-1             0.16.3-1
                           fastfetch              2.3.2-1              2.3.4-1
                           findomain              9.0.3-1              9.0.4-1
                      frei0r-plugins              2.3.1-1              2.3.2-1
                       git-warp-time              0.5.2-1              0.6.1-1
                          github-cli             2.39.2-1             2.40.0-1
                       grantleetheme            23.08.3-2            23.08.4-1
                    haskell-citeproc             0.8.1-72             0.8.1-73
           haskell-commonmark-pandoc           0.2.1.3-55           0.2.1.3-56
                      haskell-hakyll          4.16.0.0-94          4.16.0.0-95
                 haskell-hledger-lib               1.32-1             1.32.1-1
               haskell-http-download           0.2.1.0-45           0.2.1.0-46
                      haskell-pandoc             3.1.6-11             3.1.6-12
           haskell-pandoc-lua-engine             0.2.1-10             0.2.1-11
          haskell-pandoc-lua-marshal             0.2.2-37             0.2.2-38
               haskell-pandoc-server           0.1.0.1-10           0.1.0.1-11
                haskell-pandoc-types           1.23.0.1-2             1.23.1-1
                      haskell-pantry            0.5.7-192            0.5.7-193
             haskell-rio-prettyprint            0.1.5.0-4            0.1.6.0-1
                     haskell-texmath           0.12.8.2-2           0.12.8.2-3
                             hledger               1.32-3             1.32.1-1
                        hledger-iadd            1.3.19-30            1.3.19-31
                          hledger-ui               1.32-3             1.32.1-1
                         hledger-web               1.32-4             1.32.1-1
                     incidenceeditor            23.08.3-1            23.08.4-1
                      jupyter-server             2.12.0-1             2.12.1-1
               kaccounts-integration            23.08.3-1            23.08.4-1
                 kaccounts-providers            23.08.3-1            23.08.4-1
                           kcalutils            23.08.3-1            23.08.4-1
                         kdeedu-data            23.08.3-1            23.08.4-1
              kdegraphics-mobipocket            23.08.3-1            23.08.4-1
                      kdepim-runtime            23.08.3-1            23.08.4-1
                 kidentitymanagement            23.08.3-2            23.08.4-1
                               kimap            23.08.3-1            23.08.4-1
                          kitinerary            23.08.3-2            23.08.4-1
                               kldap            23.08.3-1            23.08.4-1
                      kmailtransport            23.08.3-1            23.08.4-1
                               kmbox            23.08.3-1            23.08.4-1
                               kmime            23.08.3-2            23.08.4-1
                    kontactinterface            23.08.3-2            23.08.4-1
                        kpimtextedit            23.08.3-2            23.08.4-1
                             kpkpass            23.08.3-1            23.08.4-1
                      kqtquickcharts            23.08.3-1            23.08.4-1
                           ksanecore            23.08.3-1            23.08.4-1
                               ksmtp            23.08.3-1            23.08.4-1
                               ktnef            23.08.3-1            23.08.4-1
                     lib32-rust-libs           1:1.74.0-1           1:1.74.1-1
                          libakonadi            23.08.3-2            23.08.4-1
                            libdecor              0.2.1-1              0.2.1-2
                               libei              1.1.0-1              1.2.0-1
              libgedit-gtksourceview            299.0.4-2            299.0.5-1
                         libgravatar            23.08.3-1            23.08.4-1
                           libkcddb5            23.08.3-4            23.08.4-1
                     libkcompactdisc            23.08.3-1            23.08.4-1
                          libkdcraw5            23.08.3-3            23.08.4-1
                         libkdegames            23.08.3-1            23.08.4-1
                           libkdepim            23.08.3-1            23.08.4-1
                  libkeduvocdocument            23.08.3-1            23.08.4-1
                           libkexiv2            23.08.3-1            23.08.4-1
                            libkgapi            23.08.3-1            23.08.4-1
                             libkleo            23.08.3-1            23.08.4-1
                        libkmahjongg            23.08.3-1            23.08.4-1
                     libkomparediff2            23.08.3-1            23.08.4-1
                            libksane            23.08.3-1            23.08.4-1
                           libksieve            23.08.3-1            23.08.4-1
                         libktorrent            23.08.3-1            23.08.4-1
                   libreoffice-fresh              7.6.3-3              7.6.4-1
                libreoffice-fresh-af              7.6.3-2              7.6.4-1
                libreoffice-fresh-am              7.6.3-2              7.6.4-1
                libreoffice-fresh-ar              7.6.3-2              7.6.4-1
                libreoffice-fresh-as              7.6.3-2              7.6.4-1
               libreoffice-fresh-ast              7.6.3-2              7.6.4-1
                libreoffice-fresh-be              7.6.3-2              7.6.4-1
                libreoffice-fresh-bg              7.6.3-2              7.6.4-1
                libreoffice-fresh-bn              7.6.3-2              7.6.4-1
             libreoffice-fresh-bn-in              7.6.3-2              7.6.4-1
                libreoffice-fresh-bo              7.6.3-2              7.6.4-1
                libreoffice-fresh-br              7.6.3-2              7.6.4-1
               libreoffice-fresh-brx              7.6.3-2              7.6.4-1
                libreoffice-fresh-bs              7.6.3-2              7.6.4-1
                libreoffice-fresh-ca              7.6.3-2              7.6.4-1
       libreoffice-fresh-ca-valencia              7.6.3-2              7.6.4-1
               libreoffice-fresh-ckb              7.6.3-2              7.6.4-1
                libreoffice-fresh-cs              7.6.3-2              7.6.4-1
                libreoffice-fresh-cy              7.6.3-2              7.6.4-1
                libreoffice-fresh-da              7.6.3-2              7.6.4-1
                libreoffice-fresh-de              7.6.3-2              7.6.4-1
               libreoffice-fresh-dgo              7.6.3-2              7.6.4-1
               libreoffice-fresh-dsb              7.6.3-2              7.6.4-1
                libreoffice-fresh-dz              7.6.3-2              7.6.4-1
                libreoffice-fresh-el              7.6.3-2              7.6.4-1
             libreoffice-fresh-en-gb              7.6.3-2              7.6.4-1
             libreoffice-fresh-en-za              7.6.3-2              7.6.4-1
                libreoffice-fresh-eo              7.6.3-2              7.6.4-1
                libreoffice-fresh-es              7.6.3-2              7.6.4-1
                libreoffice-fresh-et              7.6.3-2              7.6.4-1
                libreoffice-fresh-eu              7.6.3-2              7.6.4-1
                libreoffice-fresh-fa              7.6.3-2              7.6.4-1
                libreoffice-fresh-fi              7.6.3-2              7.6.4-1
                libreoffice-fresh-fr              7.6.3-2              7.6.4-1
               libreoffice-fresh-fur              7.6.3-2              7.6.4-1
                libreoffice-fresh-fy              7.6.3-2              7.6.4-1
                libreoffice-fresh-ga              7.6.3-2              7.6.4-1
                libreoffice-fresh-gd              7.6.3-2              7.6.4-1
                libreoffice-fresh-gl              7.6.3-2              7.6.4-1
                libreoffice-fresh-gu              7.6.3-2              7.6.4-1
               libreoffice-fresh-gug              7.6.3-2              7.6.4-1
                libreoffice-fresh-he              7.6.3-2              7.6.4-1
                libreoffice-fresh-hi              7.6.3-2              7.6.4-1
                libreoffice-fresh-hr              7.6.3-2              7.6.4-1
               libreoffice-fresh-hsb              7.6.3-2              7.6.4-1
                libreoffice-fresh-hu              7.6.3-2              7.6.4-1
                libreoffice-fresh-id              7.6.3-2              7.6.4-1
                libreoffice-fresh-is              7.6.3-2              7.6.4-1
                libreoffice-fresh-it              7.6.3-2              7.6.4-1
                libreoffice-fresh-ja              7.6.3-2              7.6.4-1
                libreoffice-fresh-ka              7.6.3-2              7.6.4-1
               libreoffice-fresh-kab              7.6.3-2              7.6.4-1
                libreoffice-fresh-kk              7.6.3-2              7.6.4-1
                libreoffice-fresh-km              7.6.3-2              7.6.4-1
          libreoffice-fresh-kmr-latn              7.6.3-2              7.6.4-1
                libreoffice-fresh-kn              7.6.3-2              7.6.4-1
                libreoffice-fresh-ko              7.6.3-2              7.6.4-1
               libreoffice-fresh-kok              7.6.3-2              7.6.4-1
                libreoffice-fresh-ks              7.6.3-2              7.6.4-1
                libreoffice-fresh-lb              7.6.3-2              7.6.4-1
                libreoffice-fresh-lo              7.6.3-2              7.6.4-1
                libreoffice-fresh-lt              7.6.3-2              7.6.4-1
                libreoffice-fresh-lv              7.6.3-2              7.6.4-1
               libreoffice-fresh-mai              7.6.3-2              7.6.4-1
                libreoffice-fresh-mk              7.6.3-2              7.6.4-1
                libreoffice-fresh-ml              7.6.3-2              7.6.4-1
                libreoffice-fresh-mn              7.6.3-2              7.6.4-1
               libreoffice-fresh-mni              7.6.3-2              7.6.4-1
                libreoffice-fresh-mr              7.6.3-2              7.6.4-1
                libreoffice-fresh-my              7.6.3-2              7.6.4-1
                libreoffice-fresh-nb              7.6.3-2              7.6.4-1
                libreoffice-fresh-ne              7.6.3-2              7.6.4-1
                libreoffice-fresh-nl              7.6.3-2              7.6.4-1
                libreoffice-fresh-nn              7.6.3-2              7.6.4-1
                libreoffice-fresh-nr              7.6.3-2              7.6.4-1
               libreoffice-fresh-nso              7.6.3-2              7.6.4-1
                libreoffice-fresh-oc              7.6.3-2              7.6.4-1
                libreoffice-fresh-om              7.6.3-2              7.6.4-1
                libreoffice-fresh-or              7.6.3-2              7.6.4-1
             libreoffice-fresh-pa-in              7.6.3-2              7.6.4-1
                libreoffice-fresh-pl              7.6.3-2              7.6.4-1
                libreoffice-fresh-pt              7.6.3-2              7.6.4-1
             libreoffice-fresh-pt-br              7.6.3-2              7.6.4-1
                libreoffice-fresh-ro              7.6.3-2              7.6.4-1
                libreoffice-fresh-ru              7.6.3-2              7.6.4-1
                libreoffice-fresh-rw              7.6.3-2              7.6.4-1
             libreoffice-fresh-sa-in              7.6.3-2              7.6.4-1
               libreoffice-fresh-sat              7.6.3-2              7.6.4-1
                libreoffice-fresh-sd              7.6.3-2              7.6.4-1
               libreoffice-fresh-sdk              7.6.3-3              7.6.4-1
                libreoffice-fresh-si              7.6.3-2              7.6.4-1
               libreoffice-fresh-sid              7.6.3-2              7.6.4-1
                libreoffice-fresh-sk              7.6.3-2              7.6.4-1
                libreoffice-fresh-sl              7.6.3-2              7.6.4-1
                libreoffice-fresh-sq              7.6.3-2              7.6.4-1
                libreoffice-fresh-sr              7.6.3-2              7.6.4-1
           libreoffice-fresh-sr-latn              7.6.3-2              7.6.4-1
                libreoffice-fresh-ss              7.6.3-2              7.6.4-1
                libreoffice-fresh-st              7.6.3-2              7.6.4-1
                libreoffice-fresh-sv              7.6.3-2              7.6.4-1
             libreoffice-fresh-sw-tz              7.6.3-2              7.6.4-1
               libreoffice-fresh-szl              7.6.3-2              7.6.4-1
                libreoffice-fresh-ta              7.6.3-2              7.6.4-1
                libreoffice-fresh-te              7.6.3-2              7.6.4-1
                libreoffice-fresh-tg              7.6.3-2              7.6.4-1
                libreoffice-fresh-th              7.6.3-2              7.6.4-1
                libreoffice-fresh-tn              7.6.3-2              7.6.4-1
                libreoffice-fresh-tr              7.6.3-2              7.6.4-1
                libreoffice-fresh-ts              7.6.3-2              7.6.4-1
                libreoffice-fresh-tt              7.6.3-2              7.6.4-1
                libreoffice-fresh-ug              7.6.3-2              7.6.4-1
                libreoffice-fresh-uk              7.6.3-2              7.6.4-1
                libreoffice-fresh-uz              7.6.3-2              7.6.4-1
                libreoffice-fresh-ve              7.6.3-2              7.6.4-1
               libreoffice-fresh-vec              7.6.3-2              7.6.4-1
                libreoffice-fresh-vi              7.6.3-2              7.6.4-1
                libreoffice-fresh-xh              7.6.3-2              7.6.4-1
             libreoffice-fresh-zh-cn              7.6.3-2              7.6.4-1
             libreoffice-fresh-zh-tw              7.6.3-2              7.6.4-1
                libreoffice-fresh-zu              7.6.3-2              7.6.4-1
                   libreoffice-still              7.5.8-2              7.5.9-1
                libreoffice-still-af              7.5.8-2              7.5.9-1
                libreoffice-still-am              7.5.8-2              7.5.9-1
                libreoffice-still-ar              7.5.8-2              7.5.9-1
                libreoffice-still-as              7.5.8-2              7.5.9-1
               libreoffice-still-ast              7.5.8-2              7.5.9-1
                libreoffice-still-be              7.5.8-2              7.5.9-1
                libreoffice-still-bg              7.5.8-2              7.5.9-1
                libreoffice-still-bn              7.5.8-2              7.5.9-1
             libreoffice-still-bn-in              7.5.8-2              7.5.9-1
                libreoffice-still-bo              7.5.8-2              7.5.9-1
                libreoffice-still-br              7.5.8-2              7.5.9-1
               libreoffice-still-brx              7.5.8-2              7.5.9-1
                libreoffice-still-bs              7.5.8-2              7.5.9-1
                libreoffice-still-ca              7.5.8-2              7.5.9-1
       libreoffice-still-ca-valencia              7.5.8-2              7.5.9-1
               libreoffice-still-ckb              7.5.8-2              7.5.9-1
                libreoffice-still-cs              7.5.8-2              7.5.9-1
                libreoffice-still-cy              7.5.8-2              7.5.9-1
                libreoffice-still-da              7.5.8-2              7.5.9-1
                libreoffice-still-de              7.5.8-2              7.5.9-1
               libreoffice-still-dgo              7.5.8-2              7.5.9-1
               libreoffice-still-dsb              7.5.8-2              7.5.9-1
                libreoffice-still-dz              7.5.8-2              7.5.9-1
                libreoffice-still-el              7.5.8-2              7.5.9-1
             libreoffice-still-en-gb              7.5.8-2              7.5.9-1
             libreoffice-still-en-za              7.5.8-2              7.5.9-1
                libreoffice-still-eo              7.5.8-2              7.5.9-1
                libreoffice-still-es              7.5.8-2              7.5.9-1
                libreoffice-still-et              7.5.8-2              7.5.9-1
                libreoffice-still-eu              7.5.8-2              7.5.9-1
                libreoffice-still-fa              7.5.8-2              7.5.9-1
                libreoffice-still-fi              7.5.8-2              7.5.9-1
                libreoffice-still-fr              7.5.8-2              7.5.9-1
               libreoffice-still-fur              7.5.8-2              7.5.9-1
                libreoffice-still-fy              7.5.8-2              7.5.9-1
                libreoffice-still-ga              7.5.8-2              7.5.9-1
                libreoffice-still-gd              7.5.8-2              7.5.9-1
                libreoffice-still-gl              7.5.8-2              7.5.9-1
                libreoffice-still-gu              7.5.8-2              7.5.9-1
               libreoffice-still-gug              7.5.8-2              7.5.9-1
                libreoffice-still-he              7.5.8-2              7.5.9-1
                libreoffice-still-hi              7.5.8-2              7.5.9-1
                libreoffice-still-hr              7.5.8-2              7.5.9-1
               libreoffice-still-hsb              7.5.8-2              7.5.9-1
                libreoffice-still-hu              7.5.8-2              7.5.9-1
                libreoffice-still-id              7.5.8-2              7.5.9-1
                libreoffice-still-is              7.5.8-2              7.5.9-1
                libreoffice-still-it              7.5.8-2              7.5.9-1
                libreoffice-still-ja              7.5.8-2              7.5.9-1
                libreoffice-still-ka              7.5.8-2              7.5.9-1
               libreoffice-still-kab              7.5.8-2              7.5.9-1
                libreoffice-still-kk              7.5.8-2              7.5.9-1
                libreoffice-still-km              7.5.8-2              7.5.9-1
          libreoffice-still-kmr-latn              7.5.8-2              7.5.9-1
                libreoffice-still-kn              7.5.8-2              7.5.9-1
                libreoffice-still-ko              7.5.8-2              7.5.9-1
               libreoffice-still-kok              7.5.8-2              7.5.9-1
                libreoffice-still-ks              7.5.8-2              7.5.9-1
                libreoffice-still-lb              7.5.8-2              7.5.9-1
                libreoffice-still-lo              7.5.8-2              7.5.9-1
                libreoffice-still-lt              7.5.8-2              7.5.9-1
                libreoffice-still-lv              7.5.8-2              7.5.9-1
               libreoffice-still-mai              7.5.8-2              7.5.9-1
                libreoffice-still-mk              7.5.8-2              7.5.9-1
                libreoffice-still-ml              7.5.8-2              7.5.9-1
                libreoffice-still-mn              7.5.8-2              7.5.9-1
               libreoffice-still-mni              7.5.8-2              7.5.9-1
                libreoffice-still-mr              7.5.8-2              7.5.9-1
                libreoffice-still-my              7.5.8-2              7.5.9-1
                libreoffice-still-nb              7.5.8-2              7.5.9-1
                libreoffice-still-ne              7.5.8-2              7.5.9-1
                libreoffice-still-nl              7.5.8-2              7.5.9-1
                libreoffice-still-nn              7.5.8-2              7.5.9-1
                libreoffice-still-nr              7.5.8-2              7.5.9-1
               libreoffice-still-nso              7.5.8-2              7.5.9-1
                libreoffice-still-oc              7.5.8-2              7.5.9-1
                libreoffice-still-om              7.5.8-2              7.5.9-1
                libreoffice-still-or              7.5.8-2              7.5.9-1
             libreoffice-still-pa-in              7.5.8-2              7.5.9-1
                libreoffice-still-pl              7.5.8-2              7.5.9-1
                libreoffice-still-pt              7.5.8-2              7.5.9-1
             libreoffice-still-pt-br              7.5.8-2              7.5.9-1
                libreoffice-still-ro              7.5.8-2              7.5.9-1
                libreoffice-still-ru              7.5.8-2              7.5.9-1
                libreoffice-still-rw              7.5.8-2              7.5.9-1
             libreoffice-still-sa-in              7.5.8-2              7.5.9-1
               libreoffice-still-sat              7.5.8-2              7.5.9-1
                libreoffice-still-sd              7.5.8-2              7.5.9-1
               libreoffice-still-sdk              7.5.8-2              7.5.9-1
                libreoffice-still-si              7.5.8-2              7.5.9-1
               libreoffice-still-sid              7.5.8-2              7.5.9-1
                libreoffice-still-sk              7.5.8-2              7.5.9-1
                libreoffice-still-sl              7.5.8-2              7.5.9-1
                libreoffice-still-sq              7.5.8-2              7.5.9-1
                libreoffice-still-sr              7.5.8-2              7.5.9-1
           libreoffice-still-sr-latn              7.5.8-2              7.5.9-1
                libreoffice-still-ss              7.5.8-2              7.5.9-1
                libreoffice-still-st              7.5.8-2              7.5.9-1
                libreoffice-still-sv              7.5.8-2              7.5.9-1
             libreoffice-still-sw-tz              7.5.8-2              7.5.9-1
               libreoffice-still-szl              7.5.8-2              7.5.9-1
                libreoffice-still-ta              7.5.8-2              7.5.9-1
                libreoffice-still-te              7.5.8-2              7.5.9-1
                libreoffice-still-tg              7.5.8-2              7.5.9-1
                libreoffice-still-th              7.5.8-2              7.5.9-1
                libreoffice-still-tn              7.5.8-2              7.5.9-1
                libreoffice-still-tr              7.5.8-2              7.5.9-1
                libreoffice-still-ts              7.5.8-2              7.5.9-1
                libreoffice-still-tt              7.5.8-2              7.5.9-1
                libreoffice-still-ug              7.5.8-2              7.5.9-1
                libreoffice-still-uk              7.5.8-2              7.5.9-1
                libreoffice-still-uz              7.5.8-2              7.5.9-1
                libreoffice-still-ve              7.5.8-2              7.5.9-1
               libreoffice-still-vec              7.5.8-2              7.5.9-1
                libreoffice-still-vi              7.5.8-2              7.5.9-1
                libreoffice-still-xh              7.5.8-2              7.5.9-1
             libreoffice-still-zh-cn              7.5.8-2              7.5.9-1
             libreoffice-still-zh-tw              7.5.8-2              7.5.9-1
                libreoffice-still-zu              7.5.8-2              7.5.9-1
                           librustls             0.11.0-1             0.12.0-1
                              limine       5.20231124.0-1       5.20231207.1-1
                            luacheck              1.1.1-1              1.1.2-1
                          mailcommon            23.08.3-1            23.08.4-1
                        mailimporter            23.08.3-1            23.08.4-1
                          messagelib            23.08.3-1            23.08.4-1
                               minio         2023.12.06-1         2023.12.07-1
                               mkosi                 19-1                 19-2
                 nextcloud-app-notes              4.8.1-1              4.9.0-1
                                 npm             10.2.4-1             10.2.5-1
                             nuspell              5.1.3-1              5.1.4-1
                              ollama             0.1.12-1             0.1.13-1
                         ollama-cuda             0.1.12-2             0.1.13-1
                              ostree             2023.7-1             2023.8-1
                          pandoc-cli           0.1.1.1-24           0.1.1.1-25
                     pandoc-crossref          0.3.16.0-77          0.3.16.0-78
                         pandoc-plot             1.8.0-16             1.8.0-17
                       pg-safeupdate                1.4-3                1.4-4
                  php-legacy-mongodb             1.17.0-1             1.17.1-1
                         php-mongodb             1.17.0-1             1.17.1-1
                           pimcommon            23.08.3-1            23.08.4-1
            plasma-wayland-protocols             1.11.1-2             1.12.0-1
                             postgis              3.4.1-1              3.4.1-2
                          postgresql               15.4-2               16.1-1
                     postgresql-docs               15.4-2               16.1-1
                     postgresql-ip4r              2.4.1-3              2.4.2-1
                     postgresql-libs               15.4-2               16.1-1
              postgresql-old-upgrade               14.9-2               15.5-1
                              pulumi             3.95.0-1             3.96.0-1
                            pybind11             2.11.1-1             2.11.1-2
                               pyenv           1:2.3.34-1           1:2.3.35-1
                    python-construct            2.10.69-1            2.10.70-1
                   python-findpython              0.4.0-1              0.4.1-1
                        python-pyocd             0.35.1-1             0.36.0-1
                   python-setuptools           1:68.2.1-1           1:68.2.2-1
             python-websocket-client              1.6.4-1              1.7.0-1
                            qtractor             0.9.37-1             0.9.37-2
                          rosegarden              23.06-1              23.12-1
                            rssguard              4.5.5-2              4.6.0-1
                       rssguard-lite              4.5.5-2              4.6.0-1
                    ruby-async-rspec             1.16.1-2             1.17.0-1
                        ruby-console             1.23.2-1             1.23.3-1
                            ruby-sus             0.23.0-1             0.24.0-1
             ruby-sus-fixtures-async              0.1.2-1              0.1.3-1
                                rust           1:1.74.0-1           1:1.74.1-1
                           rust-musl           1:1.74.0-1           1:1.74.1-1
                            rust-src           1:1.74.0-1           1:1.74.1-1
                           rust-wasm           1:1.74.0-1           1:1.74.1-1
                              scrapy              2.8.0-1              2.9.0-1
                              scrcpy                2.2-1              2.3.1-1
                          sdl2_image              2.6.3-1              2.8.0-1
                             seabios             1.16.2-2             1.16.3-1
                        seabios-docs             1.16.2-2             1.16.3-1
                         sequoia-wot              0.8.1-3              0.9.0-1
                             sha3sum              1.2.3-1            1.2.3.1-1
                      signal-desktop             6.40.0-1             6.41.0-1
            signon-kwallet-extension            23.08.3-1            23.08.4-1
                          soft-serve              0.7.3-1              0.7.4-1
                               stack            2.7.5-395            2.7.5-396
                              stlink              1.7.0-1              1.7.0-2
                           texstudio              4.7.0-1              4.7.1-1
                         timescaledb             2.12.2-1             2.13.0-1
             timescaledb-old-upgrade             2.12.2-1             2.13.0-1
                          typescript              5.3.2-1              5.3.3-1
                               ugrep              4.3.5-1              4.3.6-1
                         v2ray-geoip       202311300040-1       202312070040-1
           vscode-css-languageserver             1.84.0-1             1.85.0-1
          vscode-html-languageserver             1.84.0-1             1.85.0-1
          vscode-json-languageserver             1.84.0-1             1.85.0-1
      vscode-markdown-languageserver             1.84.0-1             1.85.0-1
                           wordpress              6.4.1-1              6.4.2-1
                               xsimd             12.0.0-1             12.1.0-1
                                yarn            1.22.19-1            1.22.21-1


:: Different overlay package(s) in repository kde-unstable x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023-12-05           2023-12-08
-------------------------------------------------------------------------------
                                 ark23.08.3.r5247.g6f8092d3-123.08.3.r5249.gabe87380-1
                         audiocd-kio23.08.3.r1279.g50e9ec2-123.08.3.r1281.gb239ca4-1
                              bomber23.08.3.r693.g6a931af-123.08.3.r694.g05433f6-1
                                bovo23.08.3.r920.g1d398b0-123.08.3.r921.gc95aaad-1
                         breeze-grub5.27.9.r11.g63136a9-15.27.10.r11.g63136a9-1
                          breeze-gtk5.27.9.r521.g5d4472a-15.27.10.r522.g03517ca-1
                              disman5.27.9.r1871.geb61ea1-15.27.10.r1871.geb61ea1-1
                             drkonqi5.27.9.r1185.g64378eec-15.27.10.r1185.g64378eec-1
                               elisa23.08.3.r3610.g67733221-123.08.3.r3611.gfcd194be-1
                          elisa-qtmm23.08.3.r3610.g67733221-123.08.3.r3611.gfcd194be-1
                 extra-cmake-modules5.112.0.r3657.g11dd72b0-15.112.0.r3658.g7a90baa9-1
                            gwenview23.08.3.r7318.g5a94314b-123.08.3.r7320.g7ff12e58-1
                                 k3b1:23.08.3.r7115.g0b768c681-11:23.08.3.r7117.gf5db18596-1
                   kactivitymanagerd5.27.9.r1544.g0c48f82f-15.27.10.r1544.g0c48f82f-1
                              kalarm23.08.3.r8721.g5b9bd997-123.08.3.r8723.g187b1dbc-1
                            kalgebra23.08.3.r2265.gfebe33a9-123.08.3.r2266.gc9624c9b-1
                                kalk23.08.1.r822.g62ec66b-123.08.1.r823.g2454664-1
                              kamera23.08.3.r913.g263efdb-123.08.3.r914.ga6fb61b-1
                             kapidox5.112.0.r591.g088b93c-15.112.0.r592.g8bbdc8b-1
                              kapman23.08.3.r791.g6d4d948-123.08.3.r793.gb945a83-1
                        kapptemplate23.08.3.r1124.g0a63ca5-123.08.3.r1125.gdbba395-1
                             katomic23.08.3.r1110.g360b1ec-123.08.3.r1111.gcba9244-1
                           kblackbox23.08.3.r916.g1ca780b-123.08.3.r918.g20ba926-1
                             kblocks23.08.3.r883.gff8a11c-123.08.3.r884.gb4134c0-1
                             kbounce23.08.3.r992.g6b9902e-123.08.3.r993.g04b4159-1
                               kcalc23.08.3.r1822.g73a722b-123.08.3.r1823.g7bb8e97-1
                              kclock23.08.1.r1122.g7e8c47c-123.08.1.r1122.g7e8c47c6-1
                            kcmutils5.112.0.r1042.g40887f32-15.112.0.r1044.g98c18c7e-1
                             kconfig5.112.0.r1238.g825b7bd8-15.112.0.r1243.gf17ee3b0-1
                              kcrash5.112.0.r499.g65ef768-15.112.0.r502.g5989ed7-1
                                kdav1:5.112.0.r1433.geaa442e-11:5.112.0.r1435.g41b1fc7-1
                       kde-cli-tools5.27.9.r2256.g16ec7483-15.27.10.r2258.ga2cb42bd-1
                     kde-dev-scripts23.08.3.r4207.g61ae7b6-123.08.3.r4208.g7285072-1
                       kde-dev-utils23.08.3.r732.g0852948-123.08.3.r733.gc7c32bb-1
                      kde-gtk-config5.27.9.r1016.g2661b26-15.27.10.r1017.g55f3e9e-1
                      kdebugsettings23.08.3.r1462.g9f97aa4-123.08.3.r1464.gc127fcc-1
                         kdecoration5.27.9.r389.g25dd002-15.27.10.r390.g2452a14-1
                         kdeedu-data23.08.3.r25.gc21db76-123.08.3.r28.g5b752e6-1
              kdenetwork-filesharing23.08.3.r1152.g29ee712-123.08.3.r1154.g5e41c84-1
                            kdenlive23.08.3.r19158.g72deeb4b3-123.08.3.r19160.gf0b685dc1-1
                            kdiamond23.08.3.r853.g15e65d6-123.08.3.r854.ge765b0e-1
                            kdisplay5.27.9.r1566.gd144d8a-15.27.10.r1566.gd144d8a-1
                               kfind23.08.3.r2886.g578996431-123.08.3.r2888.g8e0ce75c9-1
                             kfloppy23.08.3.r907.g2efd040-123.08.3.r908.g673a1f4-1
                         kfourinline23.08.3.r1175.ga2f40f5-123.08.3.r1176.g066b710-1
                             kgamma55.27.9.r578.g5f30ea4-15.27.10.r578.g5f30ea4-1
                          kgeography23.08.3.r1326.g14fecfc-123.08.3.r1327.g4e71d97-1
                       kglobalacceld5.27.9.r265.g97f9a02-15.27.10.r266.g06a77d3-1
                         kgoldrunner23.08.3.r1471.gf205422-123.08.3.r1473.g73bc8e3-1
                  khealthcertificate23.08.1.r181.g4526f7b-123.08.1.r182.gb893525-1
                               ki18n5.112.0.r695.gaca5ce5-15.112.0.r696.g7ac5b68-1
                            killbots23.08.3.r939.g196dc72-123.08.3.r940.gd661ebc-1
                     kimagemapeditor23.08.3.r649.g260e35a-123.08.3.r650.ge99c881-1
                         kinfocenter5.27.9.r2574.g7b19a052-15.27.10.r2576.ge63851c3-1
                                 kio5.112.0.r6757.gf84aed61d-15.112.0.r6758.g84ef1152e-1
                           kirigami25.112.0.r4299.g37acc54b-15.112.0.r4300.g14f61171-1
                               kiten23.08.3.r1388.g65f2e27-123.08.3.r1389.gfdbe81c-1
                          kitinerary23.08.3.r3401.g695bb1f3-123.08.3.r3403.g0af253c5-1
                               kldap23.08.3.r1199.g0d23c89-123.08.3.r1200.g7de8b13-1
                                kmag23.08.3.r870.g71f6c4a-123.08.3.r874.ge9447ca-1
                kmail-account-wizard23.08.3.r1102.gc9b9dda-123.08.3.r1108.g7ced218-1
                           kmenuedit5.27.9.r1262.g4fc6ac3-15.27.10.r1263.g335321b-1
                              kmines23.08.3.r1922.ge5e13e1-123.08.3.r1923.g846a3d9-1
                          kmousetool23.08.3.r582.gdf8f947-123.08.3.r583.gc522ded-1
                              kmouth23.08.3.r896.g5ae7840-123.08.3.r897.g4350408-1
                              knotes23.08.3.r4087.g93629b01-123.08.3.r4089.gece5c33f-1
                                koko23.08.1.r967.gadc7a25-123.08.1.r968.gc5bda4e-1
                           kollision23.08.3.r655.g71b4c2c-123.08.3.r656.g4d21580-1
                         kolourpaint23.08.3.r2638.g39195091-123.08.3.r2639.gb19122de-1
                             konsole23.08.3.r9312.ga20b392bb-123.08.3.r9313.g40c57de43-1
                            kontrast23.08.3.r398.g67eed8a-123.08.3.r403.g12dd4f3-1
                           kpipewire5.27.9.r397.g710d4bf-15.27.10.r398.g991fee8-1
                             kpmcore23.08.3.r1463.g7e805b1-123.08.3.r1466.g8458d32-1
                                krdc23.08.3.r1800.g8d5981a-123.08.3.r1802.gd637d67-1
                            kreversi23.08.3.r1438.gaacf7d9-123.08.3.r1439.gab8410f-1
                              kruler23.08.3.r930.g12f7e14-123.08.3.r931.g4b3781a-1
                         ksshaskpass5.27.9.r307.g77e3d49-15.27.10.r308.g328fdbb-1
                        ksystemstats5.27.9.r350.g82299f5-15.27.10.r351.gfbe4f47-1
                            ktorrent23.08.3.r3177.g3c69ba3f-123.08.3.r3178.ge3b86d33-1
                         kwallet-pam5.27.9.r304.ge5a12fb-15.27.10.r305.g67d11f2-1
                            kwayland5.112.0.r1248.gad826a0-15.112.0.r1249.gd972c88-1
                                kwin5.27.9.r25734.g25f4732764-15.27.10.r25753.g8b54372160-1
                       kwindowsystem5.112.0.r973.gc174c48-15.112.0.r976.g125e071-1
                             kwrited5.27.9.r558.gba3e5a3-15.27.10.r559.gd9450c3-1
                      layer-shell-qt5.27.9.r108.gddb0490-15.27.10.r109.g4569e78-1
                            libkcddb23.08.3.r890.g6a44a1c-123.08.3.r892.ga1341fe-1
                        libkmahjongg23.08.3.r609.ge0c3135-123.08.3.r612.g0d3809c-1
                          libkscreen5.27.9.r1872.g8419262-15.27.10.r1874.gc928588-1
                        libksysguard5.27.9.r2786.g3da755aa-15.27.10.r2787.g06081906-1
                       marble-common23.08.3.r13798.gbd32e05fd-123.08.3.r13799.g5372ed7e8-1
                           marble-qt23.08.3.r13798.gbd32e05fd-123.08.3.r13799.g5372ed7e8-1
                  mauikit-imagetools3.0.1.r193.gf4a7c3b-13.0.1.r194.gf4fb958-1
                    partitionmanager23.08.3.r1906.g6a9bf29-123.08.3.r1910.gad15ddd-1
                        plasma-disks5.27.9.r459.g35ad407-15.27.10.r459.g35ad407-1
                     plasma-firewall5.27.9.r822.g561489e-15.27.10.r822.g561489e-1
                  plasma-integration5.27.9.r757.g756a001-15.27.10.r757.g756a001-1
                         plasma-nano5.27.9.r352.gf6e108f-15.27.10.r352.gf6e108f-1
                     plasma-settings23.08.1.r1362.g305fe7e-123.08.1.r1363.gdd147ca-1
                  plasma-thunderbolt5.27.9.r318.g27782b3-15.27.10.r318.g27782b3-1
            plasma-wayland-protocols1.4.0.r1089.g2ead53e-11.4.0.r1090.g67b0cba-1
         plasma-workspace-wallpapers5.27.9.r439.gbcef863-15.27.10.r439.gbcef863-1
                      plasma5support5.27.9.r141.g9c8bc7e-15.27.10.r142.g5db933e-1
                    polkit-kde-agent5.27.9.r637.g094b64c-15.27.10.r640.g638f260-1
                   qqc2-breeze-style5.27.9.r327.g5fcffa1-15.27.10.r327.g5fcffa1-1
                  qqc2-desktop-style5.112.0.r904.g84a46ed-15.112.0.r906.g974ad34-1
                                sddm0.19.0.r249.g132f105-10.19.0.r250.gb002d02-1
                            sddm-kcm5.27.9.r889.g01a1f60-15.27.10.r889.g01a1f60-1
                               solid5.112.0.r955.g8046b9a5-15.112.0.r956.g8831787b-1
                            spacebar23.08.1.r863.g7faf8bc-123.08.1.r864.g00be005-1
                           spectacle23.08.3.r2115.g43f7ef5e-123.08.3.r2117.gcf89a85e-1
                            wrapland5.27.9.r1883.g048a451a-15.27.10.r1883.g048a451a-1
              xdg-desktop-portal-kde5.27.9.r886.g8cc2c8b-15.27.10.r887.gbe2fd22-1


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023-12-05           2023-12-08
-------------------------------------------------------------------------------
                          lib32-curl              8.4.0-2              8.5.0-1
                         lib32-glib2             2.78.1-1             2.78.3-1
                lib32-libcurl-compat              8.4.0-2              8.5.0-1
                lib32-libcurl-gnutls              8.4.0-2              8.5.0-1

</code></pre>
<p><a href="https://forum.manjaro.org/t/testing-update-2023-12-08-kernels-kde-gear-libreoffice/152963/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
            <p><small>6 posts - 4 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2023-12-08-kernels-kde-gear-libreoffice/152963">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why Chrome Enabled WebAssembly Garbage Collection (WasmGC) By Default]]></title>
<description><![CDATA[In Chrome, JavaScript (and WebAssembly) code are both executed by Google's open source V8 engine — which already has garbage-collecting capabilities. "This means developers making use of, for example, PHP compiled to Wasm, end up shipping a garbage collector implementation of the ported language ...]]></description>
<link>https://tsecurity.de/de/1924924/it-security-nachrichten/why-chrome-enabled-webassembly-garbage-collection-wasmgc-by-default/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1924924/it-security-nachrichten/why-chrome-enabled-webassembly-garbage-collection-wasmgc-by-default/</guid>
<pubDate>Sun, 12 Nov 2023 06:49:14 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In Chrome, JavaScript (and WebAssembly) code are both executed by Google's open source V8 engine — which already has garbage-collecting capabilities. "This means developers making use of, for example, PHP compiled to Wasm, end up shipping a garbage collector implementation of the ported language (PHP) to the browser that already has a garbage collector," writes Google developer advocate Thomas Steiner, "which is as wasteful as it sounds." 

"This is where WasmGC comes in."

WebAssembly Garbage Collection (or WasmGC) is a proposal of the WebAssembly Community Group [which] adds struct and array heap types, which means support for non-linear memory allocation... In simplified terms, this means that with WasmGC, porting a programming language to WebAssembly means the programming language's garbage collector no longer needs to be part of the port, but instead the existing garbage collector can be used. 
Sometime on Halloween, Steiner wrote that in Chrome, WebAssembly garbage collection is now enabled by default. But then he explored what this means for high-level programming languages (with their own built-in garbage collection) being compiled into WebAssembly:

To verify the real-world impact of this improvement, Chrome's Wasm team has compiled versions of the Fannkuch benchmark (which allocates data structures as it works) from C, Rust, and Java. The C and Rust binaries could be anywhere from 6.1 K to 9.6 K depending on the various compiler flags, while the Java version is much smaller at only 2.3 K! C and Rust do not include a garbage collector, but they do still bundle malloc/free to manage memory, and the reason Java is smaller here is because it doesn't need to bundle any memory management code at all. This is just one specific example, but it shows that WasmGC binaries have the potential of being very small, and this is even before any significant work on optimizing for size. 

The blog post includes two examples of WasmGC-ported programming languages in action:

"One of the first programming languages that has been ported to Wasm thanks to WasmGC is Kotlin in the form of Kotlin/Wasm."
"The Dart and Flutter teams at Google are also preparing support for WasmGC. The Dart-to-Wasm compilation work is almost complete, and the team is working on tooling support for delivering Flutter web applications compiled to WebAssembly."
<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Why+Chrome+Enabled+WebAssembly+Garbage+Collection+(WasmGC)+By+Default%3A+https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F23%2F11%2F12%2F0456220%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F23%2F11%2F12%2F0456220%2Fwhy-chrome-enabled-webassembly-garbage-collection-wasmgc-by-default%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/23/11/12/0456220/why-chrome-enabled-webassembly-garbage-collection-wasmgc-by-default?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hit the bullseye detecting browser exploits abusing the X memory in WebAssembly - Edouard Bochin]]></title>
<description><![CDATA[Author: Virus Bulletin - Bewertung: 0x - Views:2 Presented at the VB2023 conference in London, 4 - 6 October 2023.
↓ Slides: https://www.virusbulletin.com/uploads/pdf/conference/vb2023/slides/Slides-Hit_the_Bullseye-Detecting_Browser_Exploits_Abusing_the_X_Memory_in_WebAssembly.pdf
↓ Paper: N/A
→...]]></description>
<link>https://tsecurity.de/de/1919910/it-security-video/hit-the-bullseye-detecting-browser-exploits-abusing-the-x-memory-in-webassembly-edouard-bochin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1919910/it-security-video/hit-the-bullseye-detecting-browser-exploits-abusing-the-x-memory-in-webassembly-edouard-bochin/</guid>
<pubDate>Tue, 07 Nov 2023 12:20:04 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/NoepZZhwA6M/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Virus Bulletin - Bewertung: 0x - Views:2 <br/></p><p><iframe id="ytplayer" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/NoepZZhwA6M?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Presented at the VB2023 conference in London, 4 - 6 October 2023.
↓ Slides: https://www.virusbulletin.com/uploads/pdf/conference/vb2023/slides/Slides-Hit_the_Bullseye-Detecting_Browser_Exploits_Abusing_the_X_Memory_in_WebAssembly.pdf
↓ Paper: N/A
→ Details: https://www.virusbulletin.com/conference/vb2023/abstracts/hit-bullseye-detecting-browser-exploits-abusing-x-memory-webassembly/

✪ PRESENTED BY ✪

• Edouard Bochin (Palo Alto Networks)

✪ ABSTRACT ✪

Return-oriented programming (ROP) has traditionally been used to bypass DEP/NX mitigation in exploits. However, in recent years, the Chromium WebAssembly (WASM) engine creates a RWX region in memory when initiating a WebAssembly instance, leading to a new exploitation technique that abuses the existing X (RWX) memory to bypass DEP/NX. This technique has become the most pervasive DEP/NX bypass exploitation technique in Chromium-based browser exploits, but the defensive side of this technique has not received much attention until now.

In this context, we introduce a new exploitation guard called WASMGuard, which is designed to detect Chromium browser exploits abusing the X (RWX) memory in WebAssembly. WASMGuard focuses on the WebAssembly RWX memory and incorporates three unique detection mechanisms on it: detecting illegal memory content changes, checking the WebAssembly compiled code and object structure integrity, and detecting shellcode in the RWX memory. The combination of these three detection mechanisms enables WASMGuard to provide comprehensive coverage and detection capabilities in different working scenarios.

In this presentation, we cover all our practices and solutions for overcoming the challenges of exploring the WebAssembly engine internals at the binary level and implementing the proof-of-concept of WASMGuard. We delve into the details of various techniques, including finding and hooking the WebAssembly export function even if it is inlined by the Turbofan optimization, optimizing performance as an inline detection module, addressing false positives caused by legitimate content changes in the WebAssembly RWX memory, and designing robust detection logic that is difficult to evade. Additionally, we showcase how WASMGuard effectively detects all known and potential future zero-day Chromium browser exploits that abuse the X (RWX) memory in WebAssembly through practical demonstrations.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Speech Synthesis Standard API]]></title>
<description><![CDATA[If I understand it correctly, then Windows has a standard OS API for speech synthesis. You can install some text-to-speech software and then other software using that API uses that program, though you might need to configure it that way.  https://learn.microsoft.com/en-us/uwp/api/windows.media.sp...]]></description>
<link>https://tsecurity.de/de/1900540/linux-tipps/speech-synthesis-standard-api/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1900540/linux-tipps/speech-synthesis-standard-api/</guid>
<pubDate>Sun, 22 Oct 2023 04:00:16 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>If I understand it correctly, then Windows has a standard OS API for speech synthesis. You can install some text-to-speech software and then other software using that API uses that program, though you might need to configure it that way. </p> <p><a href="https://learn.microsoft.com/en-us/uwp/api/windows.media.speechsynthesis?view=winrt-22621">https://learn.microsoft.com/en-us/uwp/api/windows.media.speechsynthesis?view=winrt-22621</a></p> <p>Now there are programs using this, and only supporting Windows, since the Linux distros don't have that. I just wanted to bring this to attention, since this might get important pretty fast. People creating any game or program that could run on Linux will not implement this for every TTS software that might exist. I think there should be one API for that, in every desktop environment. Looking forward to opinions and hopefully help to create some attention for this. </p> <p>One place where this came to my attention was actually some program but a relatively new and niche programming language with build in functions, for Win32 but not Linux: <a href="https://aardappel.github.io/lobster/builtin_functions_reference.html">https://aardappel.github.io/lobster/builtin_functions_reference.html</a> but this might be used for doing WASM, so related to websites, and then it could become a problem for Linux desktop users very fast, if we can't use websites with speech output because of the lack of an OS API and then support for it in the browser, for example. </p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/NoidoDev"> /u/NoidoDev </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/17dkllm/speech_synthesis_standard_api/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/17dkllm/speech_synthesis_standard_api/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s new in DevTools: Network, Console, Wasm (Chrome 113-115)]]></title>
<description><![CDATA[Author: Chrome for Developers - Bewertung: 761x - Views:18156 Chrome 113 → https://goo.gle/44URkzZ 
Chrome 114 → https://goo.gle/3pUVVDm 
Chrome 115 → https://goo.gle/3Q4v5TL 

Chapters:
0:00 - Introduction 
0:13 Override network response headers
1:34 Console settings for Autocomplete
2:06 Condit...]]></description>
<link>https://tsecurity.de/de/1893549/hacking/whats-new-in-devtools-network-console-wasm-chrome-113-115/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1893549/hacking/whats-new-in-devtools-network-console-wasm-chrome-113-115/</guid>
<pubDate>Fri, 20 Oct 2023 19:08:29 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/e8tl_yp5BQg/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Chrome for Developers - Bewertung: 761x - Views:18156 <br/></p><p><iframe id="ytplayer" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/e8tl_yp5BQg?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>Chrome 113 → https://goo.gle/44URkzZ 
Chrome 114 → https://goo.gle/3pUVVDm 
Chrome 115 → https://goo.gle/3Q4v5TL 

Chapters:
0:00 - Introduction 
0:13 Override network response headers
1:34 Console settings for Autocomplete
2:06 Conditional breakpoints shortcut
2:51 Interaction to Next Paint (INP)
3:18 Layout Shifts track
3:23 Debug web vitals information
3:37 Wasm debugging support
4:23 Bonus tip: Selector specificity 

Resources:
Wasm debugging guide → https://goo.gle/3Ompib9 
CORS demo → https://goo.gle/3K7kkfE 
Selector specificity demo → https://goo.gle/3DmLRGs 

Questions? Tweet to us:
Jecelyn Yeen →  https://goo.gle/jecfish  
Chrome DevTools →  https://goo.gle/chromedevtools  

What’s New in DevTools → https://goo.gle/NewInDevTools  
Subscribe to Google Chrome Developers → https://goo.gle/ChromeDevs  

#DevTools<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2023-05-13 - Kernels, Firefox, LibreOffice Still, KDE-git, Python]]></title>
<description><![CDATA[Hello community,
Another testing branch update with some usual package updates for you.
Recent News:
Manjaro, like many other open-source projects, relies on the generosity of its community through donations and corporate sponsorships to support its growth and development. These donations are ess...]]></description>
<link>https://tsecurity.de/de/1890635/unix-server/testing-update-2023-05-13-kernels-firefox-libreoffice-still-kde-git-python/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1890635/unix-server/testing-update-2023-05-13-kernels-firefox-libreoffice-still-kde-git-python/</guid>
<pubDate>Wed, 24 May 2023 10:35:00 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello community,</p>
<p>Another <strong>testing</strong> branch update with some usual package updates for you.</p>
<p><strong>Recent News:</strong></p>
<ul><li>Manjaro, like many other open-source projects, relies on the generosity of its community through <a href="https://manjaro.org/donate/">donations</a> and corporate sponsorships to support its growth and development. These <a href="https://manjaro.org/donate/">donations</a> are essential in covering the various expenses incurred in the operations of the project such as server costs, software development tools, infrastructure expenses, training, flying people to events or <a href="https://blog.manjaro.org/fosdem-2023/">conferences</a> and the salaries of key developers. With the help of these donations, Manjaro is able to secure the necessary financial stability that allows the project to continuously improve and remain active. If you love Manjaro, consider to <a href="https://manjaro.org/donate/">donate</a>!</li>
<li>As you might have seen some of our team were able to attend <a href="https://fosdem.org/2023/">FOSDEM 2023</a> and the conference proved to be incredibly productive for us. See <a href="https://blog.manjaro.org/fosdem-2023/">our blog post</a> for more.</li>
</ul>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2023-05-13-kernels-firefox-libreoffice-still-kde-git-python/140459/1">(click for more details)</a>
<p><strong>Notable Package Updates:</strong></p>
<ul><li>Most of our <strong>Kernels</strong> got updated</li>
<li>
<strong>Firefox</strong> is at <a href="https://www.mozilla.org/en-US/firefox/113.0.1/releasenotes/">113.0.1</a>
</li>
<li>Still branch of <strong>LibreOffice</strong> got updated to <a href="https://blog.documentfoundation.org/blog/2023/05/11/libreoffice-7-4-7/">7.4.7</a> which is the last version of that series</li>
<li>Usual <strong>KDE-git</strong>, <strong>Python</strong> and <strong>Haskell</strong> updates</li>
</ul><h2>
<a name="additional-info-1" class="anchor" href="https://forum.manjaro.org/#additional-info-1"></a>Additional Info</h2>
<p><img src="https://forum.manjaro.org/images/emoji/twitter/information_source.png?v=12" title=":information_source:" class="emoji" alt=":information_source:" loading="lazy" width="20" height="20"> You will need to rebuild any AUR Python packages that install files to site-packages or link to <code>libpython3.10.so</code>. <img src="https://forum.manjaro.org/images/emoji/twitter/information_source.png?v=12" title=":information_source:" class="emoji" alt=":information_source:" loading="lazy" width="20" height="20"></p>
<p>Print a list of of packages that have files in <code>/usr/lib/python3.10/</code> :</p>
<pre><code class="lang-auto">pacman -Qoq /usr/lib/python3.10/
</code></pre>
<p>Rebuild them all at once:*</p>
<pre><code class="lang-auto">pamac build $(pacman -Qoq /usr/lib/python3.10)
</code></pre>
<p>* Note that if any fail to build, you’ll have to rebuild what’s remaining one or a few at a time.</p>
<p>Use <code>rebuild-detector</code> to see if anything else needs to be rebuilt:</p>
<pre><code class="lang-auto">checkrebuild
</code></pre>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2023-05-13-kernels-firefox-libreoffice-still-kde-git-python/140459/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr><p><strong>Our current supported kernels</strong></p>
<ul><li>linux419 4.19.282</li>
<li>linux54 5.4.242</li>
<li>linux510 5.10.179</li>
<li>linux515 5.15.111</li>
<li>linux61 6.1.28</li>
<li>linux62 6.2.15</li>
<li>linux63 6.3.2</li>
<li>linux62-rt 6.2.0_rt3</li>
<li>linux63-rt 6.3.0_rt11</li>
</ul><p><strong>Package Changes</strong> (Sat May 13 08:41:50 CEST 2023)</p>
<ul><li>testing community x86_64:  183 new and 186 removed package(s)</li>
<li>testing core x86_64:  11 new and 11 removed package(s)</li>
<li>testing extra x86_64:  282 new and 286 removed package(s)</li>
<li>testing kde-unstable x86_64:  175 new and 175 removed package(s)</li>
<li>testing multilib x86_64:  1 new and 1 removed package(s)</li>
</ul><pre><code class="lang-auto">:: Different overlay package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023.05.11           2023.05.13
-------------------------------------------------------------------------------
               adwaita-color-schemes              0.9.1-2                    -
                  qgnomeplatform-qt5              0.9.1-2                    -
                  qgnomeplatform-qt6              0.9.1-2                    -
                           sofia-sip            1.13.14-1            1.13.15-1
                   system76-firmware             1.0.52-1             1.0.52-2
            system76-firmware-daemon             1.0.52-1             1.0.52-2


:: Different sync package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023.05.11           2023.05.13
-------------------------------------------------------------------------------
                               atril             1.26.0-3             1.26.1-1
                                  b4             0.12.2-2             0.12.2-3
                             baresip             2.10.0-3              3.1.0-1
                               bazel              6.1.2-1              6.2.0-1
                              blosc2              2.8.0-1              2.9.1-1
                             chezmoi             2.33.4-1             2.33.5-1
                                code             1.78.1-1             1.78.2-1
                                dolt              1.0.0-1              1.0.1-1
                           duplicity              1.2.2-2              1.2.3-1
                     element-desktop            1.11.31-1            1.11.31-2
                         element-web            1.11.31-1            1.11.31-2
                              embree              4.0.1-2              4.1.0-1
                          emscripten             3.1.37-1             3.1.38-1
           firefox-developer-edition            114.0b2-1            114.0b3-1
  firefox-developer-edition-i18n-ach            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-af            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-an            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-ar            114.0b2-1            114.0b3-1
  firefox-developer-edition-i18n-ast            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-az            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-be            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-bg            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-bn            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-br            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-bs            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-ca            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-ca-valencia      114.0b2-1            114.0b3-1
  firefox-developer-edition-i18n-cak            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-cs            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-cy            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-da            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-de            114.0b2-1            114.0b3-1
  firefox-developer-edition-i18n-dsb            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-el            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-en-ca            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-en-gb            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-en-us            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-eo            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-es-ar            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-es-cl            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-es-es            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-es-mx            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-et            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-eu            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-fa            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-ff            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-fi            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-fr            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-fy-nl            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-ga-ie            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-gd            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-gl            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-gn            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-gu-in            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-he            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-hi-in            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-hr            114.0b2-1            114.0b3-1
  firefox-developer-edition-i18n-hsb            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-hu            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-hy-am            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-ia            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-id            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-is            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-it            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-ja            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-ka            114.0b2-1            114.0b3-1
  firefox-developer-edition-i18n-kab            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-kk            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-km            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-kn            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-ko            114.0b2-1            114.0b3-1
  firefox-developer-edition-i18n-lij            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-lt            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-lv            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-mk            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-mr            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-ms            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-my            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-nb-no            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-ne-np            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-nl            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-nn-no            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-oc            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-pa-in            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-pl            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-pt-br            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-pt-pt            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-rm            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-ro            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-ru            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-si            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-sk            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-sl            114.0b2-1            114.0b3-1
  firefox-developer-edition-i18n-son            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-sq            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-sr            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-sv-se            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-ta            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-te            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-th            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-tl            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-tr            114.0b2-1            114.0b3-1
  firefox-developer-edition-i18n-trs            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-uk            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-ur            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-uz            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-vi            114.0b2-1            114.0b3-1
   firefox-developer-edition-i18n-xh            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-zh-cn            114.0b2-1            114.0b3-1
firefox-developer-edition-i18n-zh-tw            114.0b2-1            114.0b3-1
                      fsverity-utils                1.5-2                1.5-3
                               fwupd             1.8.14-1             1.8.15-1
                              ghidra             10.2.3-1               10.3-1
                               gopls             0.11.0-1             0.11.0-2
                                hdf5             1.14.0-2             1.14.1-1
                        hdf5-openmpi             1.14.0-3             1.14.1-1
                            libmupdf             1.22.0-1             1.22.1-1
                               libre             2.10.0-1              3.1.0-1
                              librem             2.10.0-1                    -
                                mage             1.14.0-1             1.15.0-1
                               marco             1.26.1-1             1.26.2-1
                          mate-panel             1.26.2-1             1.26.3-1
                               mupdf             1.22.0-1             1.22.1-1
                            mupdf-gl             1.22.0-1             1.22.1-1
                         mupdf-tools             1.22.0-1             1.22.1-1
                             neomutt           20230407-1           20230512-1
                                 oil             0.14.2-1             0.15.0-1
                             pyright            1.1.307-1            1.1.308-1
                   python-apeye-core              1.1.0-2              1.1.2-1
                  python-autodocsumm             0.2.10-2             0.2.11-1
               python-beautifulsoup4             4.11.2-3             4.12.2-1
                       python-blosc2              2.2.0-4              2.2.2-1
                   python-css-parser              1.0.8-3              1.0.9-1
                  python-cython-lint             0.12.4-2             0.15.0-1
                     python-dict2css              0.2.4-2              0.3.0-1
                    python-dist-meta              0.6.0-2              0.8.0-1
                         python-dkim              1.1.3-1              1.1.4-1
                       python-docker              6.1.1-1              6.1.2-1
                     python-docutils             1:0.19-6             1:0.20-1
                     python-dom-toml              0.6.0-2              0.6.1-1
           python-domdf-python-tools              3.6.0-2              3.6.1-1
                      python-dunamai             1.15.0-2             1.16.0-1
            python-flake8-docstrings              1.6.0-4              1.7.0-1
                    python-geopandas             0.12.2-2             0.13.0-1
       python-hatch-requirements-txt              0.3.0-2              0.4.0-1
                   python-lsp-server              1.7.2-2              1.7.2-3
                        python-minio             7.1.13-2             7.1.14-1
    python-poetry-dynamic-versioning             0.21.3-2             0.21.4-1
                      python-psycopg              3.1.8-2              3.1.9-1
                 python-psycopg-pool              3.1.6-2              3.1.7-1
                    python-puremagic               1.14-3               1.15-1
                     python-pydrive2             1.15.0-2             1.15.3-1
             python-pyproject-parser              0.7.0-2              0.8.0-1
                        python-redis              4.4.0-3              4.5.5-1
                         python-ruff            0.0.265-1            0.0.267-1
                      python-shapely        1.8.5.post1-2              2.0.1-1
                python-shippinglabel              1.4.1-2              1.5.0-1
                    python-soupsieve                2.4-3              2.4.1-1
                       python-sphinx              7.0.0-1              7.0.1-1
                     python-txtorcon             22.0.0-2             23.0.0-1
                         python-whey             0.0.23-2             0.0.24-1
                  qgnomeplatform-qt5              0.9.1-1              0.9.1-3
                  qgnomeplatform-qt6              0.9.1-1              0.9.1-3
                                repo               2.32-1               2.33-1
                  ruby-benchmark-ips             2.11.0-1             2.12.0-1
                        ruby-bundler              2.4.1-1             2.4.12-1
                     ruby-chef-utils             18.2.7-1            18.2.25-1
                           ruby-dbus             0.20.0-1             0.22.0-1
                                ruff            0.0.265-1            0.0.267-1
                            ruff-lsp             0.0.25-1             0.0.27-1
                      signal-desktop             6.17.0-1             6.17.1-1
                                sqlc             1.17.2-1             1.18.0-1
                           ssh-audit              2.5.0-3              2.9.0-1
                                sssd              2.8.2-2              2.9.0-1
                            step-cli             0.24.3-1             0.24.4-1
                         stratis-cli              3.4.0-2              3.4.0-3
                                tldr              3.1.0-5              3.2.0-1
                           wasm-pack             0.10.3-2             0.11.1-1
                                wgcf             2.2.15-1             2.2.16-1
                               ytfzf              2.5.5-1              2.6.0-1
               adwaita-color-schemes                    -              0.9.1-3


:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023.05.11           2023.05.13
-------------------------------------------------------------------------------
                            linux515           5.15.110-2           5.15.111-1
                    linux515-headers           5.15.110-2           5.15.111-1
                             linux61             6.1.27-2             6.1.28-1
                     linux61-headers             6.1.27-2             6.1.28-1
                             linux62             6.2.14-2             6.2.15-1
                     linux62-headers             6.2.14-2             6.2.15-1
                             linux63              6.3.1-3              6.3.2-1
                     linux63-headers              6.3.1-3              6.3.2-1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023.05.11           2023.05.13
-------------------------------------------------------------------------------
                              libbpf              1.1.0-1              1.2.0-1
                          libnghttp2             1.52.0-2             1.53.0-1
                            tpm2-tss              3.2.0-3              4.0.1-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023.05.11           2023.05.13
-------------------------------------------------------------------------------
               gtk-update-icon-cache         1:4.10.3-1.0                    -
                                gtk4         1:4.10.3-1.0                    -
                          gtk4-demos         1:4.10.3-1.0                    -
                           gtk4-docs         1:4.10.3-1.0                    -
                  linux515-acpi_call            1.2.2-117            1.2.2-118
                   linux515-bbswitch              0.8-132              0.8-133
                linux515-broadcom-wl     6.30.223.271-132     6.30.223.271-133
               linux515-nvidia-390xx           390.157-37           390.157-38
               linux515-nvidia-470xx         470.182.03-8         470.182.03-9
                     linux515-nvidia          530.41.03-8          530.41.03-9
                      linux515-r8168          8.050.03-63          8.050.03-64
                  linux515-rtl8723bu          20220818-53          20220818-54
                   linux515-tp_smapi             0.43-132             0.43-133
                linux515-vhba-module         20211218-113         20211218-114
    linux515-virtualbox-host-modules              7.0.8-5              7.0.8-6
                        linux515-zfs             2.1.11-4             2.1.11-5
                   linux61-acpi_call             1.2.2-33             1.2.2-34
                    linux61-bbswitch               0.8-33               0.8-34
                 linux61-broadcom-wl      6.30.223.271-33      6.30.223.271-34
                linux61-nvidia-390xx           390.157-33           390.157-34
                linux61-nvidia-470xx         470.182.03-8         470.182.03-9
                      linux61-nvidia          530.41.03-8          530.41.03-9
                       linux61-r8168          8.050.03-33          8.050.03-34
                   linux61-rtl8723bu          20220818-33          20220818-34
                    linux61-tp_smapi              0.43-33              0.43-34
                 linux61-vhba-module          20211218-33          20211218-34
     linux61-virtualbox-host-modules              7.0.8-5              7.0.8-6
                         linux61-zfs             2.1.11-4             2.1.11-5
                   linux62-acpi_call             1.2.2-18             1.2.2-19
                    linux62-bbswitch               0.8-18               0.8-19
                 linux62-broadcom-wl      6.30.223.271-18      6.30.223.271-19
                linux62-nvidia-390xx           390.157-18           390.157-19
                linux62-nvidia-470xx         470.182.03-9        470.182.03-10
                      linux62-nvidia          530.41.03-9         530.41.03-10
                       linux62-r8168          8.050.03-18          8.050.03-19
                   linux62-rtl8723bu          20220818-18          20220818-19
                    linux62-tp_smapi              0.43-18              0.43-19
                 linux62-vhba-module          20211218-18          20211218-19
     linux62-virtualbox-host-modules              7.0.8-5              7.0.8-6
                         linux62-zfs             2.1.11-4             2.1.11-5
                   linux63-acpi_call              1.2.2-5              1.2.2-6
                    linux63-bbswitch                0.8-5                0.8-6
                 linux63-broadcom-wl       6.30.223.271-5       6.30.223.271-6
                linux63-nvidia-390xx            390.157-5            390.157-6
                linux63-nvidia-470xx         470.182.03-5         470.182.03-6
                      linux63-nvidia          530.41.03-5          530.41.03-6
                       linux63-r8168           8.050.03-5           8.050.03-6
                   linux63-rtl8723bu           20220818-5           20220818-6
                    linux63-tp_smapi               0.43-5               0.43-6
                 linux63-vhba-module           20211218-5           20211218-6
     linux63-virtualbox-host-modules              7.0.8-5              7.0.8-6
                               snapd             2.59.1-1             2.59.4-1


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023.05.11           2023.05.13
-------------------------------------------------------------------------------
                             ddcutil              1.3.0-1              1.4.1-1
                             firefox              113.0-1            113.0.1-1
                    firefox-i18n-ach              113.0-1            113.0.1-1
                     firefox-i18n-af              113.0-1            113.0.1-1
                     firefox-i18n-an              113.0-1            113.0.1-1
                     firefox-i18n-ar              113.0-1            113.0.1-1
                    firefox-i18n-ast              113.0-1            113.0.1-1
                     firefox-i18n-az              113.0-1            113.0.1-1
                     firefox-i18n-be              113.0-1            113.0.1-1
                     firefox-i18n-bg              113.0-1            113.0.1-1
                     firefox-i18n-bn              113.0-1            113.0.1-1
                     firefox-i18n-br              113.0-1            113.0.1-1
                     firefox-i18n-bs              113.0-1            113.0.1-1
                     firefox-i18n-ca              113.0-1            113.0.1-1
            firefox-i18n-ca-valencia              113.0-1            113.0.1-1
                    firefox-i18n-cak              113.0-1            113.0.1-1
                     firefox-i18n-cs              113.0-1            113.0.1-1
                     firefox-i18n-cy              113.0-1            113.0.1-1
                     firefox-i18n-da              113.0-1            113.0.1-1
                     firefox-i18n-de              113.0-1            113.0.1-1
                    firefox-i18n-dsb              113.0-1            113.0.1-1
                     firefox-i18n-el              113.0-1            113.0.1-1
                  firefox-i18n-en-ca              113.0-1            113.0.1-1
                  firefox-i18n-en-gb              113.0-1            113.0.1-1
                  firefox-i18n-en-us              113.0-1            113.0.1-1
                     firefox-i18n-eo              113.0-1            113.0.1-1
                  firefox-i18n-es-ar              113.0-1            113.0.1-1
                  firefox-i18n-es-cl              113.0-1            113.0.1-1
                  firefox-i18n-es-es              113.0-1            113.0.1-1
                  firefox-i18n-es-mx              113.0-1            113.0.1-1
                     firefox-i18n-et              113.0-1            113.0.1-1
                     firefox-i18n-eu              113.0-1            113.0.1-1
                     firefox-i18n-fa              113.0-1            113.0.1-1
                     firefox-i18n-ff              113.0-1            113.0.1-1
                     firefox-i18n-fi              113.0-1            113.0.1-1
                     firefox-i18n-fr              113.0-1            113.0.1-1
                  firefox-i18n-fy-nl              113.0-1            113.0.1-1
                  firefox-i18n-ga-ie              113.0-1            113.0.1-1
                     firefox-i18n-gd              113.0-1            113.0.1-1
                     firefox-i18n-gl              113.0-1            113.0.1-1
                     firefox-i18n-gn              113.0-1            113.0.1-1
                  firefox-i18n-gu-in              113.0-1            113.0.1-1
                     firefox-i18n-he              113.0-1            113.0.1-1
                  firefox-i18n-hi-in              113.0-1            113.0.1-1
                     firefox-i18n-hr              113.0-1            113.0.1-1
                    firefox-i18n-hsb              113.0-1            113.0.1-1
                     firefox-i18n-hu              113.0-1            113.0.1-1
                  firefox-i18n-hy-am              113.0-1            113.0.1-1
                     firefox-i18n-ia              113.0-1            113.0.1-1
                     firefox-i18n-id              113.0-1            113.0.1-1
                     firefox-i18n-is              113.0-1            113.0.1-1
                     firefox-i18n-it              113.0-1            113.0.1-1
                     firefox-i18n-ja              113.0-1            113.0.1-1
                     firefox-i18n-ka              113.0-1            113.0.1-1
                    firefox-i18n-kab              113.0-1            113.0.1-1
                     firefox-i18n-kk              113.0-1            113.0.1-1
                     firefox-i18n-km              113.0-1            113.0.1-1
                     firefox-i18n-kn              113.0-1            113.0.1-1
                     firefox-i18n-ko              113.0-1            113.0.1-1
                    firefox-i18n-lij              113.0-1            113.0.1-1
                     firefox-i18n-lt              113.0-1            113.0.1-1
                     firefox-i18n-lv              113.0-1            113.0.1-1
                     firefox-i18n-mk              113.0-1            113.0.1-1
                     firefox-i18n-mr              113.0-1            113.0.1-1
                     firefox-i18n-ms              113.0-1            113.0.1-1
                     firefox-i18n-my              113.0-1            113.0.1-1
                  firefox-i18n-nb-no              113.0-1            113.0.1-1
                  firefox-i18n-ne-np              113.0-1            113.0.1-1
                     firefox-i18n-nl              113.0-1            113.0.1-1
                  firefox-i18n-nn-no              113.0-1            113.0.1-1
                     firefox-i18n-oc              113.0-1            113.0.1-1
                  firefox-i18n-pa-in              113.0-1            113.0.1-1
                     firefox-i18n-pl              113.0-1            113.0.1-1
                  firefox-i18n-pt-br              113.0-1            113.0.1-1
                  firefox-i18n-pt-pt              113.0-1            113.0.1-1
                     firefox-i18n-rm              113.0-1            113.0.1-1
                     firefox-i18n-ro              113.0-1            113.0.1-1
                     firefox-i18n-ru              113.0-1            113.0.1-1
                    firefox-i18n-sco              113.0-1            113.0.1-1
                     firefox-i18n-si              113.0-1            113.0.1-1
                     firefox-i18n-sk              113.0-1            113.0.1-1
                     firefox-i18n-sl              113.0-1            113.0.1-1
                    firefox-i18n-son              113.0-1            113.0.1-1
                     firefox-i18n-sq              113.0-1            113.0.1-1
                     firefox-i18n-sr              113.0-1            113.0.1-1
                  firefox-i18n-sv-se              113.0-1            113.0.1-1
                    firefox-i18n-szl              113.0-1            113.0.1-1
                     firefox-i18n-ta              113.0-1            113.0.1-1
                     firefox-i18n-te              113.0-1            113.0.1-1
                     firefox-i18n-th              113.0-1            113.0.1-1
                     firefox-i18n-tl              113.0-1            113.0.1-1
                     firefox-i18n-tr              113.0-1            113.0.1-1
                    firefox-i18n-trs              113.0-1            113.0.1-1
                     firefox-i18n-uk              113.0-1            113.0.1-1
                     firefox-i18n-ur              113.0-1            113.0.1-1
                     firefox-i18n-uz              113.0-1            113.0.1-1
                     firefox-i18n-vi              113.0-1            113.0.1-1
                     firefox-i18n-xh              113.0-1            113.0.1-1
                  firefox-i18n-zh-cn              113.0-1            113.0.1-1
                  firefox-i18n-zh-tw              113.0-1            113.0.1-1
               gtk-update-icon-cache           1:4.10.3-1           1:4.10.3-2
                                gtk4           1:4.10.3-1           1:4.10.3-2
                          gtk4-demos           1:4.10.3-1           1:4.10.3-2
                           gtk4-docs           1:4.10.3-1           1:4.10.3-2
                   libreoffice-still              7.4.6-2              7.4.7-1
                libreoffice-still-af              7.4.6-1              7.4.7-1
                libreoffice-still-am              7.4.6-1              7.4.7-1
                libreoffice-still-ar              7.4.6-1              7.4.7-1
                libreoffice-still-as              7.4.6-1              7.4.7-1
               libreoffice-still-ast              7.4.6-1              7.4.7-1
                libreoffice-still-be              7.4.6-1              7.4.7-1
                libreoffice-still-bg              7.4.6-1              7.4.7-1
                libreoffice-still-bn              7.4.6-1              7.4.7-1
             libreoffice-still-bn-in              7.4.6-1              7.4.7-1
                libreoffice-still-bo              7.4.6-1              7.4.7-1
                libreoffice-still-br              7.4.6-1              7.4.7-1
               libreoffice-still-brx              7.4.6-1              7.4.7-1
                libreoffice-still-bs              7.4.6-1              7.4.7-1
                libreoffice-still-ca              7.4.6-1              7.4.7-1
       libreoffice-still-ca-valencia              7.4.6-1              7.4.7-1
               libreoffice-still-ckb              7.4.6-1              7.4.7-1
                libreoffice-still-cs              7.4.6-1              7.4.7-1
                libreoffice-still-cy              7.4.6-1              7.4.7-1
                libreoffice-still-da              7.4.6-1              7.4.7-1
                libreoffice-still-de              7.4.6-1              7.4.7-1
               libreoffice-still-dgo              7.4.6-1              7.4.7-1
               libreoffice-still-dsb              7.4.6-1              7.4.7-1
                libreoffice-still-dz              7.4.6-1              7.4.7-1
                libreoffice-still-el              7.4.6-1              7.4.7-1
             libreoffice-still-en-gb              7.4.6-1              7.4.7-1
             libreoffice-still-en-za              7.4.6-1              7.4.7-1
                libreoffice-still-eo              7.4.6-1              7.4.7-1
                libreoffice-still-es              7.4.6-1              7.4.7-1
                libreoffice-still-et              7.4.6-1              7.4.7-1
                libreoffice-still-eu              7.4.6-1              7.4.7-1
                libreoffice-still-fa              7.4.6-1              7.4.7-1
                libreoffice-still-fi              7.4.6-1              7.4.7-1
                libreoffice-still-fr              7.4.6-1              7.4.7-1
               libreoffice-still-fur              7.4.6-1              7.4.7-1
                libreoffice-still-fy              7.4.6-1              7.4.7-1
                libreoffice-still-ga              7.4.6-1              7.4.7-1
                libreoffice-still-gd              7.4.6-1              7.4.7-1
                libreoffice-still-gl              7.4.6-1              7.4.7-1
                libreoffice-still-gu              7.4.6-1              7.4.7-1
               libreoffice-still-gug              7.4.6-1              7.4.7-1
                libreoffice-still-he              7.4.6-1              7.4.7-1
                libreoffice-still-hi              7.4.6-1              7.4.7-1
                libreoffice-still-hr              7.4.6-1              7.4.7-1
               libreoffice-still-hsb              7.4.6-1              7.4.7-1
                libreoffice-still-hu              7.4.6-1              7.4.7-1
                libreoffice-still-id              7.4.6-1              7.4.7-1
                libreoffice-still-is              7.4.6-1              7.4.7-1
                libreoffice-still-it              7.4.6-1              7.4.7-1
                libreoffice-still-ja              7.4.6-1              7.4.7-1
                libreoffice-still-ka              7.4.6-1              7.4.7-1
               libreoffice-still-kab              7.4.6-1              7.4.7-1
                libreoffice-still-kk              7.4.6-1              7.4.7-1
                libreoffice-still-km              7.4.6-1              7.4.7-1
          libreoffice-still-kmr-latn              7.4.6-1              7.4.7-1
                libreoffice-still-kn              7.4.6-1              7.4.7-1
                libreoffice-still-ko              7.4.6-1              7.4.7-1
               libreoffice-still-kok              7.4.6-1              7.4.7-1
                libreoffice-still-ks              7.4.6-1              7.4.7-1
                libreoffice-still-lb              7.4.6-1              7.4.7-1
                libreoffice-still-lo              7.4.6-1              7.4.7-1
                libreoffice-still-lt              7.4.6-1              7.4.7-1
                libreoffice-still-lv              7.4.6-1              7.4.7-1
               libreoffice-still-mai              7.4.6-1              7.4.7-1
                libreoffice-still-mk              7.4.6-1              7.4.7-1
                libreoffice-still-ml              7.4.6-1              7.4.7-1
                libreoffice-still-mn              7.4.6-1              7.4.7-1
               libreoffice-still-mni              7.4.6-1              7.4.7-1
                libreoffice-still-mr              7.4.6-1              7.4.7-1
                libreoffice-still-my              7.4.6-1              7.4.7-1
                libreoffice-still-nb              7.4.6-1              7.4.7-1
                libreoffice-still-ne              7.4.6-1              7.4.7-1
                libreoffice-still-nl              7.4.6-1              7.4.7-1
                libreoffice-still-nn              7.4.6-1              7.4.7-1
                libreoffice-still-nr              7.4.6-1              7.4.7-1
               libreoffice-still-nso              7.4.6-1              7.4.7-1
                libreoffice-still-oc              7.4.6-1              7.4.7-1
                libreoffice-still-om              7.4.6-1              7.4.7-1
                libreoffice-still-or              7.4.6-1              7.4.7-1
             libreoffice-still-pa-in              7.4.6-1              7.4.7-1
                libreoffice-still-pl              7.4.6-1              7.4.7-1
                libreoffice-still-pt              7.4.6-1              7.4.7-1
             libreoffice-still-pt-br              7.4.6-1              7.4.7-1
                libreoffice-still-ro              7.4.6-1              7.4.7-1
                libreoffice-still-ru              7.4.6-1              7.4.7-1
                libreoffice-still-rw              7.4.6-1              7.4.7-1
             libreoffice-still-sa-in              7.4.6-1              7.4.7-1
               libreoffice-still-sat              7.4.6-1              7.4.7-1
                libreoffice-still-sd              7.4.6-1              7.4.7-1
               libreoffice-still-sdk              7.4.6-2              7.4.7-1
                libreoffice-still-si              7.4.6-1              7.4.7-1
               libreoffice-still-sid              7.4.6-1              7.4.7-1
                libreoffice-still-sk              7.4.6-1              7.4.7-1
                libreoffice-still-sl              7.4.6-1              7.4.7-1
                libreoffice-still-sq              7.4.6-1              7.4.7-1
                libreoffice-still-sr              7.4.6-1              7.4.7-1
           libreoffice-still-sr-latn              7.4.6-1              7.4.7-1
                libreoffice-still-ss              7.4.6-1              7.4.7-1
                libreoffice-still-st              7.4.6-1              7.4.7-1
                libreoffice-still-sv              7.4.6-1              7.4.7-1
             libreoffice-still-sw-tz              7.4.6-1              7.4.7-1
               libreoffice-still-szl              7.4.6-1              7.4.7-1
                libreoffice-still-ta              7.4.6-1              7.4.7-1
                libreoffice-still-te              7.4.6-1              7.4.7-1
                libreoffice-still-tg              7.4.6-1              7.4.7-1
                libreoffice-still-th              7.4.6-1              7.4.7-1
                libreoffice-still-tn              7.4.6-1              7.4.7-1
                libreoffice-still-tr              7.4.6-1              7.4.7-1
                libreoffice-still-ts              7.4.6-1              7.4.7-1
                libreoffice-still-tt              7.4.6-1              7.4.7-1
                libreoffice-still-ug              7.4.6-1              7.4.7-1
                libreoffice-still-uk              7.4.6-1              7.4.7-1
                libreoffice-still-uz              7.4.6-1              7.4.7-1
                libreoffice-still-ve              7.4.6-1              7.4.7-1
               libreoffice-still-vec              7.4.6-1              7.4.7-1
                libreoffice-still-vi              7.4.6-1              7.4.7-1
                libreoffice-still-xh              7.4.6-1              7.4.7-1
             libreoffice-still-zh-cn              7.4.6-1              7.4.7-1
             libreoffice-still-zh-tw              7.4.6-1              7.4.7-1
                libreoffice-still-zu              7.4.6-1              7.4.7-1
                             openvpn              2.6.3-1              2.6.4-1
                      qtkeychain-qt5             0.13.2-1             0.14.0-1
                      qtkeychain-qt6             0.13.2-1             0.14.0-1
                        sof-firmware              2.2.4-1              2.2.5-1
                           sof-tools              2.2.4-1              2.2.5-1
                            tracker3              3.5.1-1              3.5.2-1
                       tracker3-docs              3.5.1-1              3.5.2-1
                     tracker3-miners              3.5.1-2              3.5.2-1
                            valgrind             3.20.0-1             3.21.0-1
                               xaw3d              1.6.4-1              1.6.5-1


:: Different overlay package(s) in repository kde-unstable x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023.05.11           2023.05.13
-------------------------------------------------------------------------------
                             akonadi23.04.0.r13067.g0763800ae-123.04.1.r13067.g0763800ae-1
                    akonadi-calendar23.04.0.r2358.gbe99ca8-123.04.1.r2359.g8412ed2-1
                    akonadi-contacts23.04.0.r3469.g403eec0d-123.04.1.r3469.g403eec0d-1
               akonadi-import-wizard23.04.0.r1933.g3b81c3f-123.04.1.r1933.g3b81c3f-1
                        akonadi-mime23.04.0.r1870.g13a5a9d-123.04.1.r1870.g13a5a9d-1
                       akonadi-notes23.04.0.r1167.g415c48d-123.04.1.r1167.g415c48d-1
                      akonadi-search23.04.0.r1388.gc0cc63b-123.04.1.r1388.gc0cc63b-1
                           akregator23.04.0.r6716.g99fc6b19-123.04.0.r6718.g37645d06-1
                            analitza23.04.0.r2393.g58206c7b-123.04.1.r2394.ge44a273c-1
                                 ark23.04.0.r5071.g41fab57f-123.04.0.r5073.g9d3581b2-1
                          artikulate23.04.0.r1516.g7025169-123.04.1.r1516.g7025169-1
                         audiocd-kio23.04.0.r1202.gca4351f-123.04.1.r1202.gca4351f-1
                               baloo5.105.0.r3214.g50f02d99-15.105.0.r3216.g25195071-1
                       baloo-widgets23.04.0.r868.g5117981-123.04.1.r868.g5117981-1
                             blinken23.04.0.r736.ga09eef1-123.04.1.r736.ga09eef1-1
                              bomber23.04.0.r632.g6044764-123.04.1.r632.g6044764-1
                                bovo23.04.0.r853.g581f959-123.04.1.r853.g581f959-1
                                buho 2.2.2.r22.g6dbb5ec-1 2.2.2.r24.g04b38cf-1
                              cantor23.04.0.r3583.gb6c88e8d-123.04.0.r3584.g31ac9290-1
                             dolphin23.04.0.r7396.g629a5d44d-123.04.1.r7397.g8f0167372-1
                              dragon23.04.0.r1186.ge05fe4c-123.04.1.r1186.ge05fe4c-1
                               elisa23.04.0.r3300.g06a135bb-123.04.1.r3302.ge0c3b37d-1
                          elisa-qtmm23.04.0.r3300.g06a135bb-123.04.1.r3302.ge0c3b37d-1
                        ffmpegthumbs23.04.0.r262.g945a606-123.04.1.r262.g945a606-1
                           granatier23.04.0.r1047.g2d3fd03-123.04.1.r1047.g2d3fd03-1
                       grantleetheme23.04.0.r501.g2436869-123.04.1.r501.g2436869-1
                            gwenview23.04.0.r7133.g0a82e831-123.04.1.r7134.gda8985a8-1
                     incidenceeditor23.04.0.r1043.ge965704-123.04.1.r1044.g1134873-1
                           itinerary23.04.0.r2621.gb3c90de9-123.04.0.r2623.g9cb1a28d-1
                                 juk23.04.0.r3260.gb6efd8d2-123.04.1.r3260.gb6efd8d2-1
                                 k3b1:23.04.0.r6986.g12fdf0b92-11:23.04.1.r6987.gf00d31b50-1
               kaccounts-integration23.04.0.r1358.gd634630-123.04.1.r1358.gd634630-1
                 kaccounts-providers23.04.0.r439.g0cb60fd-123.04.1.r439.g0cb60fd-1
                        kaddressbook23.04.0.r6412.gb384a76e-123.04.1.r6412.gb384a76e-1
                             kajongg23.04.0.r4414.g6c12331b-123.04.1.r4414.g6c12331b-1
                            kalgebra23.04.0.r2158.gb992b47-123.04.1.r2158.gb992b47-1
                             kalzium23.04.0.r4509.g685f9d9a-123.04.0.r4510.g2786bc9d-1
                              kamera23.04.0.r825.g22355d1-123.04.1.r825.g22355d1-1
                            kanagram23.04.0.r1402.g698d610-123.04.1.r1402.g698d610-1
                              kapman23.04.0.r728.g1b0d6c3-123.04.1.r728.g1b0d6c3-1
                               kasts23.01.0.r142.gf69366f-123.01.0.r145.g229190f-1
                                kate23.04.0.r20666.g3d3b8bb6e-123.04.0.r20669.gae1e66445-1
                             katomic23.04.0.r1041.g512220c-123.04.1.r1041.g512220c-1
                           kblackbox23.04.0.r842.g5921b89-123.04.1.r842.g5921b89-1
                             kblocks23.04.0.r821.gf56d749-123.04.1.r821.gf56d749-1
                             kbounce23.04.0.r927.gacf8c35-123.04.1.r927.gacf8c35-1
                           kbreakout23.04.0.r996.ga458365-123.04.1.r996.ga458365-1
                              kbruch23.04.0.r952.g4053eb1-123.04.1.r952.g4053eb1-1
                           kcalutils23.04.0.r1079.ged6e140a3-123.04.1.r1079.ged6e140a3-1
                            kcmutils5.105.0.r742.gd227bd4e-15.105.0.r743.gceafeb96-1
                       kcolorchooser23.04.0.r333.gc8f8a13-123.04.1.r333.gc8f8a13-1
                      kconfigwidgets5.105.0.r900.gc30df5d5-15.105.0.r902.g66ccbcf9-1
                      kdebugsettings23.04.0.r1210.gdc2746c-123.04.0.r1222.ge401b75-1
                         kdeedu-data23.04.0.r22.g793df3b-123.04.1.r22.g793df3b-1
              kdegraphics-mobipocket23.04.0.r290.g16b2e58-123.04.1.r290.g16b2e58-1
                            kdenlive23.04.0.r18013.g3ef0a7749-123.04.0.r18026.g9bc988464-1
                       kdepim-addons23.04.0.r5259.g12ec8cebe-123.04.0.r5261.gcb1ab84bd-1
                      kdepim-runtime23.04.0.r15904.g5d43f96b5-123.04.1.r15905.g42c0d565a-1
                    kdeplasma-addons5.27.5.r9382.ge3e9a321d-15.27.5.r9384.g0133877ce-1
                            kdiamond23.04.0.r795.g86f666d-123.04.1.r795.g86f666d-1
                         kfourinline23.04.0.r1105.g91cc913-123.04.1.r1105.g91cc913-1
                          kgeography23.04.0.r1250.g5c32c42-123.04.1.r1250.g5c32c42-1
                         kgoldrunner23.04.0.r1374.g4b09fb4-123.04.1.r1374.g4b09fb4-1
                            khangman23.04.0.r1695.ge754745-123.04.1.r1695.ge754745-1
                           kholidays1:5.105.0.r1127.g11c9194-11:5.105.0.r1128.gf1f5c94-1
                 kidentitymanagement23.04.0.r4002.g09e00247-123.04.1.r4003.g7560ef5e-1
                                 kig23.04.0.r3334.g2876231c-123.04.1.r3334.g2876231c-1
                                kigo23.04.0.r653.g2ba8c26-123.04.1.r653.g2ba8c26-1
                            killbots23.04.0.r870.g483f166-123.04.1.r870.g483f166-1
                     kimagemapeditor23.04.0.r579.g36f8272-123.04.1.r579.g36f8272-1
                               kimap23.04.0.r1297.gd9e70b7-123.04.1.r1298.g2c78875-1
                                 kio5.105.0.r6169.gcaab46fa8-15.105.0.r6170.g3b8852c29-1
                           kirigami25.105.0.r3695.g20baedd5-15.105.0.r3697.g9df90525-1
                              kiriki23.04.0.r530.g1c11c4a-123.04.1.r530.g1c11c4a-1
                               kiten23.04.0.r1279.ga3bbc8a-123.04.1.r1279.ga3bbc8a-1
                          kitinerary23.04.0.r2860.ga91a3030-123.04.1.r2872.gb105b55c-1
                        kjumpingcube23.04.0.r914.ge87795e-123.04.1.r914.ge87795e-1
                               kldap23.04.0.r1088.g02ffc6c-123.04.1.r1089.g0eccfcb-1
                            klettres23.04.0.r1045.gf29e783-123.04.1.r1045.gf29e783-1
                            klickety23.04.0.r772.g573553a-123.04.1.r772.g573553a-1
                              klines23.04.0.r890.g15bad9e-123.04.1.r890.g15bad9e-1
                                kmag23.04.0.r814.gde9d65e-123.04.1.r814.gde9d65e-1
                           kmahjongg23.04.0.r1658.gdfe953d-123.04.1.r1658.gdfe953d-1
                               kmail23.04.0.r26994.g492253960-123.04.0.r26996.g605ab3f11-1
                      kmailtransport23.04.0.r1932.gb7d8f3b-123.04.1.r1933.gc5fa0bd-1
                               kmbox23.04.0.r653.gf9238bc-123.04.1.r653.gf9238bc-1
                               kmime23.04.0.r1625.g9751d4f-123.04.1.r1626.g5bf5c27-1
                              kmines23.04.0.r1841.gef2fe2f-123.04.1.r1841.gef2fe2f-1
                          kmousetool23.04.0.r518.gbbff8f7-123.04.1.r518.gbbff8f7-1
                              kmouth23.04.0.r826.gf76be7c-123.04.1.r826.gf76be7c-1
                              kmplot23.04.0.r1584.g71e93c3-123.04.0.r1586.g24458b0-1
                        knavalbattle23.04.0.r1510.g074dc4a-123.04.1.r1510.g074dc4a-1
                            knetwalk23.04.0.r785.g85583ef-123.04.1.r785.g85583ef-1
                             knights23.04.0.r1239.g14d3de5-123.04.1.r1239.g14d3de5-1
                                kolf23.04.0.r1600.ga381d36-123.04.1.r1600.ga381d36-1
                           kollision23.04.0.r603.gf5dab7c-123.04.1.r603.gf5dab7c-1
                         kolourpaint23.04.0.r2527.gc8a9f137-123.04.1.r2527.gc8a9f137-1
                            kongress23.01.0.r25.g1052796-123.01.0.r28.g4dbb9fa-1
                           konqueror23.04.0.r15433.g409936442-123.04.0.r15435.g8f5714de0-1
                            konquest23.04.0.r1016.g4be48fa-123.04.1.r1016.g4be48fa-1
                    kontactinterface23.04.0.r788.g97663f3-123.04.1.r789.g8a7242a-1
                            kontrast23.04.0.r314.g2bc9c2b-123.04.1.r314.g2bc9c2b-1
                        konversation23.04.0.r9289.g8f3ed7e7-123.04.0.r9290.g160f7702-1
                       kopeninghours23.04.0.r389.g95ae7c7-123.04.1.r389.g95ae7c7-1
                       kosmindoormap23.04.0.r1005.gcb4d4a7-123.04.1.r1005.gcb4d4a7-1
                                kpat23.04.0.r2751.g1e783fc0-123.04.1.r2751.g1e783fc0-1
                        kpimtextedit23.04.0.r1869.gda45f10-123.04.1.r1870.ga595eea-1
                             kpkpass23.04.0.r348.ge38d0dd-123.04.1.r348.ge38d0dd-1
                             kpmcore23.04.0.r1371.g4468ff1-123.04.1.r1371.g4468ff1-1
                    kpublictransport23.04.0.r2169.g2e929652-123.04.1.r2169.g2e929652-1
                      kqtquickcharts23.04.0.r78.g22ff9c9-123.04.1.r78.g22ff9c9-1
                            kreversi23.04.0.r1349.g8c4cf0c-123.04.1.r1349.g8c4cf0c-1
                              kruler23.04.0.r849.g378ae8c-123.04.1.r849.g378ae8c-1
                            kservice5.105.0.r1114.g09c749b6-15.105.0.r1115.gc0c3da62-1
                             kshisen23.04.0.r1338.g4f948c8-123.04.1.r1338.g4f948c8-1
                               ksirk23.04.0.r1134.gf619560-123.04.1.r1134.gf619560-1
                               ksmtp23.04.0.r529.g5da1d7f-123.04.1.r529.g5da1d7f-1
                          ksnakeduel23.04.0.r925.gdc0a5b0-123.04.1.r925.gdc0a5b0-1
                          kspaceduel23.04.0.r737.gfeced39-123.04.1.r737.gfeced39-1
                            ksquares23.04.0.r654.g48d9697-123.04.1.r654.g48d9697-1
                             ksudoku23.04.0.r1195.ge27980f-123.04.1.r1195.ge27980f-1
                         ktextaddons      r466.g6c97971-1      r467.g7d5b44c-1
                               ktnef23.04.0.r813.gb855a1e-123.04.1.r813.gb855a1e-1
                              ktouch23.04.0.r2264.gcc9c125-123.04.1.r2264.gcc9c125-1
                          ktuberling23.04.0.r1159.g4f28dbd-123.04.1.r1159.g4f28dbd-1
                             kturtle23.04.0.r1269.g25c27a6-123.04.1.r1269.g25c27a6-1
                             kubrick23.04.0.r486.g7cd4713-123.04.1.r486.g7cd4713-1
                     kunitconversion5.105.0.r519.gf0c050e-15.105.0.r520.gbc46e3d-1
                                kwin5.27.5.r24211.g2237391e97-15.27.5.r24212.g3d62e75489-1
                           kwordquiz23.04.0.r1308.g2e677a8-123.04.0.r1310.g5674f22-1
                              kwrite23.04.0.r20666.g3d3b8bb6e-123.04.0.r20669.gae1e66445-1
                          libakonadi23.04.0.r13067.g0763800ae-123.04.1.r13067.g0763800ae-1
                         libgravatar23.04.0.r516.gfb88fce-123.04.1.r517.g44bd10b-1
                            libkcddb23.04.0.r840.gb8ca1e6-123.04.1.r840.gb8ca1e6-1
                     libkcompactdisc23.04.0.r435.g1767993-123.04.1.r435.g1767993-1
                           libkdcraw23.04.0.r1160.g580849c-123.04.1.r1160.g580849c-1
                         libkdegames23.04.0.r2332.g668af9d2-123.04.1.r2332.g668af9d2-1
                           libkdepim23.04.0.r1001.g8bdeeb1-123.04.1.r1002.g6161299-1
                  libkeduvocdocument23.04.0.r1851.g140658a-123.04.1.r1851.g140658a-1
                           libkexiv223.04.0.r840.ga7e8d31-123.04.1.r840.ga7e8d31-1
                             libkipi23.04.0.r1289.g8cacdbb-123.04.1.r1289.g8cacdbb-1
                             libkleo23.04.0.r1507.g42d6083-123.04.1.r1508.gebdb1e8-1
                        libkmahjongg23.04.0.r530.gdc8e2ae-123.04.1.r530.gdc8e2ae-1
                     libkomparediff223.04.0.r399.g3fc35e5-123.04.1.r399.g3fc35e5-1
                            libksane23.04.0.r654.gb9a8d72-123.04.1.r654.gb9a8d72-1
                           libksieve23.04.0.r1903.gd291a75d-123.04.1.r1904.g9336dcf6-1
                         libktorrent23.04.0.r601.g9d4f5bc-123.04.1.r601.g9d4f5bc-1
                               lskat23.04.0.r931.g553096a-123.04.1.r931.g553096a-1
                          mailcommon23.04.0.r1485.g8eaec0a-123.04.1.r1486.g82105d5-1
                        mailimporter23.04.0.r624.ga243af1-123.04.1.r625.gc635b39-1
                             mauikit2.2.2.r99.g20729417-12.2.2.r101.g81c0669a-1
                          messagelib23.04.0.r7113.g69570ee6c-123.04.1.r7114.g04278382d-1
                              minuet23.04.0.r694.g8b01adb-123.04.1.r694.g8b01adb-1
                              okular23.04.0.r10078.ge53090bff-123.04.1.r10082.g9bf726881-1
                            palapeli23.04.0.r1388.g25b890d-123.04.1.r1390.g7251eba-1
                              parley23.04.0.r4615.g7ae58374-123.04.1.r4615.g7ae58374-1
                    partitionmanager23.04.0.r1804.g9dac0a5-123.04.0.r1805.g0de62b7-1
                               picmi23.04.0.r637.ga2249fd-123.04.1.r637.ga2249fd-1
                           pimcommon23.04.0.r2106.geb2eb8ea-123.04.0.r2107.g15164c32-1
                       plasma-camera  1.0.r170.ga31c77f-1  1.0.r171.g6e10ded-1
                    plasma-mobile-nm5.27.5.r3605.g7bddb670-15.27.5.r3607.gdf95c4bf-1
                           plasma-nm5.27.5.r3605.g7bddb670-15.27.5.r3607.gdf95c4bf-1
                          powerdevil5.27.5.r2719.g04e7b2d0-15.27.5.r2720.g14dc7efe-1
                             purpose5.105.0.r1118.gcfa85f8f-15.105.0.r1119.gb8c078e9-1
                                rocs23.04.0.r3187.g53612ffa-123.04.0.r3189.g962c1cdc-1
                            sddm-kcm5.27.5.r761.g15795b7-15.27.5.r762.g30f6653-1
            signon-kwallet-extension23.04.0.r85.g2d8eb31-123.04.1.r85.g2d8eb31-1
                            spacebar23.01.0.r61.g453f5e3-123.01.0.r63.g133380f-1
                           spectacle23.04.0.r1734.gf314da3-123.04.1.r1734.gf314da3-1
                                step23.04.0.r1332.gce865da-123.04.1.r1332.gce865da-1
                             svgpart23.04.0.r283.gcc9520b-123.04.1.r283.gcc9520b-1
      telepathy-kde-common-internals23.04.0.r2071.g9357606-123.04.1.r2071.g9357606-1
                             tokodon23.02.0.r244.gb88638f-123.02.0.r246.gf4e376a-1
                            umbrello23.04.0.r8672.g62e3ddccd-123.04.0.r8673.g3ea0e5995-1
                               vvave 2.2.2.r53.gf4964b4-1 2.2.2.r54.g7147b8a-1


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023.05.11           2023.05.13
-------------------------------------------------------------------------------
                    lib32-libnghttp2             1.52.0-2             1.53.0-1
</code></pre>
<p><a href="https://forum.manjaro.org/t/testing-update-2023-05-13-kernels-firefox-libreoffice-still-kde-git-python/140459/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul><li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul><p><small>33 posts - 17 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2023-05-13-kernels-firefox-libreoffice-still-kde-git-python/140459">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-31670]]></title>
<description><![CDATA[An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a Denial of Service (DoS) via running a crafted binary.]]></description>
<link>https://tsecurity.de/de/1890231/sicherheitsluecken/cve-2023-31670/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1890231/sicherheitsluecken/cve-2023-31670/</guid>
<pubDate>Wed, 24 May 2023 10:30:52 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An issue in wasm2c 1.0.32, wasm2wat 1.0.32, wasm-decompile 1.0.32, and wasm-validate 1.0.32 allows attackers to cause a Denial of Service (DoS) via running a crafted binary.]]></content:encoded>
</item>
<item>
<title><![CDATA[How Slow Roads intrigues gamers and developers alike, spotlighting the surprising capabilities of 3D in the browser]]></title>
<description><![CDATA[Slow Roads is a casual driving game with an emphasis on endlessly procedurally generated scenery, all
hosted in the browser as a WebGL application. For many, such an intensive
experience might seem out of place in the limited context of the browser—and indeed, redressing that attitude has been on...]]></description>
<link>https://tsecurity.de/de/1856286/web-tipps/how-slow-roads-intrigues-gamers-and-developers-alike-spotlighting-the-surprising-capabilities-of-3d-in-the-browser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1856286/web-tipps/how-slow-roads-intrigues-gamers-and-developers-alike-spotlighting-the-surprising-capabilities-of-3d-in-the-browser/</guid>
<pubDate>Tue, 11 Apr 2023 18:33:43 +0200</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://slowroads.io/" rel="noopener">Slow Roads</a> is a casual driving game with an emphasis on endlessly procedurally generated scenery, all
hosted in the browser as a <a href="https://developer.mozilla.org/docs/Web/API/WebGL_API" rel="noopener">WebGL application</a>. For many, such an intensive
experience might seem out of place in the limited context of the browser—and indeed, redressing that attitude has been one of my
goals with this project. In this article I'll be breaking down some of the techniques I used to navigate the performance hurdle in
my mission to highlight the oft-overlooked potential of 3D in the web.</p>
<h2 id="3d-development-in-the-browser">3D development in the browser <a class="headline-link" href="https://web.dev/slow-roads/#3d-development-in-the-browser">#</a></h2>
<p>After releasing Slow Roads, I saw a recurring comment in the feedback: &quot;I didn't know this was possible in the browser&quot;. If
you share this sentiment, you're certainly not a minority; according to the <a href="https://2022.stateofjs.com/en-US/" rel="noopener">2022 State of JS</a>
survey, some 80% of developers have yet to experiment with WebGL. To me, it feels something of a shame that so much potential
might be missed, especially when it comes to browser-based gaming. With Slow Roads I hope to bring WebGL further into the limelight,
and perhaps reduce the number of developers who balk at the phrase &quot;high-performance JavaScript game engine&quot;.</p>
<p>WebGL may seem mysterious and complex for many, but in recent years its development ecosystems have greatly matured into highly
capable and convenient tools and libraries. It's now easier than ever for front-end developers to incorporate 3D UX into their
work, even without prior experience in computer graphics. <a href="https://threejs.org/" rel="noopener">Three.js</a>, the leading WebGL library, serves
as the foundation for many expansions, including <a href="https://docs.pmnd.rs/react-three-fiber/getting-started/introduction" rel="noopener">react-three-fiber</a> which brings 3D components into the React framework. There
are now also comprehensive web-based game editors such as <a href="https://www.babylonjs.com/" rel="noopener">Babylon.js</a> or <a href="https://playcanvas.com/" rel="noopener">PlayCanvas</a>
which offer a familiar interface and integrated toolchains.</p>
<p>Despite the remarkable utility of these libraries, however, ambitious projects are eventually bound by technical limitations. Skeptics
to the idea of browser-based gaming might highlight that JavaScript is single-threaded and resource-constrained. But navigating
these limitations unlocks the hidden value: no other platform offers the same instant accessibility and mass compatibility
enabled by the browser. Users on any browser-capable system can begin playing in one click, with no need to install applications
and no need to sign in to services. Not to mention that developers enjoy the elegant convenience of having robust front-end frameworks
available for building UI, or handling networking for multiplayer modes. These values, in my opinion, are what make the browser such an
excellent platform for both players and developers alike—and, as demonstrated by Slow Roads, the technical limitations might often be
reducible to a design problem.</p>
<h2 id="achieving-smooth-performance-in-slow-roads">Achieving smooth performance in Slow Roads <a class="headline-link" href="https://web.dev/slow-roads/#achieving-smooth-performance-in-slow-roads">#</a></h2>
<p>Since the core elements of Slow Roads involve high-speed motion and expensive scenery generation, the need for smooth performance
underlined my every design decision. My main strategy was to start with a pared-down gameplay design that allowed for contextual
short-cuts to be taken within the engine's architecture. On the downside this means trading off some nice-to-have features in the
pursuit of minimalism, but results in a bespoke, hyper-optimized system that plays nicely across different browsers and devices.</p>
<p>Here follows a breakdown of the key components that keep Slow Roads lean.</p>
<h3 id="shaping-the-environment-engine-around-the-gameplay">Shaping the environment engine around the gameplay <a class="headline-link" href="https://web.dev/slow-roads/#shaping-the-environment-engine-around-the-gameplay">#</a></h3>
<p>As the key component of the game, the environment generation engine is unavoidably expensive, justifiably taking the greatest
proportion of the budgets for memory and compute. The trick used here is in scheduling and distributing the heavy computation over
a period of time, so as not to interrupt the framerate with performance spikes.</p>
<aside class="aside flow bg-state-info-bg color-state-info-text"><div class=" flow"> At its core, a game engine is an infinite <code>while</code> loop which reads user input, updates the world state, and then renders the image for the frame. This loop runs at the refresh rate of the monitor (typically 60 Hz), so any computation happening within it needs to complete within the given frame time to avoid causing visible stutters. </div></aside>
<p>The environment is composed of tiles of geometry, differing in size and resolution (categorized as &quot;levels of detail&quot; or LoDs)
depending on how close they will appear to the camera. In typical games with a free-roaming camera, different LoDs must be constantly
loaded and unloaded to detail the player's surroundings wherever they may choose to go. This can be an expensive and wasteful operation,
especially when the environment itself is dynamically generated. Fortunately, this convention can be entirely subverted in Slow Roads
thanks to the contextual expectation that the user should stay on the road. Instead, high-detail geometry can be reserved for the narrow
corridor directly flanking the route.</p>
<figure>
  <img alt="A diagram showing how generating the road far in advance can allow for proactive scheduling and caching of the environment generation." decoding="async" height="720" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format" srcset="https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EK3mXmwSxE422zjs9mMw.png?auto=format&w=1600 1600w" width="1280" />
  <figcaption>
    A view of the environment geometry in Slow Roads rendered as a wireframe, indicating corridors of high-resolution geometry flanking the road. Distant portions of the environment, which should never be seen up close, are rendered at a much lower resolution.
  </figcaption>
</figure>
<p>The midline of the road itself is generated far ahead of the player's arrival, allowing for accurate prediction of exactly
when and where the environment detail will be needed. The result is a lean system that can proactively schedule expensive work,
generating just the minimum needed at each point in time, and with no wasted effort on details that won't be seen. This technique
is only possible because the road is a single, non-branching path—a good example of making gameplay trade-offs that accommodate
architectural short-cuts.</p>
<figure>
  <img alt="A diagram showing how generating the road far in advance can allow for proactive scheduling and caching of the environment generation." decoding="async" height="480" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format" srcset="https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/6rjJXHREoaUXIxhun35L.png?auto=format&w=1600 1600w" width="960" />
  <figcaption>
    By looking a certain distance along the road, environment chunks can be pre-empted and generated gradually just before they're needed. Additionally, any chunks that will be revisited in the near future can be identified and cached to avoid unnecessary regeneration.
  </figcaption>
</figure>
<h3 id="being-picky-with-the-laws-of-physics">Being picky with the laws of physics <a class="headline-link" href="https://web.dev/slow-roads/#being-picky-with-the-laws-of-physics">#</a></h3>
<p>Second to the computational demand of the environment engine is the physics simulation. Slow Roads uses a custom, minimal physics engine which takes every short-cut available.</p>
<aside class="aside flow bg-state-info-bg color-state-info-text"><div class=" flow"> Physics engines are hard, but thankfully many excellent libraries exist to streamline the process. Custom implementations are necessary in extreme cases, but libraries like <a href="https://schteppe.github.io/cannon.js/">cannon.js</a> are increasingly covering more bases. </div></aside>
<p>The major saving here is to avoid simulating too many objects in the first place—leaning into the minimal, zen context by
discounting things like dynamic collisions and destructible objects. The assumption that the vehicle will stay on the road
means that collisions with off-road objects can reasonably be ignored. Additionally, the encoding of the road as a sparse
midline enables elegant tricks for fast collision detection with the road surface and guard rails, all based on a distance
check to the road's center. Off-road driving then becomes more expensive, but this is another example of a fair trade-off
suited to the context of the gameplay.</p>
<h3 id="managing-the-memory-footprint">Managing the memory footprint <a class="headline-link" href="https://web.dev/slow-roads/#managing-the-memory-footprint">#</a></h3>
<p>As another browser-restrained resource, it's important to manage memory with care—despite the fact JavaScript is
garbage-collected. It can be easy to overlook, but declaring even small amounts of new memory within a game loop can snowball
into significant issues when running at 60Hz. Besides eating up the user's resources in a context where they're likely multitasking,
large garbage collections can take several frames to complete, causing noticeable stutters. To avoid this, loop memory can be
pre-allocated in class variables at initialisation and recycled in each frame.</p>
<figure>
  <img alt="A before-and-after view of the memory profile during optimisation of the Slow Roads codebase, indicating significant savings and a reduction in garbage collection rate." decoding="async" height="480" loading="lazy" sizes="(min-width: 560px) 560px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format" srcset="https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/EDXmi4BDLYiLZuVET870.png?auto=format&w=1120 1120w" width="560" />
  <figcaption>
    While the overall memory utilization is barely changed, pre-allocating and recycling loop memory can greatly reduce the impact of expensive garbage collections.
  </figcaption>
</figure>
<p>It's also highly important that heavier data structures, such as geometries and their associated data buffers, are managed economically. In an infinitely-generated game like Slow Roads, most of the geometry exists on a sort of treadmill - once an old piece falls behind into the distance, its data structures can be stored and recycled again for an upcoming piece of the world, a design pattern known as object pooling.</p>
<p>These practices help to prioritize lean execution, with the sacrifice of some code simplicity. In high-performance contexts it's
important to be mindful of how convenience features sometimes borrow from the client for the benefit of the developer. For example, methods
like <code>Object.keys()</code> or <code>Array.map()</code> are incredibly handy, but it's easy to overlook that each creates a new array for their return
value. Understanding the inner workings of such black-boxes can help to tighten up your code and avoid sneaky performance hits.</p>
<h3 id="reducing-load-time-with-procedurally-generated-assets">Reducing load time with procedurally-generated assets <a class="headline-link" href="https://web.dev/slow-roads/#reducing-load-time-with-procedurally-generated-assets">#</a></h3>
<p>While runtime performance should be the primary concern for game developers, the usual axioms concerning initial web page load time still
hold true. Users may be more forgiving when knowingly accessing heavy content, but long load times can still be detrimental to the experience,
if not user retention. Games often require large assets in the form of textures, sounds, and 3D models, and at a minimum these should be carefully
compressed wherever detail can be spared.</p>
<aside class="aside flow bg-tertiary-box-bg color-tertiary-box-text"><p class="cluster "><span class="aside__icon box-block "><svg width="24" height="24" viewBox="0 0 24 24" role="img" aria-label="Lightbulb" fill="currentColor" xmlns="http://www.w3.org/2000/svg">   <path d="M9 21c0 .55.45 1 1 1h4c.55 0 1-.45 1-1v-1H9v1zm3-19C8.14 2 5 5.14 5 9c0 2.38 1.19 4.47 3 5.74V17c0 .55.45 1 1 1h6c.55 0 1-.45 1-1v-2.26c1.81-1.27 3-3.36 3-5.74 0-3.86-3.14-7-7-7zm2.85 11.1l-.85.6V16h-4v-2.3l-.85-.6A4.997 4.997 0 017 9c0-2.76 2.24-5 5-5s5 2.24 5 5c0 1.63-.8 3.16-2.15 4.1z"></path> </svg></span><strong>Important</strong></p><div class=" flow"> Be sure to use the appropriate formats for your assets—converting all of the images to <a href="https://web.dev/learn/images/webp/">WebP</a> format halved the Slow Roads bundle size with barely a perceptible difference in quality. </div></aside>
<p>Alternatively, procedurally generating assets on the client can avoid lengthy transfers in the first place. This is a huge benefit for users on slow connections,
and gives the developer more direct control over how their game is constituted—not just for the initial loading step, but also when it comes to adapting levels
of details for different quality settings.</p>
<img alt="A comparison illustrating how the quality of procedurally-generated geometry in Slow Roads can be dynamically adapted to the user&#x27;s performance needs." decoding="async" height="640" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format" srcset="https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/LSTBxy582GfK2KDfbXuv.png?auto=format&w=1600 1600w" width="800" />
<p>Most of the geometry in Slow Roads is procedurally generated and simplistic, with custom shaders combining multiple textures to bring the detail.
The drawback is that these textures can be heavy assets, though there are further opportunities for savings here, with methods such as stochastic
texturing able to achieve greater detail from small source textures. And at an extreme level, it's also possible to generate textures entirely on the client with tools such as <a href="https://texgenjs.org/" rel="noopener">texgen.js</a>. The same is even true for audio, with the Web Audio API allowing for <a href="https://developer.mozilla.org/docs/Web/API/Web_Audio_API/Advanced_techniques" rel="noopener">sound generation</a> with audio nodes.</p>
<p>With the benefit of procedural assets, generating the initial environment takes just 3.2 seconds on average. To best take advantage of
the small up-front download size, a simple splash screen greets new visitors and postpones the expensive scene initialisation until
after an affirmative button press. This also acts as a convenient buffer for bounced sessions, minimizing wasted transfer of dynamically-loaded
assets.</p>
<img alt="A histogram of load times showing a strong peak in the first three seconds accounting for over 60% of users, followed by a rapid decline. The histogram shows that over 97% of users see load times of less than 10 seconds." decoding="async" height="576" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format" srcset="https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/hxiIMl31gXaXpqlAEvNu.png?auto=format&w=1600 1600w" width="1080" />
<h3 id="taking-an-agile-approach-to-late-optimization">Taking an agile approach to late optimization <a class="headline-link" href="https://web.dev/slow-roads/#taking-an-agile-approach-to-late-optimization">#</a></h3>
<p>I've always considered the codebase for Slow Roads to be experimental, and as such have taken a fiercely agile approach to
development. When working with a complex and rapidly-evolving system architecture, it can be difficult to predict where the
important bottlenecks may occur. The focus should be on implementing the desired features quickly, rather than cleanly, and
then working backwards to optimize systems where it really counts. The performance profiler in Chrome DevTools is invaluable
for this step, and has helped me to diagnose some major issues with earlier versions of the game. Your time as a developer is
valuable, so be sure you aren't spending time deliberating over problems that may prove insignificant or redundant.</p>
<h3 id="monitoring-the-user-experience">Monitoring the user experience <a class="headline-link" href="https://web.dev/slow-roads/#monitoring-the-user-experience">#</a></h3>
<p>While implementing all of these tricks, it's important to be sure the game performs as expected in the wild. Accommodating
a range of hardware capabilities is a staple aspect of any game development, but web games can target a much broader spectrum
comprising both top-end desktops and decade-old mobile devices at once. The simplest way to approach this is by offering settings
for adapting the most likely bottlenecks in your codebase—for both GPU- and CPU-intensive tasks—as revealed by your profiler.</p>
<p>Profiling on your own machine can only cover so much, however, so it's valuable to close the feedback loop with your users in
some way. For Slow Roads I run simple analytics which report on performance along with contextual factors such as screen resolution.
These analytics are sent to a basic Node backend using socket.io, along with any written feedback the user submits via the in-game
form. In the early days, these analytics caught a lot of important issues that could be mitigated with simple changes to the UX,
such as highlighting the settings menu when a consistently low FPS is detected, or warning that a user may need to enable hardware
acceleration if the performance is particularly poor.</p>
<h2 id="the-slow-roads-ahead">The slow roads ahead <a class="headline-link" href="https://web.dev/slow-roads/#the-slow-roads-ahead">#</a></h2>
<p>Even after taking all of these measures, there remains a significant portion of the player base that needs to play on lower
settings—primarily those using lightweight devices which lack a GPU. While the range of quality settings available leads to a
fairly even performance distribution, only 52% of players achieve above 55 FPS.</p>
<figure>
  <img alt="A matrix defined by view distance setting against detail setting, showing the average frames-per-second achieved at different pairings. The distribution is fairly evenly spread between 45 and 60, with 60 being the target for good performance. Users at low settings tend to see a lower FPS than those at high settings, highlighting the differences in client hardware capability." decoding="async" height="420" loading="lazy" sizes="(min-width: 640px) 640px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format" srcset="https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/cGQxYFGJrUUaUZyWhyt9yo5gHhs1/eZFv6ulS99NQdwyjAYzi.png?auto=format&w=1280 1280w" width="640" />
  <figcaption>
    Note that this data is somewhat skewed by users who run their browser with hardware acceleration disabled, often causing artificially low performance.
  </figcaption>
</figure>
<p>Fortunately, there are still many opportunities for making performance savings. Alongside adding further rendering tricks
to reduce GPU demand, I hope to experiment with web workers in parallelising the environment generation in the near term,
and may eventually see a need for incorporating WASM or <a href="https://developer.mozilla.org/docs/Web/API/WebGPU_API" rel="noopener">WebGPU</a> into the codebase. Any headroom I'm able to free up will allow
for richer and more diverse environments, which will be the enduring goal for the remainder of the project.</p>
<p>As hobby projects go, Slow Roads has been an overwhelmingly fulfilling way to demonstrate how surprisingly elaborate, performant,
and popular browser games can be. If I've been successful in piquing your interest in WebGL, know that technologically Slow
Roads is a fairly shallow example of its full capabilities. I strongly encourage readers to explore the <a href="https://threejs.org/" rel="noopener">Three.js showcase</a>,
and those interested in web game development in particular would be welcome to the community at <a href="https://www.webgamedev.com/" rel="noopener">webgamedev.com</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome 112 Released With WASM Garbage Collection Trial, CSS Nesting]]></title>
<description><![CDATA[Google today promoted the Chrome 112 web browser to their stable channel on all supported platforms. Phoronix reports: Starting as an origin trial with Chrome 112 is WebAssembly (WASM) Garbage Collection support. Yes, garbage collection to allow for efficient support for high-level managed langua...]]></description>
<link>https://tsecurity.de/de/1849905/it-security-nachrichten/chrome-112-released-with-wasm-garbage-collection-trial-css-nesting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1849905/it-security-nachrichten/chrome-112-released-with-wasm-garbage-collection-trial-css-nesting/</guid>
<pubDate>Wed, 05 Apr 2023 02:48:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google today promoted the Chrome 112 web browser to their stable channel on all supported platforms. Phoronix reports: Starting as an origin trial with Chrome 112 is WebAssembly (WASM) Garbage Collection support. Yes, garbage collection to allow for efficient support for high-level managed languages with WebAssembly. This trial support allows for compilers targeting WASM to integrate with a garbage collector in the host VM. Also on the WebAssembly front with today's Chrome browser update is making WebAssembly tail call support available out of the box. This adds explicit tail call and indirect tail call opcodes. This support is useful for correct/efficient implementations of languages that require tail call elimination, compilation of control constructs that can be implemented with it, and other computations being expressed as WASM functions.
 
Meanwhile by default in Chrome 112 is now CSS nesting support as the ability to nest CSS style rules inside other style rules for increasing modularity and maintainability of style sheets. Chrome 112 also adds support for the CSS animation-composition property. Behind a developer flag is also the background-blur feature that allows using a native platform's API for camera background segmentation. This is intended for use with web-based video conferencing applications running within the web browser to make use of native platform APIs. A full list of changes is available on the Chrome Releases blog.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Chrome+112+Released+With+WASM+Garbage+Collection+Trial%2C+CSS+Nesting%3A+https%3A%2F%2Ftech.slashdot.org%2Fstory%2F23%2F04%2F04%2F2128239%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F23%2F04%2F04%2F2128239%2Fchrome-112-released-with-wasm-garbage-collection-trial-css-nesting%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/23/04/04/2128239/chrome-112-released-with-wasm-garbage-collection-trial-css-nesting?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-27114 | radare2 5.8.3 p/wasm/wasm.c wasm_dis memory corruption (ID 21363)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in radare2 5.8.3. Affected is the function wasm_dis of the file p/wasm/wasm.c. The manipulation leads to memory corruption.

This vulnerability is traded as CVE-2023-27114. Access to the local network is required for this attack to succ...]]></description>
<link>https://tsecurity.de/de/1846102/sicherheitsluecken/cve-2023-27114-radare2-583-pwasmwasmc-wasmdis-memory-corruption-id-21363/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1846102/sicherheitsluecken/cve-2023-27114-radare2-583-pwasmwasmc-wasmdis-memory-corruption-id-21363/</guid>
<pubDate>Sun, 02 Apr 2023 12:37:51 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/?kb.risk">critical</a>, was found in <a href="https://vuldb.com/?product.radare2">radare2 5.8.3</a>. Affected is the function <code>wasm_dis</code> of the file <em>p/wasm/wasm.c</em>. The manipulation leads to memory corruption.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.222690">CVE-2023-27114</a>. Access to the local network is required for this attack to succeed. There is no exploit available.

It is recommended to apply a patch to fix this issue.]]></content:encoded>
</item>
<item>
<title><![CDATA[WebAssembly-Framework Spin 1.0: Serverless-Anwendungen mit Wasm]]></title>
<description><![CDATA[Das neue Release der Open-Source-Software soll die Anforderungen der Full-Stack-Entwickler durch eine breite Unterstützung verschiedenster Sprachen erfüllen.]]></description>
<link>https://tsecurity.de/de/1842707/it-nachrichten/webassembly-framework-spin-10-serverless-anwendungen-mit-wasm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1842707/it-nachrichten/webassembly-framework-spin-10-serverless-anwendungen-mit-wasm/</guid>
<pubDate>Thu, 30 Mar 2023 16:08:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das neue Release der Open-Source-Software soll die Anforderungen der Full-Stack-Entwickler durch eine breite Unterstützung verschiedenster Sprachen erfüllen.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-27114]]></title>
<description><![CDATA[radare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/wasm.c.]]></description>
<link>https://tsecurity.de/de/1817796/sicherheitsluecken/cve-2023-27114/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1817796/sicherheitsluecken/cve-2023-27114/</guid>
<pubDate>Fri, 10 Mar 2023 07:20:37 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[radare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/wasm.c.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-27477]]></title>
<description><![CDATA[wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_64 platforms for the WebAssembly `i8x16.select` instruction which will produce the wrong results when the same operand is provided to the instruction and some of the selected ind...]]></description>
<link>https://tsecurity.de/de/1816020/sicherheitsluecken/cve-2023-27477/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1816020/sicherheitsluecken/cve-2023-27477/</guid>
<pubDate>Thu, 09 Mar 2023 04:06:03 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_64 platforms for the WebAssembly `i8x16.select` instruction which will produce the wrong results when the same operand is provided to the instruction and some of the selected indices are greater than 16. There is an off-by-one error in the calculation of the mask to the `pshufb` instruction which causes incorrect results to be returned if lanes are selected from the second vector. This codegen bug has been fixed in Wasmtiem 6.0.1, 5.0.1, and 4.0.1. Users are recommended to upgrade to these updated versions. If upgrading is not an option for you at this time, you can avoid this miscompilation by disabling the Wasm simd proposal. Additionally the bug is only present on x86_64 hosts. Other platforms such as AArch64 and s390x are not affected. (CVSS:0.0) (Last Update:2023-03-08)]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-27477]]></title>
<description><![CDATA[wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_64 platforms for the WebAssembly `i8x16.select` instruction which will produce the wrong results when the same operand is provided to the instruction and some of the selected ind...]]></description>
<link>https://tsecurity.de/de/1815929/sicherheitsluecken/cve-2023-27477/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1815929/sicherheitsluecken/cve-2023-27477/</guid>
<pubDate>Thu, 09 Mar 2023 00:20:58 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_64 platforms for the WebAssembly `i8x16.select` instruction which will produce the wrong results when the same operand is provided to the instruction and some of the selected indices are greater than 16. There is an off-by-one error in the calculation of the mask to the `pshufb` instruction which causes incorrect results to be returned if lanes are selected from the second vector. This codegen bug has been fixed in Wasmtiem 6.0.1, 5.0.1, and 4.0.1. Users are recommended to upgrade to these updated versions. If upgrading is not an option for you at this time, you can avoid this miscompilation by disabling the Wasm simd proposal. Additionally the bug is only present on x86_64 hosts. Other platforms such as AArch64 and s390x are not affected.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2023-26489]]></title>
<description><![CDATA[wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a bug on x86_64 targets where address-mode computation mistakenly would calculate a 35-bit effective address instead of WebAssembly's defined 33-bit effective address. This bug me...]]></description>
<link>https://tsecurity.de/de/1815825/sicherheitsluecken/cve-2023-26489/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1815825/sicherheitsluecken/cve-2023-26489/</guid>
<pubDate>Wed, 08 Mar 2023 22:21:00 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a bug on x86_64 targets where address-mode computation mistakenly would calculate a 35-bit effective address instead of WebAssembly's defined 33-bit effective address. This bug means that, with default codegen settings, a wasm-controlled load/store operation could read/write addresses up to 35 bits away from the base of linear memory. Due to this bug, however, addresses up to `0xffffffff * 8 + 0x7ffffffc = 36507222004 = ~34G` bytes away from the base of linear memory are possible from guest code. This means that the virtual memory 6G away from the base of linear memory up to ~34G away can be read/written by a malicious module. A guest module can, without the knowledge of the embedder, read/write memory in this region. The memory may belong to other WebAssembly instances when using the pooling allocator, for example. Affected embedders are recommended to analyze preexisting wasm modules to see if they're affected by the incorrect codegen rules and possibly correlate that with an anomalous number of traps during historical execution to locate possibly suspicious modules. The specific bug in Cranelift's x86_64 backend is that a WebAssembly address which is left-shifted by a constant amount from 1 to 3 will get folded into x86_64's addressing modes which perform shifts. For example `(i32.load (i32.shl (local.get 0) (i32.const 3)))` loads from the WebAssembly address `$local0 &lt;&lt; 3`. When translated to Cranelift the `$local0 &lt;&lt; 3` computation, a 32-bit value, is zero-extended to a 64-bit value and then added to the base address of linear memory. Cranelift would generate an instruction of the form `movl (%base, %local0, 8), %dst` which calculates `%base + %local0 &lt;&lt; 3`. The bug here, however, is that the address computation happens with 64-bit values, where the `$local0 &lt;&lt; 3` computation was supposed to be truncated to a a 32-bit value. This means that `%local0`, which can use up to 32-bits for an address, gets 3 extra bits of address space to be accessible via this `movl` instruction. The fix in Cranelift is to remove the erroneous lowering rules in the backend which handle these zero-extended expression. The above example is then translated to `movl %local0, %temp; shl $3, %temp; movl (%base, %temp), %dst` which correctly truncates the intermediate computation of `%local0 &lt;&lt; 3` to 32-bits inside the `%temp` register which is then added to the `%base` value. Wasmtime version 4.0.1, 5.0.1, and 6.0.1 have been released and have all been patched to no longer contain the erroneous lowering rules. While updating Wasmtime is recommended, there are a number of possible workarounds that embedders can employ to mitigate this issue if updating is not possible. Note that none of these workarounds are on-by-default and require explicit configuration: 1. The `Config::static_memory_maximum_size(0)` option can be used to force all accesses to linear memory to be explicitly bounds-checked. This will perform a bounds check separately from the address-mode computation which correctly calculates the effective address of a load/store. Note that this can have a large impact on the execution performance of WebAssembly modules. 2. The `Config::static_memory_guard_size(1 &lt;&lt; 36)` option can be used to greatly increase the guard pages placed after linear memory. This will guarantee that memory accesses up-to-34G away are guaranteed to be semantically correct by reserving unmapped memory for the instance. Note that this reserves a very large amount of virtual memory per-instances and can greatly reduce the maximum number of concurrent instances being run. 3. If using a non-x86_64 host is possible, then that will also work around this bug. This bug does not affect Wasmtime's or Cranelift's AArch64 backend, for example.]]></content:encoded>
</item>
<item>
<title><![CDATA[Safely run WebAssembly in the Linux kernel, with faster-than-native performance.]]></title>
<description><![CDATA[submitted by    /u/speckz  [link]   [comments]]]></description>
<link>https://tsecurity.de/de/1779452/linux-tipps/safely-run-webassembly-in-the-linux-kernel-with-faster-than-native-performance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1779452/linux-tipps/safely-run-webassembly-in-the-linux-kernel-with-faster-than-native-performance/</guid>
<pubDate>Mon, 23 Jan 2023 16:45:51 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/speckz"> /u/speckz </a> <br><span><a href="https://github.com/wasmerio/kernel-wasm">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/10jfht8/safely_run_webassembly_in_the_linux_kernel_with/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-36643]]></title>
<description><![CDATA[A vulnerability was found in intgr uqm-wasm. It has been classified as critical. This affects the function log_displayBox in the library sc2/src/libs/log/msgbox_macosx.m. The manipulation leads to format string. The name of the patch is 1d5cbf3350a02c423ad6bef6dfd5300d38aa828f. It is recommended ...]]></description>
<link>https://tsecurity.de/de/1759530/sicherheitsluecken/cve-2020-36643/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1759530/sicherheitsluecken/cve-2020-36643/</guid>
<pubDate>Fri, 06 Jan 2023 20:47:19 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in intgr uqm-wasm. It has been classified as critical. This affects the function log_displayBox in the library sc2/src/libs/log/msgbox_macosx.m. The manipulation leads to format string. The name of the patch is 1d5cbf3350a02c423ad6bef6dfd5300d38aa828f. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217563.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-40957]]></title>
<description><![CDATA[Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.*This bug only affects Firefox on ARM64 platforms.*. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.]]></description>
<link>https://tsecurity.de/de/1743969/sicherheitsluecken/cve-2022-40957/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1743969/sicherheitsluecken/cve-2022-40957/</guid>
<pubDate>Thu, 22 Dec 2022 23:02:38 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.&lt;br&gt;*This bug only affects Firefox on ARM64 platforms.*. This vulnerability affects Firefox ESR &lt; 102.3, Thunderbird &lt; 102.3, and Firefox &lt; 105.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-31740]]></title>
<description><![CDATA[On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.]]></description>
<link>https://tsecurity.de/de/1744014/sicherheitsluecken/cve-2022-31740/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1744014/sicherheitsluecken/cve-2022-31740/</guid>
<pubDate>Thu, 22 Dec 2022 23:02:38 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vulnerability affects Thunderbird &lt; 91.10, Firefox &lt; 101, and Firefox ESR &lt; 91.10.]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux Foundation Announces an Open Map Project and 'Open Metaverse Foundation']]></title>
<description><![CDATA[The Linux Foundation "sponsors the work of Linux creator Linus Torvalds and lead maintainer Greg Kroah-Hartman," according to its page on Wikipedia. And now the Linux Foundation "is pleased to announce the launch of the Overture Maps Foundation," according to their December newsletter. 

It's a c...]]></description>
<link>https://tsecurity.de/de/1737329/linux-tipps/linux-foundation-announces-an-open-map-project-and-open-metaverse-foundation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1737329/linux-tipps/linux-foundation-announces-an-open-map-project-and-open-metaverse-foundation/</guid>
<pubDate>Sat, 17 Dec 2022 19:45:20 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Linux Foundation "sponsors the work of Linux creator Linus Torvalds and lead maintainer Greg Kroah-Hartman," according to its page on Wikipedia. And now the Linux Foundation "is pleased to announce the launch of the Overture Maps Foundation," according to their December newsletter. 

It's a collaborative effort "to enable current and next-generation map products by creating reliable, easy-to-use, and interoperable open map data as a shared asset that can strengthen mapping services worldwide."
The initiative was founded by Amazon Web Services (AWS), Meta, Microsoft, and TomTom and is open to all communities with a common interest in building open map data. To get involved, please visit overturemaps.org. 

And they're also announcing plans to form the Open Metaverse Foundation:
In October, we brought top experts from diverse sectors together with leaders from many of the projects across the Linux Foundation to discuss what it will take to transform the emerging concept of the Metaverse from promise to reality.... As the next step in this amazing journey, we welcome the Open Metaverse Foundation (OMF) into the Linux Foundation as another piece of the puzzle. With your help, we can realize the promise of the open Metaverse. Learn more about what's next, join us, and get involved at openmv.org. 
The Foundation has also published three new research papers:

 The 2022 State of Open Source in Financial Services 
 WebAssembly (Wasm) for Legal Professionals 
 Data and Storage Trends 2022.

The newsletter also points out that through Tuesday the foundation is offering 35% off any of their training courses, certifications, bundles or bootcamps.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Linux+Foundation+Announces+an+Open+Map+Project+and+'Open+Metaverse+Foundation'%3A+https%3A%2F%2Fbit.ly%2F3V0gacc"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F22%2F12%2F17%2F0442229%2Flinux-foundation-announces-an-open-map-project-and-open-metaverse-foundation%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/22/12/17/0442229/linux-foundation-announces-an-open-map-project-and-open-metaverse-foundation?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google's Dart Programming Language Soon Won't Take 'Null' For an Answer]]></title>
<description><![CDATA["When the third major release of the Dart programming language debuts in mid-2023, null values will no longer be allowed where they're not expected," reports the Register:

Null in this context is an assignment value indicating the absence of a value or referenced object.... Dart, an object-orien...]]></description>
<link>https://tsecurity.de/de/1727914/it-security-nachrichten/googles-dart-programming-language-soon-wont-take-null-for-an-answer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1727914/it-security-nachrichten/googles-dart-programming-language-soon-wont-take-null-for-an-answer/</guid>
<pubDate>Sat, 10 Dec 2022 23:01:06 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["When the third major release of the Dart programming language debuts in mid-2023, null values will no longer be allowed where they're not expected," reports the Register:

Null in this context is an assignment value indicating the absence of a value or referenced object.... Dart, an object-oriented, garbage-collected C-like language that once aspired to replace JavaScript, supported sound null safety — a way to prevent errors from accessing variables set to null — as of version 2.12. But it maintained modes for running code without null safety or with partial null safety. Dart 3 will no longer entertain those suboptimal possibilities. 

"Our next release, Dart 3, completes the journey to a fully sound null safe language," explained Michael Thomsen, product manager on Dart and Flutter, in a blog post. "As the last step of that journey, we're removing several historical Dart language and SDK artifacts, including removing support for running without sound null safety." Sound null safety, Thomsen explains, means that a non-nullable variable never contains a null value. Not every implementation of null safety is so certain: TypeScript, for example, is unsound — you can assign a null value to a non-null variable. C# has exceptions to its null checks. And Kotlin also has exceptions. 


Dart's transition will help catch type-related bugs at compile time, and should improve code readability, maintainability, and ahead-of-time (AOT) compilation. There's a cost however. Sound null safety will be the only option so pubspec files — Dart package metadata — with an SDK constraint set for less than 2.12 will no longer resolve in Dart 3. According to Thomsen, about 85 percent of Flutter code (which is written in Dart) supports sound null safety at this point. Those with apps and packages in the remaining 15 percent are urged to adapt their code prior to Dart 3's arrival.... 

Following the release of Dart 3, the next significant milestone for the language is likely to be support for compiling Dart code into WebAssembly (Wasm), which will allow Flutter Web apps to run as native code in browsers.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Google's+Dart+Programming+Language+Soon+Won't+Take+'Null'+For+an+Answer%3A+https%3A%2F%2Fbit.ly%2F3FEAZpe"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F22%2F12%2F10%2F059256%2Fgoogles-dart-programming-language-soon-wont-take-null-for-an-answer%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/22/12/10/059256/googles-dart-programming-language-soon-wont-take-null-for-an-answer?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MishiPay's PWA increases transactions 10 times and saves 2.5 years of queuing]]></title>
<description><![CDATA[MishiPay empowers shoppers to scan and pay for their shopping with their smartphones, rather than
wasting time queuing at the checkout. With MishiPay's Scan & Go technology,
shoppers can use their own phone to scan the barcode on items and pay for them, then simply leave
the store. Studies reveal...]]></description>
<link>https://tsecurity.de/de/1725689/web-tipps/mishipays-pwa-increases-transactions-10-times-and-saves-25-years-of-queuing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1725689/web-tipps/mishipays-pwa-increases-transactions-10-times-and-saves-25-years-of-queuing/</guid>
<pubDate>Thu, 08 Dec 2022 19:45:05 +0100</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>MishiPay empowers shoppers to scan and pay for their shopping with their smartphones, rather than
wasting time queuing at the checkout. With MishiPay's <a href="https://mishipay.com/" rel="noopener">Scan &amp; Go</a> technology,
shoppers can use their own phone to scan the barcode on items and pay for them, then simply leave
the store. <a href="https://www.adyen.com/en_GB/landing/online/uk/2019/bnb/report" rel="noopener">Studies</a> reveal that
in-store queuing costs the global retail sector about $200 billion annually.</p>
<p>Our technology relies on device hardware capabilities such as GPS sensors and cameras that allow
users to locate MishiPay-enabled stores, scan item barcodes within the physical store, and then pay
using the digital payment method of their choice. The initial versions of our Scan &amp; Go technology
were platform-specific iOS and Android applications, and early adopters loved the technology. Read
on to learn how switching to a PWA increased transactions by 10 times and saved 2.5 years of
queuing!</p>
<ul class="stats">
  <div class="stats__item">
    <p class="stats__figure">
      10<sub>×</sub>
    </p>
    <p>Increased transactions</p>
  </div>
  <div class="stats__item">
    <p class="stats__figure">
      2.5 years
   </p>
    <p>Queuing saved</p>
  </div>
</ul>
<h2 id="challenge">Challenge <a class="w-headline-link" href="https://web.dev/mishipay/#challenge">#</a></h2>
<p>Users find our technology extremely helpful when waiting in a queue or check-out line, as it allows
them to skip the queue and have a smooth in-store experience. But the hassle of downloading an
Android or iOS application made users not choose our technology despite the value. It was a growing
challenge for MishiPay, and we needed to increase user adoption with a lower barrier of entry.</p>
<h2 id="solution">Solution <a class="w-headline-link" href="https://web.dev/mishipay/#solution">#</a></h2>
<p>Our efforts at building and launching the PWA helped us remove the installation hassle and
encouraged new users to try our technology inside a physical store, skip the queue, and have a
seamless shopping experience. Since the launch, we have seen a massive spike in user adoption with
our PWA compared to our platform-specific applications.</p>
<figure>
  <video autoplay="" loop="" muted="" playsinline="">      <source src="https://storage.googleapis.com/web-dev-uploads/video/8WbTDNrhLsU0El80frMBGE4eMCD3/jtJZ418n11SOtHLTsOht.mp4" type="video/mp4" />    </video>
  <figcaption>
    Side-by-side comparison of directly launching the PWA (left, faster) vs. installing and launching the Android app (right, slower).
  </figcaption>
</figure>
<figure>
  <img alt="Transactions by platform. ¡OS: 16397 (3.98%). Android: 13769 (3.34%). Web: 382184 (92.68%)." decoding="async" height="415" loading="lazy" sizes="(min-width: 300px) 300px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/I5FMltbcuDHqgqEQMyqA.png?auto=format" srcset="https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/I5FMltbcuDHqgqEQMyqA.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/I5FMltbcuDHqgqEQMyqA.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/I5FMltbcuDHqgqEQMyqA.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/I5FMltbcuDHqgqEQMyqA.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/I5FMltbcuDHqgqEQMyqA.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/I5FMltbcuDHqgqEQMyqA.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/I5FMltbcuDHqgqEQMyqA.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/I5FMltbcuDHqgqEQMyqA.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/I5FMltbcuDHqgqEQMyqA.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/I5FMltbcuDHqgqEQMyqA.png?auto=format&w=600 600w" width="300" />
  <figcaption>
    The majority of all transactions happen on the web.
  </figcaption>
</figure>
<h2 id="technical-deep-dive">Technical deep-dive <a class="w-headline-link" href="https://web.dev/mishipay/#technical-deep-dive">#</a></h2>
<h3 id="locating-mishipay-enabled-stores">Locating MishiPay enabled stores <a class="w-headline-link" href="https://web.dev/mishipay/#locating-mishipay-enabled-stores">#</a></h3>
<p>To enable this feature, we rely on the
<a href="https://developer.mozilla.org/docs/Web/API/Geolocation/getCurrentPosition" rel="noopener"><code>getCurrentPosition()</code></a>
API along with an IP-based fallback solution.</p>
<div><pre class="language-js"><code class="language-js"><span class="token keyword">const</span> geoOptions <span class="token operator">=</span> <span class="token punctuation">{</span><br />  <span class="token literal-property property">timeout</span><span class="token operator">:</span> <span class="token number">10</span> <span class="token operator">*</span> <span class="token number">1000</span><span class="token punctuation">,</span><br />  <span class="token literal-property property">enableHighAccuracy</span><span class="token operator">:</span> <span class="token boolean">true</span><span class="token punctuation">,</span><br />  <span class="token literal-property property">maximumAge</span><span class="token operator">:</span> <span class="token number">0</span><span class="token punctuation">,</span><br /><span class="token punctuation">}</span><span class="token punctuation">;</span><br /><br />window<span class="token punctuation">.</span>navigator<span class="token punctuation">.</span>geolocation<span class="token punctuation">.</span><span class="token function">getCurrentPosition</span><span class="token punctuation">(</span><br />  <span class="token punctuation">(</span><span class="token parameter">position</span><span class="token punctuation">)</span> <span class="token operator">=></span> <span class="token punctuation">{</span><br />    <span class="token keyword">const</span> cords <span class="token operator">=</span> position<span class="token punctuation">.</span>coords<span class="token punctuation">;</span><br />    console<span class="token punctuation">.</span><span class="token function">log</span><span class="token punctuation">(</span><span class="token template-string"><span class="token template-punctuation string">`</span><span class="token string">Latitude :  </span><span class="token interpolation"><span class="token interpolation-punctuation punctuation">${</span>cords<span class="token punctuation">.</span>latitude<span class="token interpolation-punctuation punctuation">}</span></span><span class="token template-punctuation string">`</span></span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />    console<span class="token punctuation">.</span><span class="token function">log</span><span class="token punctuation">(</span><span class="token template-string"><span class="token template-punctuation string">`</span><span class="token string">Longitude :  </span><span class="token interpolation"><span class="token interpolation-punctuation punctuation">${</span>cords<span class="token punctuation">.</span>longitude<span class="token interpolation-punctuation punctuation">}</span></span><span class="token template-punctuation string">`</span></span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token punctuation">}</span><span class="token punctuation">,</span><br />  <span class="token punctuation">(</span><span class="token parameter">error</span><span class="token punctuation">)</span> <span class="token operator">=></span> <span class="token punctuation">{</span><br />    console<span class="token punctuation">.</span><span class="token function">debug</span><span class="token punctuation">(</span><span class="token template-string"><span class="token template-punctuation string">`</span><span class="token string">Error: </span><span class="token interpolation"><span class="token interpolation-punctuation punctuation">${</span>error<span class="token punctuation">.</span>code<span class="token interpolation-punctuation punctuation">}</span></span><span class="token string">:</span><span class="token interpolation"><span class="token interpolation-punctuation punctuation">${</span>error<span class="token punctuation">.</span>message<span class="token interpolation-punctuation punctuation">}</span></span><span class="token template-punctuation string">`</span></span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />    <span class="token comment">/**<br />     * Invoke the IP based location services<br />     * to fetch the latitude and longitude of the user.<br />     */</span><br />  <span class="token punctuation">}</span><span class="token punctuation">,</span><br />  geoOptions<span class="token punctuation">,</span><br /><span class="token punctuation">)</span><span class="token punctuation">;</span></code></pre>
</div><p>This approach worked well in the earlier versions of the app, but was later proven to be a huge pain
point for MishiPay's users for the following reasons:</p>
<ul>
<li>Location inaccuracies in the IP-based fallback solutions.</li>
<li>A growing listing of MishiPay-enabled stores per region requires users to scroll a list and
identify the correct store.</li>
<li>Users accidentally occasionally choose the wrong store, causing the purchases to be recorded
incorrectly.</li>
</ul>
<p>To address these issues, we embedded unique geolocated QR codes on the in-store displays for each
store. It paved the way for a faster onboarding experience. Users simply scan the geolocated QR
codes printed on marketing material present in the stores to access the Scan &amp; Go web application.
This way, they can avoid typing in the web address <code>mishipay.shop</code> to access the service.</p>
<figure>
  <video autoplay="" height="600" loop="" muted="" playsinline="" width="1296">      <source src="https://storage.googleapis.com/web-dev-uploads/video/8WbTDNrhLsU0El80frMBGE4eMCD3/NqyMBZGYzGSNqLE7soXR.mp4" type="video/mp4" />    </video>
  <figcaption>
    In-store scanning experience using the PWA.
  </figcaption>
</figure>
<h3 id="scanning-products">Scanning products <a class="w-headline-link" href="https://web.dev/mishipay/#scanning-products">#</a></h3>
<p>A core feature in the MishiPay app is the barcode scanning as this empowers our users to scan their
own purchases and see the running total even before they would otherwise have reached a cash
register.</p>
<p>To build a scanning experience on the web, we have identified three core layers.</p>
<img alt="Diagram showing the three main thread layers: video stream, processing layer, and decoder layer." decoding="async" height="358" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format" srcset="https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/jRJeqbGW7yqU8VpdbjBO.png?auto=format&w=1600 1600w" width="800" />
<h3 id="video-stream">Video stream <a class="w-headline-link" href="https://web.dev/mishipay/#video-stream">#</a></h3>
<p>With the help of the
<a href="https://developer.mozilla.org/docs/Web/API/MediaDevices/getUserMedia" rel="noopener"><code>getUserMedia()</code></a> method, we
can access the user's rear view camera with the constraints listed below. Invoking the method
automatically triggers a prompt for users to accept or deny access to their camera. Once we have
access to the video stream, we can relay it to a video element as shown below:</p>
<div><pre class="language-js"><code class="language-js"><span class="token comment">/**<br /> * Video Stream Layer<br /> * https://developer.mozilla.org/docs/Web/API/MediaDevices/getUserMedia<br /> */</span><br /><span class="token keyword">const</span> canvasEle <span class="token operator">=</span> document<span class="token punctuation">.</span><span class="token function">getElementById</span><span class="token punctuation">(</span><span class="token string">'canvas'</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br /><span class="token keyword">const</span> videoEle <span class="token operator">=</span> document<span class="token punctuation">.</span><span class="token function">getElementById</span><span class="token punctuation">(</span><span class="token string">'videoElement'</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br /><span class="token keyword">const</span> canvasCtx <span class="token operator">=</span> canvasEle<span class="token punctuation">.</span><span class="token function">getContext</span><span class="token punctuation">(</span><span class="token string">'2d'</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br /><span class="token function">fetchVideoStream</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br /><span class="token keyword">function</span> <span class="token function">fetchVideoStream</span><span class="token punctuation">(</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br />  <span class="token keyword">let</span> constraints <span class="token operator">=</span> <span class="token punctuation">{</span> <span class="token literal-property property">video</span><span class="token operator">:</span> <span class="token punctuation">{</span> <span class="token literal-property property">facingMode</span><span class="token operator">:</span> <span class="token string">'environment'</span> <span class="token punctuation">}</span> <span class="token punctuation">}</span><span class="token punctuation">;</span><br />  <span class="token keyword">if</span> <span class="token punctuation">(</span>navigator<span class="token punctuation">.</span>mediaDevices <span class="token operator">!==</span> <span class="token keyword">undefined</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br />    navigator<span class="token punctuation">.</span>mediaDevices<br />      <span class="token punctuation">.</span><span class="token function">getUserMedia</span><span class="token punctuation">(</span>constraints<span class="token punctuation">)</span><br />      <span class="token punctuation">.</span><span class="token function">then</span><span class="token punctuation">(</span><span class="token punctuation">(</span><span class="token parameter">stream</span><span class="token punctuation">)</span> <span class="token operator">=></span> <span class="token punctuation">{</span><br />        videoEle<span class="token punctuation">.</span>srcObject <span class="token operator">=</span> stream<span class="token punctuation">;</span><br />        videoStream <span class="token operator">=</span> stream<span class="token punctuation">;</span><br />        videoEle<span class="token punctuation">.</span><span class="token function">play</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />        <span class="token comment">// Initiate frame capture - Processing Layer.</span><br />      <span class="token punctuation">}</span><span class="token punctuation">)</span><br />      <span class="token punctuation">.</span><span class="token function">catch</span><span class="token punctuation">(</span><span class="token punctuation">(</span><span class="token parameter">error</span><span class="token punctuation">)</span> <span class="token operator">=></span> <span class="token punctuation">{</span><br />        console<span class="token punctuation">.</span><span class="token function">debug</span><span class="token punctuation">(</span>error<span class="token punctuation">)</span><span class="token punctuation">;</span><br />        console<span class="token punctuation">.</span><span class="token function">warn</span><span class="token punctuation">(</span><span class="token template-string"><span class="token template-punctuation string">`</span><span class="token string">Failed to access the stream:</span><span class="token interpolation"><span class="token interpolation-punctuation punctuation">${</span>error<span class="token punctuation">.</span>name<span class="token interpolation-punctuation punctuation">}</span></span><span class="token template-punctuation string">`</span></span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />      <span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token punctuation">}</span> <span class="token keyword">else</span> <span class="token punctuation">{</span><br />    console<span class="token punctuation">.</span><span class="token function">warn</span><span class="token punctuation">(</span><span class="token template-string"><span class="token template-punctuation string">`</span><span class="token string">getUserMedia API not supported!!</span><span class="token template-punctuation string">`</span></span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token punctuation">}</span><br /><span class="token punctuation">}</span></code></pre>
</div><h3 id="processing-layer">Processing layer <a class="w-headline-link" href="https://web.dev/mishipay/#processing-layer">#</a></h3>
<p>For detecting a barcode in a given video stream, we need to periodically capture frames and transfer
them to the decoder layer. To capture a frame, we simply draw the streams from <code>VideoElement</code> onto
an <code>HTMLCanvasElement</code> using the
<a href="https://developer.mozilla.org/docs/Web/API/CanvasRenderingContext2D/drawImage" rel="noopener"><code>drawImage()</code></a>
method of the <a href="https://developer.mozilla.org/docs/Web/API/Canvas_API" rel="noopener">Canvas API</a>.</p>
<div><pre class="language-js"><code class="language-js"><span class="token comment">/**<br /> * Processing Layer - Frame Capture<br /> * https://developer.mozilla.org/en-US/docs/Web/API/Canvas_API/Manipulating_video_using_canvas<br /> */</span><br /><span class="token keyword">async</span> <span class="token keyword">function</span> <span class="token function">captureFrames</span><span class="token punctuation">(</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br />  <span class="token keyword">if</span> <span class="token punctuation">(</span>videoEle<span class="token punctuation">.</span>readyState <span class="token operator">===</span> videoEle<span class="token punctuation">.</span><span class="token constant">HAVE_ENOUGH_DATA</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br />    <span class="token keyword">const</span> canvasHeight <span class="token operator">=</span> <span class="token punctuation">(</span>canvasEle<span class="token punctuation">.</span>height <span class="token operator">=</span> videoEle<span class="token punctuation">.</span>videoHeight<span class="token punctuation">)</span><span class="token punctuation">;</span><br />    <span class="token keyword">const</span> canvasWidth <span class="token operator">=</span> <span class="token punctuation">(</span>canvasEle<span class="token punctuation">.</span>width <span class="token operator">=</span> videoEle<span class="token punctuation">.</span>videoWidth<span class="token punctuation">)</span><span class="token punctuation">;</span><br />    canvasCtx<span class="token punctuation">.</span><span class="token function">drawImage</span><span class="token punctuation">(</span>videoEle<span class="token punctuation">,</span> <span class="token number">0</span><span class="token punctuation">,</span> <span class="token number">0</span><span class="token punctuation">,</span> canvasWidth<span class="token punctuation">,</span> canvasHeight<span class="token punctuation">)</span><span class="token punctuation">;</span><br />    <span class="token comment">// Transfer the `canvasEle` to the decoder for barcode detection.</span><br />    <span class="token keyword">const</span> result <span class="token operator">=</span> <span class="token keyword">await</span> <span class="token function">decodeBarcode</span><span class="token punctuation">(</span>canvasEle<span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token punctuation">}</span> <span class="token keyword">else</span> <span class="token punctuation">{</span><br />    console<span class="token punctuation">.</span><span class="token function">log</span><span class="token punctuation">(</span><span class="token string">'Video feed not available yet'</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token punctuation">}</span><br /><span class="token punctuation">}</span></code></pre>
</div><p>For advanced use cases, this layer also performs some pre-processing tasks such as cropping,
rotating, or converting to grayscale. These tasks can be CPU-intensive and result in the application
being unresponsive given that barcode scanning is a long-running operation. With the help of the
<a href="https://developer.mozilla.org/docs/Web/API/OffscreenCanvas" rel="noopener">OffscreenCanvas</a> API, we can offload
the CPU-intensive task to a web worker. On devices that support hardware graphics acceleration,
WebGL API and its
<a href="https://developer.mozilla.org/docs/Web/API/WebGL2RenderingContext" rel="noopener"><code>WebGL2RenderingContext</code></a> can
optimize gains on the CPU-intensive pre-processing tasks.</p>
<h3 id="decoder-layer">Decoder layer <a class="w-headline-link" href="https://web.dev/mishipay/#decoder-layer">#</a></h3>
<p>The final layer is the decoder layer which is responsible for decoding barcodes from the frames
captured by the processing layer. Thanks to the
<a href="https://developer.mozilla.org/docs/Web/API/Barcode_Detection_API" rel="noopener">Shape Detection API</a> (which is
not yet available on all browsers) the browser itself decodes the barcode from an
<code>ImageBitmapSource</code>, which can be an <code>img</code> element, an SVG <code>image</code> element, a <code>video</code> element, a
<code>canvas</code> element, a <code>Blob</code> object, an <code>ImageData</code> object, or an <code>ImageBitmap</code> object.</p>
<img alt="Diagram showing the three main thread layers: video stream, processing layer, and Shape Detection API." decoding="async" height="358" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format" srcset="https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GR4od5fHOxys6lrxttPn.png?auto=format&w=1600 1600w" width="800" />
<div><pre class="language-js"><code class="language-js"><span class="token comment">/**<br /> * Barcode Decoder with Shape Detection API<br /> * https://web.dev/shape-detection/<br /> */</span><br /><span class="token keyword">async</span> <span class="token keyword">function</span> <span class="token function">decodeBarcode</span><span class="token punctuation">(</span><span class="token parameter">canvas</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br />  <span class="token keyword">const</span> formats <span class="token operator">=</span> <span class="token punctuation">[</span><br />    <span class="token string">'aztec'</span><span class="token punctuation">,</span><br />    <span class="token string">'code_128'</span><span class="token punctuation">,</span><br />    <span class="token string">'code_39'</span><span class="token punctuation">,</span><br />    <span class="token string">'code_93'</span><span class="token punctuation">,</span><br />    <span class="token string">'codabar'</span><span class="token punctuation">,</span><br />    <span class="token string">'data_matrix'</span><span class="token punctuation">,</span><br />    <span class="token string">'ean_13'</span><span class="token punctuation">,</span><br />    <span class="token string">'ean_8'</span><span class="token punctuation">,</span><br />    <span class="token string">'itf'</span><span class="token punctuation">,</span><br />    <span class="token string">'pdf417'</span><span class="token punctuation">,</span><br />    <span class="token string">'qr_code'</span><span class="token punctuation">,</span><br />    <span class="token string">'upc_a'</span><span class="token punctuation">,</span><br />    <span class="token string">'upc_e'</span><span class="token punctuation">,</span><br />  <span class="token punctuation">]</span><span class="token punctuation">;</span><br />  <span class="token keyword">const</span> barcodeDetector <span class="token operator">=</span> <span class="token keyword">new</span> <span class="token class-name">window<span class="token punctuation">.</span>BarcodeDetector</span><span class="token punctuation">(</span><span class="token punctuation">{</span><br />    formats<span class="token punctuation">,</span><br />  <span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token keyword">try</span> <span class="token punctuation">{</span><br />    <span class="token keyword">const</span> barcodes <span class="token operator">=</span> <span class="token keyword">await</span> barcodeDetector<span class="token punctuation">.</span><span class="token function">detect</span><span class="token punctuation">(</span>canvas<span class="token punctuation">)</span><span class="token punctuation">;</span><br />    console<span class="token punctuation">.</span><span class="token function">log</span><span class="token punctuation">(</span>barcodes<span class="token punctuation">)</span><span class="token punctuation">;</span><br />    <span class="token keyword">return</span> barcodes<span class="token punctuation">.</span>length <span class="token operator">></span> <span class="token number">0</span> <span class="token operator">?</span> barcodes<span class="token punctuation">[</span><span class="token number">0</span><span class="token punctuation">]</span><span class="token punctuation">[</span><span class="token string">'rawValue'</span><span class="token punctuation">]</span> <span class="token operator">:</span> <span class="token keyword">undefined</span><span class="token punctuation">;</span><br />  <span class="token punctuation">}</span> <span class="token keyword">catch</span> <span class="token punctuation">(</span>e<span class="token punctuation">)</span> <span class="token punctuation">{</span><br />    <span class="token keyword">throw</span> e<span class="token punctuation">;</span><br />  <span class="token punctuation">}</span><br /><span class="token punctuation">}</span></code></pre>
</div><p>For devices that don't support the Shape Detection API yet, we need a fallback solution to decode
the barcodes. The Shape Detection API exposes a
<a href="https://developer.mozilla.org/docs/Web/API/BarcodeDetector/getSupportedFormats" rel="noopener"><code>getSupportedFormats()</code></a>
method which helps switch between the Shape Detection API and the fallback solution.</p>
<div><pre class="language-js"><code class="language-js"><span class="token comment">// Feature detection.</span><br /><span class="token keyword">if</span> <span class="token punctuation">(</span><span class="token operator">!</span><span class="token punctuation">(</span><span class="token string">'BarceodeDetector'</span> <span class="token keyword">in</span> window<span class="token punctuation">)</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br />  <span class="token keyword">return</span><span class="token punctuation">;</span><br /><span class="token punctuation">}</span><br /><span class="token comment">// Check supported barcode formats.</span><br />BarcodeDetector<span class="token punctuation">.</span><span class="token function">getSupportedFormats</span><span class="token punctuation">(</span><span class="token punctuation">)</span><br /><span class="token punctuation">.</span><span class="token function">then</span><span class="token punctuation">(</span><span class="token punctuation">(</span><span class="token parameter">supportedFormats</span><span class="token punctuation">)</span> <span class="token operator">=></span> <span class="token punctuation">{</span><br />  supportedFormats<span class="token punctuation">.</span><span class="token function">forEach</span><span class="token punctuation">(</span><span class="token punctuation">(</span><span class="token parameter">format</span><span class="token punctuation">)</span> <span class="token operator">=></span> console<span class="token punctuation">.</span><span class="token function">log</span><span class="token punctuation">(</span>format<span class="token punctuation">)</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br /><span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span></code></pre>
</div><img alt="Flow diagram showing how, dependent on Barcode Detector support and the supported barcode formats, either the Shape Detection API or the fallback solution  is being used." decoding="async" height="404" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format" srcset="https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/GmrPC7mFTdtsEdS1BDWp.png?auto=format&w=1600 1600w" width="800" />
<h3 id="fallback-solution">Fallback solution <a class="w-headline-link" href="https://web.dev/mishipay/#fallback-solution">#</a></h3>
<p>Several open-source and enterprise scanning libraries are available that can be easily integrated
with any web application to implement scanning. Here are some of the libraries that MishiPay
recommend.</p>
<div class="table-wrapper scrollbar">
  <table>
    <thead>
      <tr>
        <th>Library Name</th>
        <th>Type</th>
        <th>Wasm Solution</th>
        <th>Barcode Formats</th>
      </tr>
    </thead>
    <tbody>
      <tr>
        <td><a href="https://github.com/serratus/quaggaJS">QuaggaJs</a></td>
        <td>Open Source</td>
        <td>No</td>
        <td>1D</td>
      </tr>
      <tr>
        <td><a href="https://github.com/zxing-js/library">ZxingJs</a></td>
        <td>Open Source</td>
        <td>No</td>
        <td>1D & 2D (Limited)</td>
      </tr>
      <tr>
        <td><a href="https://codecorp.com/products">CodeCorp</a></td>
        <td>Enterprise</td>
        <td>Yes</td>
        <td>1D & 2D</td>
      </tr>
      <tr>
        <td><a href="https://docs.scandit.com/stable/web/">Scandit</a></td>
        <td>Enterprise</td>
        <td>Yes</td>
        <td>1D & 2D</td>
      </tr>
    </tbody>
    <caption style="max-width:initial;">
      Comparison of open-source and commercial barcode scanning libraries
    </caption>
  </table>
</div>
<p>All the above libraries are full-fledged SDKs that compose all the layers discussed above. They also
expose interfaces to support various scanning operations. Depending on the barcode formats and
detection speed needed for the business case, a decision can be between Wasm and non-Wasm solutions.
Despite the overhead of requiring an additional resource (Wasm) to decode the barcode, Wasm
solutions outperform the non-Wasm solution in terms of accuracy.</p>
<p><a href="https://docs.scandit.com/stable/web/" rel="noopener">Scandit</a> was our primary choice. It supports all barcode
formats required for our business use cases; it beats all the available open-source libraries in
scanning speed.</p>
<h2 id="future-of-scanning">Future of scanning <a class="w-headline-link" href="https://web.dev/mishipay/#future-of-scanning">#</a></h2>
<p>Once the Shape Detection API is fully supported by all major browsers, we could potentially have a
new HTML element <code>&lt;scanner&gt;</code> that has the capabilities required for a barcode scanner. Engineering
at MishiPay believes there is a solid use case for the barcode scanning functionality to be a new
HTML element due to the growing number of open source and licensed libraries that are enabling
experiences such as Scan &amp; Go and many others.</p>
<h2 id="conclusion">Conclusion <a class="w-headline-link" href="https://web.dev/mishipay/#conclusion">#</a></h2>
<p>App fatigue is an issue that developers face when their products enter the market. Users often want
to understand the value that an application gives them before they download it. In a store, where
MishiPay saves shoppers' time and improves their experience, it is counterintuitive to wait for a
download before they can use an application. This is where our PWA helps. By eliminating the barrier
to entry, we have increased our transactions by 10 times and enabled our users to save 2.5 years of
waiting in the queue.</p>
<h2 id="acknowledgements">Acknowledgements <a class="w-headline-link" href="https://web.dev/mishipay/#acknowledgements">#</a></h2>
<p>This article was reviewed by <a href="https://github.com/jpmedley" rel="noopener">Joe Medley</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[SVGcode: a PWA to convert raster images to SVG vector graphics]]></title>
<description><![CDATA[In a hurry? Go straight to the SVGcode app and read the article later. 

      
  
    (If you prefer watching over reading, this article is also available as a video.)
  

From raster to vector #
Have you ever scaled an image and the result was pixelated and unsatisfactory? If
so, you have proba...]]></description>
<link>https://tsecurity.de/de/1725694/web-tipps/svgcode-a-pwa-to-convert-raster-images-to-svg-vector-graphics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1725694/web-tipps/svgcode-a-pwa-to-convert-raster-images-to-svg-vector-graphics/</guid>
<pubDate>Thu, 08 Dec 2022 19:45:05 +0100</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<aside class="aside flow bg-state-info-bg color-state-info-text"><div class=" flow"> In a hurry? Go <a href="https://svgco.de/">straight to the SVGcode app</a> and read the article later. </div></aside>
<figure data-size="full">
  <div class="youtube">  <lite-youtube videoid="kcvfyQh6J-0">  </lite-youtube></div>
  <figcaption>
    (If you prefer watching over reading, this article is also available as a <a href="https://youtu.be/kcvfyQh6J-0">video</a>.)
  </figcaption>
</figure>
<h2 id="from-raster-to-vector">From raster to vector <a class="w-headline-link" href="https://web.dev/svgcode/#from-raster-to-vector">#</a></h2>
<p>Have you ever scaled an image and the result was pixelated and unsatisfactory? If
so, you have probably dealt with a raster image format such as WebP, PNG, or JPG.</p>
<figure>
  <video autoplay="" loop="" muted="" playsinline="">      <source src="https://storage.googleapis.com/web-dev-uploads/video/8WbTDNrhLsU0El80frMBGE4eMCD3/bIiC6vyZLqgGWPuFF9od.mp4" type="video/mp4" />    </video>
  <figcaption>
    Scaling up a raster image makes it look pixelated.
  </figcaption>
</figure>
<p>In contrast, vector graphics are images that are defined by points in a coordinate system. These
points are connected by lines and curves to form polygons and other shapes. Vector graphics have an
advantage over raster graphics in that they may be scaled up or down to any resolution
without pixelation.</p>
<figure>
  <video autoplay="" loop="" muted="" playsinline="">      <source src="https://storage.googleapis.com/web-dev-uploads/video/8WbTDNrhLsU0El80frMBGE4eMCD3/yM32DfKFp8ooBAshjlUE.mp4" type="video/mp4" />    </video>
  <figcaption>
    Scaling up a vector image with no loss of quality.
  </figcaption>
</figure>
<h2 id="introducing-svgcode">Introducing SVGcode <a class="w-headline-link" href="https://web.dev/svgcode/#introducing-svgcode">#</a></h2>
<p>I have built a PWA called <a href="https://svgco.de/" rel="noopener">SVGcode</a> that can help you convert raster images to
vectors. Credit where credit is due: I didn't invent this. With SVGcode, I just stand on the
shoulders of a command line tool called <a href="http://potrace.sourceforge.net/" rel="noopener">Potrace</a> by
<a href="https://www.mathstat.dal.ca/~selinger/" rel="noopener">Peter Selinger</a> that I have
<a href="https://www.npmjs.com/package/esm-potrace-wasm" rel="noopener">converted to Web Assembly</a>, so it can be used in a
Web app.</p>
<figure>
  <img alt="SVGcode application screenshot." decoding="async" height="483" loading="lazy" sizes="(min-width: 800px) 800px, calc(100vw - 48px)" src="https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format" srcset="https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=200 200w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=228 228w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=260 260w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=296 296w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=338 338w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=385 385w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=439 439w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=500 500w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=571 571w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=650 650w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=741 741w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=845 845w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=964 964w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=1098 1098w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=1252 1252w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=1428 1428w, https://web-dev.imgix.net/image/8WbTDNrhLsU0El80frMBGE4eMCD3/xMosQFxacBsz116CcFwy.png?auto=format&w=1600 1600w" width="800" />
  <figcaption>
    The <a href="https://svgco.de/">SVGcode</a> app.
  </figcaption>
</figure>
<h3 id="using-svgcode">Using SVGcode <a class="w-headline-link" href="https://web.dev/svgcode/#using-svgcode">#</a></h3>
<p>First, I want to show you how to use the app. I start with the teaser image for Chrome Dev Summit
that I downloaded from the ChromiumDev Twitter channel. This is a PNG raster image that I then
drag onto the SVGcode app. When I drop the file, the app traces the image color by color,
until a vectorized version of the input appears. I can now zoom into the image, and as you can see,
the edges stay sharp. But zooming in on the Chrome logo, you can see that the tracing wasn't
perfect, and especially the outlines of the logo look a bit speckled. I can improve the result by
de-speckling the tracing by suppressing speckles of up to, say, five pixels.</p>
<figure>
  <video autoplay="" loop="" muted="" playsinline="">      <source src="https://storage.googleapis.com/web-dev-uploads/video/8WbTDNrhLsU0El80frMBGE4eMCD3/WvmYtNTHAbINP3ec1h1w.mp4" type="video/mp4" />    </video>
  <figcaption>
    Converting a dropped image to SVG.
  </figcaption>
</figure>
<h3 id="posterization-in-svgcode">Posterization in SVGcode <a class="w-headline-link" href="https://web.dev/svgcode/#posterization-in-svgcode">#</a></h3>
<p>An important step for vectorization, especially for photographic images, is posterizing the input
image to reduce the number of colors. SVGcode allows me to do this per color channel, and see the
resulting SVG as I make changes. When I'm happy with the result, I can save the SVG to my hard disk
and use it wherever I like.</p>
<figure>
  <video autoplay="" loop="" muted="" playsinline="">      <source src="https://storage.googleapis.com/web-dev-uploads/video/8WbTDNrhLsU0El80frMBGE4eMCD3/BzcR6yPyuQ0TIgzwYbLy.mp4" type="video/mp4" />    </video>
  <figcaption>
    Posterizing an image to reduce the number of colors.
  </figcaption>
</figure>
<h2 id="apis-used-in-svgcode">APIs used in SVGcode <a class="w-headline-link" href="https://web.dev/svgcode/#apis-used-in-svgcode">#</a></h2>
<p>Now that you have seen what the app is capable of, let me show you some of the APIs that help make
the magic happen.</p>
<h3 id="progressive-web-app">Progressive Web App <a class="w-headline-link" href="https://web.dev/svgcode/#progressive-web-app">#</a></h3>
<p>SVGcode is an installable Progressive Web App and therefore fully offline enabled. The app is based
on the
<a href="https://github.com/vitejs/vite/tree/main/packages/create-vite/template-vanilla" rel="noopener">Vanilla JS template</a>
for <a href="https://github.com/vitejs/vite" rel="noopener">Vite.js</a> and uses the popular
<a href="https://github.com/antfu/vite-plugin-pwa" rel="noopener">Vite plugin PWA</a>, which creates a service worker that
uses <a href="https://developer.chrome.com/docs/workbox/" rel="noopener">Workbox.js</a> under the hood. Workbox is a set
of libraries that can power a production-ready service worker for Progressive Web Apps, This pattern
may not necessarily work for all apps, but for SVGcode's use case it's great.</p>
<h4 id="window-controls-overlay">Window Controls Overlay <a class="w-headline-link" href="https://web.dev/svgcode/#window-controls-overlay">#</a></h4>
<p>To maximize the available screen real estate, SVGcode uses
<a href="https://web.dev/window-controls-overlay/">Window Controls Overlay</a> customization by moving its main menu up into
the titlebar area. You can see this get activated at the end of the install flow.</p>
<figure>
  <video autoplay="" loop="" muted="" playsinline="">      <source src="https://storage.googleapis.com/web-dev-uploads/video/8WbTDNrhLsU0El80frMBGE4eMCD3/aDk3LFxexL6g2NbH4RCA.mp4" type="video/mp4" />    </video>
  <figcaption>
    Installing SVGcode and activating the Window Controls Overlay customization.
  </figcaption>
</figure>
<h3 id="file-system-access-api">File System Access API <a class="w-headline-link" href="https://web.dev/svgcode/#file-system-access-api">#</a></h3>
<p>To open input image files and save the resulting SVGs, I use the
<a href="https://web.dev/file-system-access/">File System Access API</a>. This allows me to keep a reference to previously
opened files and to continue where I left off, even after an app reload. Whenever an image gets
saved, it is optimized via the <a href="https://github.com/svg/svgo" rel="noopener">svgo</a> library, which may take a moment,
depending on the complexity of the SVG. Showing the file save dialog requires a user gesture. It is
therefore important to obtain the file handle before the SVG optimization happens, so the user
gesture is not invalidated by the time the optimized SVG is ready.</p>
<div><pre class="language-js"><code class="language-js"><span class="token keyword">try</span> <span class="token punctuation">{</span><br />  <span class="token keyword">let</span> svg <span class="token operator">=</span> svgOutput<span class="token punctuation">.</span>innerHTML<span class="token punctuation">;</span><br />  <span class="token keyword">let</span> handle <span class="token operator">=</span> <span class="token keyword">null</span><span class="token punctuation">;</span><br />  <span class="token comment">// To not consume the user gesture obtain the handle before preparing the</span><br />  <span class="token comment">// blob, which may take longer.</span><br />  <span class="token keyword">if</span> <span class="token punctuation">(</span>supported<span class="token punctuation">)</span> <span class="token punctuation">{</span><br />    handle <span class="token operator">=</span> <span class="token keyword">await</span> <span class="token function">showSaveFilePicker</span><span class="token punctuation">(</span><span class="token punctuation">{</span><br />      <span class="token literal-property property">types</span><span class="token operator">:</span> <span class="token punctuation">[</span><span class="token punctuation">{</span><span class="token literal-property property">description</span><span class="token operator">:</span> <span class="token string">'SVG file'</span><span class="token punctuation">,</span> <span class="token literal-property property">accept</span><span class="token operator">:</span> <span class="token punctuation">{</span><span class="token string-property property">'image/svg+xml'</span><span class="token operator">:</span> <span class="token punctuation">[</span><span class="token string">'.svg'</span><span class="token punctuation">]</span><span class="token punctuation">}</span><span class="token punctuation">}</span><span class="token punctuation">]</span><span class="token punctuation">,</span><br />    <span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token punctuation">}</span><br />  <span class="token function">showToast</span><span class="token punctuation">(</span>i18n<span class="token punctuation">.</span><span class="token function">t</span><span class="token punctuation">(</span><span class="token string">'optimizingSVG'</span><span class="token punctuation">)</span><span class="token punctuation">,</span> <span class="token number">Infinity</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  svg <span class="token operator">=</span> <span class="token keyword">await</span> <span class="token function">optimizeSVG</span><span class="token punctuation">(</span>svg<span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token function">showToast</span><span class="token punctuation">(</span>i18n<span class="token punctuation">.</span><span class="token function">t</span><span class="token punctuation">(</span><span class="token string">'savedSVG'</span><span class="token punctuation">)</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token keyword">const</span> blob <span class="token operator">=</span> <span class="token keyword">new</span> <span class="token class-name">Blob</span><span class="token punctuation">(</span><span class="token punctuation">[</span>svg<span class="token punctuation">]</span><span class="token punctuation">,</span> <span class="token punctuation">{</span><span class="token literal-property property">type</span><span class="token operator">:</span> <span class="token string">'image/svg+xml'</span><span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token keyword">await</span> <span class="token function">fileSave</span><span class="token punctuation">(</span>blob<span class="token punctuation">,</span> <span class="token punctuation">{</span><span class="token literal-property property">description</span><span class="token operator">:</span> <span class="token string">'SVG file'</span><span class="token punctuation">}</span><span class="token punctuation">,</span> handle<span class="token punctuation">)</span><span class="token punctuation">;</span><br /><span class="token punctuation">}</span> <span class="token keyword">catch</span> <span class="token punctuation">(</span>err<span class="token punctuation">)</span> <span class="token punctuation">{</span><br />  console<span class="token punctuation">.</span><span class="token function">error</span><span class="token punctuation">(</span>err<span class="token punctuation">.</span>name<span class="token punctuation">,</span> err<span class="token punctuation">.</span>message<span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token function">showToast</span><span class="token punctuation">(</span>err<span class="token punctuation">.</span>message<span class="token punctuation">)</span><span class="token punctuation">;</span><br /><span class="token punctuation">}</span></code></pre>
</div><h4 id="drag-an-drop">Drag an drop <a class="w-headline-link" href="https://web.dev/svgcode/#drag-an-drop">#</a></h4>
<p>For opening an input image, I can either use the file open feature, or, as you have seen above, just
drag and drop an image file onto the app. The file open feature is pretty straightforward, more
interesting is the drag and drop case. What's particularly nice about this is that you can
get a file system handle from the data transfer item via the
<a href="https://developer.mozilla.org/docs/Web/API/DataTransferItem/getAsFileSystemHandle" rel="noopener"><code>getAsFileSystemHandle()</code></a>
method. As mentioned before, I can persist this handle, so it's ready when the app gets reloaded.</p>
<div><pre class="language-js"><code class="language-js">document<span class="token punctuation">.</span><span class="token function">addEventListener</span><span class="token punctuation">(</span><span class="token string">'drop'</span><span class="token punctuation">,</span> <span class="token keyword">async</span> <span class="token punctuation">(</span><span class="token parameter">event</span><span class="token punctuation">)</span> <span class="token operator">=></span> <span class="token punctuation">{</span><br />  event<span class="token punctuation">.</span><span class="token function">preventDefault</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  dropContainer<span class="token punctuation">.</span>classList<span class="token punctuation">.</span><span class="token function">remove</span><span class="token punctuation">(</span><span class="token string">'dropenter'</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token keyword">const</span> item <span class="token operator">=</span> event<span class="token punctuation">.</span>dataTransfer<span class="token punctuation">.</span>items<span class="token punctuation">[</span><span class="token number">0</span><span class="token punctuation">]</span><span class="token punctuation">;</span><br />  <span class="token keyword">if</span> <span class="token punctuation">(</span>item<span class="token punctuation">.</span>kind <span class="token operator">===</span> <span class="token string">'file'</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br />    inputImage<span class="token punctuation">.</span><span class="token function">addEventListener</span><span class="token punctuation">(</span><br />      <span class="token string">'load'</span><span class="token punctuation">,</span><br />      <span class="token punctuation">(</span><span class="token punctuation">)</span> <span class="token operator">=></span> <span class="token punctuation">{</span><br />        <span class="token constant">URL</span><span class="token punctuation">.</span><span class="token function">revokeObjectURL</span><span class="token punctuation">(</span>blobURL<span class="token punctuation">)</span><span class="token punctuation">;</span><br />      <span class="token punctuation">}</span><span class="token punctuation">,</span><br />      <span class="token punctuation">{</span><span class="token literal-property property">once</span><span class="token operator">:</span> <span class="token boolean">true</span><span class="token punctuation">}</span><span class="token punctuation">,</span><br />    <span class="token punctuation">)</span><span class="token punctuation">;</span><br />    <span class="token keyword">const</span> handle <span class="token operator">=</span> <span class="token keyword">await</span> item<span class="token punctuation">.</span><span class="token function">getAsFileSystemHandle</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />    <span class="token keyword">if</span> <span class="token punctuation">(</span>handle<span class="token punctuation">.</span>kind <span class="token operator">!==</span> <span class="token string">'file'</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br />      <span class="token keyword">return</span><span class="token punctuation">;</span><br />    <span class="token punctuation">}</span><br />    <span class="token keyword">const</span> file <span class="token operator">=</span> <span class="token keyword">await</span> handle<span class="token punctuation">.</span><span class="token function">getFile</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />    <span class="token keyword">const</span> blobURL <span class="token operator">=</span> <span class="token constant">URL</span><span class="token punctuation">.</span><span class="token function">createObjectURL</span><span class="token punctuation">(</span>file<span class="token punctuation">)</span><span class="token punctuation">;</span><br />    inputImage<span class="token punctuation">.</span>src <span class="token operator">=</span> blobURL<span class="token punctuation">;</span><br />    <span class="token keyword">await</span> <span class="token function">set</span><span class="token punctuation">(</span><span class="token constant">FILE_HANDLE</span><span class="token punctuation">,</span> handle<span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token punctuation">}</span><br /><span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span></code></pre>
</div><p>For more details, check out the article on the <a href="https://web.dev/file-system-access/">File System Access API</a> and,
if you're interested, study the SVGcode source code in
<a href="https://github.com/tomayac/SVGcode/blob/main/src/js/filesystem.js" rel="noopener"><code>src/js/filesystem.js</code></a>.</p>
<h3 id="async-clipboard-api">Async Clipboard API <a class="w-headline-link" href="https://web.dev/svgcode/#async-clipboard-api">#</a></h3>
<p>SVGcode is also fully integrated with the operating system's clipboard via the Async Clipboard API.
You can paste images from the operating system's file explorer into the app either by clicking the
paste image button or by pressing command or control plus v on your keyboard.</p>
<figure>
  <video autoplay="" loop="" muted="" playsinline="">      <source src="https://storage.googleapis.com/web-dev-uploads/video/8WbTDNrhLsU0El80frMBGE4eMCD3/9wHL0Uc7eHFEFF99anaB.mp4" type="video/mp4" />    </video>
  <figcaption>
    Pasting an image from the file explorer into SVGcode.
  </figcaption>
</figure>
<p>The Async Clipboard API has recently gained the ability to deal with SVG images as well, so you can
also copy an SVG image and paste it into another application for further processing.</p>
<figure>
  <video autoplay="" loop="" muted="" playsinline="">      <source src="https://storage.googleapis.com/web-dev-uploads/video/8WbTDNrhLsU0El80frMBGE4eMCD3/KiGt5UHOvZZEvPhtwIny.mp4" type="video/mp4" />    </video>
  <figcaption>
    Copying an image from SVGcode into SVGOMG.
  </figcaption>
</figure>
<div><pre class="language-js"><code class="language-js">copyButton<span class="token punctuation">.</span><span class="token function">addEventListener</span><span class="token punctuation">(</span><span class="token string">'click'</span><span class="token punctuation">,</span> <span class="token keyword">async</span> <span class="token punctuation">(</span><span class="token punctuation">)</span> <span class="token operator">=></span> <span class="token punctuation">{</span><br />  <span class="token keyword">let</span> svg <span class="token operator">=</span> svgOutput<span class="token punctuation">.</span>innerHTML<span class="token punctuation">;</span><br />  <span class="token function">showToast</span><span class="token punctuation">(</span>i18n<span class="token punctuation">.</span><span class="token function">t</span><span class="token punctuation">(</span><span class="token string">'optimizingSVG'</span><span class="token punctuation">)</span><span class="token punctuation">,</span> <span class="token number">Infinity</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  svg <span class="token operator">=</span> <span class="token keyword">await</span> <span class="token function">optimizeSVG</span><span class="token punctuation">(</span>svg<span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token keyword">const</span> textBlob <span class="token operator">=</span> <span class="token keyword">new</span> <span class="token class-name">Blob</span><span class="token punctuation">(</span><span class="token punctuation">[</span>svg<span class="token punctuation">]</span><span class="token punctuation">,</span> <span class="token punctuation">{</span><span class="token literal-property property">type</span><span class="token operator">:</span> <span class="token string">'text/plain'</span><span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token keyword">const</span> svgBlob <span class="token operator">=</span> <span class="token keyword">new</span> <span class="token class-name">Blob</span><span class="token punctuation">(</span><span class="token punctuation">[</span>svg<span class="token punctuation">]</span><span class="token punctuation">,</span> <span class="token punctuation">{</span><span class="token literal-property property">type</span><span class="token operator">:</span> <span class="token string">'image/svg+xml'</span><span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  navigator<span class="token punctuation">.</span>clipboard<span class="token punctuation">.</span><span class="token function">write</span><span class="token punctuation">(</span><span class="token punctuation">[</span><br />    <span class="token keyword">new</span> <span class="token class-name">ClipboardItem</span><span class="token punctuation">(</span><span class="token punctuation">{</span><br />      <span class="token punctuation">[</span>svgBlob<span class="token punctuation">.</span>type<span class="token punctuation">]</span><span class="token operator">:</span> svgBlob<span class="token punctuation">,</span><br />      <span class="token punctuation">[</span>textBlob<span class="token punctuation">.</span>type<span class="token punctuation">]</span><span class="token operator">:</span> textBlob<span class="token punctuation">,</span><br />    <span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">,</span><br />  <span class="token punctuation">]</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token function">showToast</span><span class="token punctuation">(</span>i18n<span class="token punctuation">.</span><span class="token function">t</span><span class="token punctuation">(</span><span class="token string">'copiedSVG'</span><span class="token punctuation">)</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br /><span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span></code></pre>
</div><p>To learn more, read the <a href="https://web.dev/async-clipboard/">Async Clipboard</a> article, or see the file
<a href="https://github.com/tomayac/SVGcode/blob/main/src/js/clipboard.js" rel="noopener"><code>src/js/clipboard.js</code></a>.</p>
<h3 id="file-handling">File Handling <a class="w-headline-link" href="https://web.dev/svgcode/#file-handling">#</a></h3>
<p>One of my favorite features of SVGcode is how well it blends in with the operating system. As an
installed PWA, it can become a file handler, or even the default file handler, for image files. This
means that when I'm in the Finder on my macOS machine, I can right-click an image and open it with
SVGcode. This feature is called File Handling and works based on the file_handlers property in the
Web App Manifest and the launch queue, which allows the app to consume the passed file.</p>
<figure>
  <video autoplay="" loop="" muted="" playsinline="">      <source src="https://storage.googleapis.com/web-dev-uploads/video/8WbTDNrhLsU0El80frMBGE4eMCD3/DEQLkm1vrt226xsAoysI.mp4" type="video/mp4" />    </video>
  <figcaption>
    Opening a file from the desktop with installed SVGcode app.
  </figcaption>
</figure>
<div><pre class="language-js"><code class="language-js">window<span class="token punctuation">.</span>launchQueue<span class="token punctuation">.</span><span class="token function">setConsumer</span><span class="token punctuation">(</span><span class="token keyword">async</span> <span class="token punctuation">(</span><span class="token parameter">launchParams</span><span class="token punctuation">)</span> <span class="token operator">=></span> <span class="token punctuation">{</span><br />  <span class="token keyword">if</span> <span class="token punctuation">(</span><span class="token operator">!</span>launchParams<span class="token punctuation">.</span>files<span class="token punctuation">.</span>length<span class="token punctuation">)</span> <span class="token punctuation">{</span><br />    <span class="token keyword">return</span><span class="token punctuation">;</span><br />  <span class="token punctuation">}</span><br />  <span class="token keyword">for</span> <span class="token punctuation">(</span><span class="token keyword">const</span> handle <span class="token keyword">of</span> launchParams<span class="token punctuation">.</span>files<span class="token punctuation">)</span> <span class="token punctuation">{</span><br />    <span class="token keyword">const</span> file <span class="token operator">=</span> <span class="token keyword">await</span> handle<span class="token punctuation">.</span><span class="token function">getFile</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />    <span class="token keyword">if</span> <span class="token punctuation">(</span>file<span class="token punctuation">.</span>type<span class="token punctuation">.</span><span class="token function">startsWith</span><span class="token punctuation">(</span><span class="token string">'image/'</span><span class="token punctuation">)</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br />      <span class="token keyword">const</span> blobURL <span class="token operator">=</span> <span class="token constant">URL</span><span class="token punctuation">.</span><span class="token function">createObjectURL</span><span class="token punctuation">(</span>file<span class="token punctuation">)</span><span class="token punctuation">;</span><br />      inputImage<span class="token punctuation">.</span><span class="token function">addEventListener</span><span class="token punctuation">(</span><br />        <span class="token string">'load'</span><span class="token punctuation">,</span><br />        <span class="token punctuation">(</span><span class="token punctuation">)</span> <span class="token operator">=></span> <span class="token punctuation">{</span><br />          <span class="token constant">URL</span><span class="token punctuation">.</span><span class="token function">revokeObjectURL</span><span class="token punctuation">(</span>blobURL<span class="token punctuation">)</span><span class="token punctuation">;</span><br />        <span class="token punctuation">}</span><span class="token punctuation">,</span><br />        <span class="token punctuation">{</span><span class="token literal-property property">once</span><span class="token operator">:</span> <span class="token boolean">true</span><span class="token punctuation">}</span><span class="token punctuation">,</span><br />      <span class="token punctuation">)</span><span class="token punctuation">;</span><br />      inputImage<span class="token punctuation">.</span>src <span class="token operator">=</span> blobURL<span class="token punctuation">;</span><br />      <span class="token keyword">await</span> <span class="token function">set</span><span class="token punctuation">(</span><span class="token constant">FILE_HANDLE</span><span class="token punctuation">,</span> handle<span class="token punctuation">)</span><span class="token punctuation">;</span><br />      <span class="token keyword">return</span><span class="token punctuation">;</span><br />    <span class="token punctuation">}</span><br />  <span class="token punctuation">}</span><br /><span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span></code></pre>
</div><p>For more information, see <a href="https://web.dev/file-handling/">Let installed web applications be file handlers</a>, and view the source code in
<a href="https://github.com/tomayac/SVGcode/blob/main/src/js/filehandling.js" rel="noopener"><code>src/js/filehandling.js</code></a>.</p>
<h3 id="web-share-files">Web Share (Files) <a class="w-headline-link" href="https://web.dev/svgcode/#web-share-files">#</a></h3>
<p>Another example of blending in with the operating system is the app's share feature. Assuming I want
to make edits to an SVG created with SVGcode, one way to deal with this would be to save the file,
launch the SVG editing app, and then open the SVG file from there. A smoother flow, though, is to
use the <a href="https://web.dev/web-share/#sharing-files">Web Share API</a>, which allows for files to be shared directly. So if
the SVG editing app is a share target, it can directly receive the file without deviation.</p>
<div><pre class="language-js"><code class="language-js">shareSVGButton<span class="token punctuation">.</span><span class="token function">addEventListener</span><span class="token punctuation">(</span><span class="token string">'click'</span><span class="token punctuation">,</span> <span class="token keyword">async</span> <span class="token punctuation">(</span><span class="token punctuation">)</span> <span class="token operator">=></span> <span class="token punctuation">{</span><br />  <span class="token keyword">let</span> svg <span class="token operator">=</span> svgOutput<span class="token punctuation">.</span>innerHTML<span class="token punctuation">;</span><br />  svg <span class="token operator">=</span> <span class="token keyword">await</span> <span class="token function">optimizeSVG</span><span class="token punctuation">(</span>svg<span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token keyword">const</span> suggestedFileName <span class="token operator">=</span><br />    <span class="token function">getSuggestedFileName</span><span class="token punctuation">(</span><span class="token keyword">await</span> <span class="token function">get</span><span class="token punctuation">(</span><span class="token constant">FILE_HANDLE</span><span class="token punctuation">)</span><span class="token punctuation">)</span> <span class="token operator">||</span> <span class="token string">'Untitled.svg'</span><span class="token punctuation">;</span><br />  <span class="token keyword">const</span> file <span class="token operator">=</span> <span class="token keyword">new</span> <span class="token class-name">File</span><span class="token punctuation">(</span><span class="token punctuation">[</span>svg<span class="token punctuation">]</span><span class="token punctuation">,</span> suggestedFileName<span class="token punctuation">,</span> <span class="token punctuation">{</span> <span class="token literal-property property">type</span><span class="token operator">:</span> <span class="token string">'image/svg+xml'</span> <span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token keyword">const</span> data <span class="token operator">=</span> <span class="token punctuation">{</span><br />    <span class="token literal-property property">files</span><span class="token operator">:</span> <span class="token punctuation">[</span>file<span class="token punctuation">]</span><span class="token punctuation">,</span><br />  <span class="token punctuation">}</span><span class="token punctuation">;</span><br />  <span class="token keyword">if</span> <span class="token punctuation">(</span>navigator<span class="token punctuation">.</span><span class="token function">canShare</span><span class="token punctuation">(</span>data<span class="token punctuation">)</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br />    <span class="token keyword">try</span> <span class="token punctuation">{</span><br />      <span class="token keyword">await</span> navigator<span class="token punctuation">.</span><span class="token function">share</span><span class="token punctuation">(</span>data<span class="token punctuation">)</span><span class="token punctuation">;</span><br />    <span class="token punctuation">}</span> <span class="token keyword">catch</span> <span class="token punctuation">(</span>err<span class="token punctuation">)</span> <span class="token punctuation">{</span><br />      <span class="token keyword">if</span> <span class="token punctuation">(</span>err<span class="token punctuation">.</span>name <span class="token operator">!==</span> <span class="token string">'AbortError'</span><span class="token punctuation">)</span> <span class="token punctuation">{</span><br />        console<span class="token punctuation">.</span><span class="token function">error</span><span class="token punctuation">(</span>err<span class="token punctuation">.</span>name<span class="token punctuation">,</span> err<span class="token punctuation">.</span>message<span class="token punctuation">)</span><span class="token punctuation">;</span><br />      <span class="token punctuation">}</span><br />    <span class="token punctuation">}</span><br />  <span class="token punctuation">}</span><br /><span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span></code></pre>
</div><figure>
  <video autoplay="" loop="" muted="" playsinline="">      <source src="https://storage.googleapis.com/web-dev-uploads/video/8WbTDNrhLsU0El80frMBGE4eMCD3/p3Dn9FXrNLPtb4syXnfl.mp4" type="video/mp4" />    </video>
  <figcaption>
    Sharing an SVG image to Gmail.
  </figcaption>
</figure>
<h3 id="web-share-target-files">Web Share Target (Files) <a class="w-headline-link" href="https://web.dev/svgcode/#web-share-target-files">#</a></h3>
<p>The other way round, SVGcode can also act as a share target and receive files from other apps. To
make this work, the app needs to let the operating system know via the
<a href="https://web.dev/web-share-target/">Web Share Target API</a> what types of data it can accept. This happens via a
dedicated field in the Web App Manifest.</p>
<div><pre class="language-json"><code class="language-json"><span class="token punctuation">{</span><br />  <span class="token property">"share_target"</span><span class="token operator">:</span> <span class="token punctuation">{</span><br />    <span class="token property">"action"</span><span class="token operator">:</span> <span class="token string">"https://svgco.de/share-target/"</span><span class="token punctuation">,</span><br />    <span class="token property">"method"</span><span class="token operator">:</span> <span class="token string">"POST"</span><span class="token punctuation">,</span><br />    <span class="token property">"enctype"</span><span class="token operator">:</span> <span class="token string">"multipart/form-data"</span><span class="token punctuation">,</span><br />    <span class="token property">"params"</span><span class="token operator">:</span> <span class="token punctuation">{</span><br />      <span class="token property">"files"</span><span class="token operator">:</span> <span class="token punctuation">[</span><br />        <span class="token punctuation">{</span><br />          <span class="token property">"name"</span><span class="token operator">:</span> <span class="token string">"image"</span><span class="token punctuation">,</span><br />          <span class="token property">"accept"</span><span class="token operator">:</span> <span class="token punctuation">[</span><span class="token string">"image/jpeg"</span><span class="token punctuation">,</span> <span class="token string">"image/png"</span><span class="token punctuation">,</span> <span class="token string">"image/webp"</span><span class="token punctuation">,</span> <span class="token string">"image/gif"</span><span class="token punctuation">]</span><br />        <span class="token punctuation">}</span><br />      <span class="token punctuation">]</span><br />    <span class="token punctuation">}</span><br />  <span class="token punctuation">}</span><br /><span class="token punctuation">}</span></code></pre>
</div><p>The <code>action</code> route does not actually exist, but is handled purely in the service worker's <code>fetch</code>
handler, which then passes on received files for actual processing in the app.</p>
<div><pre class="language-js"><code class="language-js">self<span class="token punctuation">.</span><span class="token function">addEventListener</span><span class="token punctuation">(</span><span class="token string">'fetch'</span><span class="token punctuation">,</span> <span class="token punctuation">(</span><span class="token parameter">fetchEvent</span><span class="token punctuation">)</span> <span class="token operator">=></span> <span class="token punctuation">{</span><br />  <span class="token keyword">if</span> <span class="token punctuation">(</span><br />    fetchEvent<span class="token punctuation">.</span>request<span class="token punctuation">.</span>url<span class="token punctuation">.</span><span class="token function">endsWith</span><span class="token punctuation">(</span><span class="token string">'/share-target/'</span><span class="token punctuation">)</span> <span class="token operator">&amp;&amp;</span><br />    fetchEvent<span class="token punctuation">.</span>request<span class="token punctuation">.</span>method <span class="token operator">===</span> <span class="token string">'POST'</span><br />  <span class="token punctuation">)</span> <span class="token punctuation">{</span><br />    <span class="token keyword">return</span> fetchEvent<span class="token punctuation">.</span><span class="token function">respondWith</span><span class="token punctuation">(</span><br />      <span class="token punctuation">(</span><span class="token keyword">async</span> <span class="token punctuation">(</span><span class="token punctuation">)</span> <span class="token operator">=></span> <span class="token punctuation">{</span><br />        <span class="token keyword">const</span> formData <span class="token operator">=</span> <span class="token keyword">await</span> fetchEvent<span class="token punctuation">.</span>request<span class="token punctuation">.</span><span class="token function">formData</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />        <span class="token keyword">const</span> image <span class="token operator">=</span> formData<span class="token punctuation">.</span><span class="token function">get</span><span class="token punctuation">(</span><span class="token string">'image'</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />        <span class="token keyword">const</span> keys <span class="token operator">=</span> <span class="token keyword">await</span> caches<span class="token punctuation">.</span><span class="token function">keys</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />        <span class="token keyword">const</span> mediaCache <span class="token operator">=</span> <span class="token keyword">await</span> caches<span class="token punctuation">.</span><span class="token function">open</span><span class="token punctuation">(</span><br />          keys<span class="token punctuation">.</span><span class="token function">filter</span><span class="token punctuation">(</span><span class="token punctuation">(</span><span class="token parameter">key</span><span class="token punctuation">)</span> <span class="token operator">=></span> key<span class="token punctuation">.</span><span class="token function">startsWith</span><span class="token punctuation">(</span><span class="token string">'media'</span><span class="token punctuation">)</span><span class="token punctuation">)</span><span class="token punctuation">[</span><span class="token number">0</span><span class="token punctuation">]</span><span class="token punctuation">,</span><br />        <span class="token punctuation">)</span><span class="token punctuation">;</span><br />        <span class="token keyword">await</span> mediaCache<span class="token punctuation">.</span><span class="token function">put</span><span class="token punctuation">(</span><span class="token string">'shared-image'</span><span class="token punctuation">,</span> <span class="token keyword">new</span> <span class="token class-name">Response</span><span class="token punctuation">(</span>image<span class="token punctuation">)</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />        <span class="token keyword">return</span> Response<span class="token punctuation">.</span><span class="token function">redirect</span><span class="token punctuation">(</span><span class="token string">'./?share-target'</span><span class="token punctuation">,</span> <span class="token number">303</span><span class="token punctuation">)</span><span class="token punctuation">;</span><br />      <span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">(</span><span class="token punctuation">)</span><span class="token punctuation">,</span><br />    <span class="token punctuation">)</span><span class="token punctuation">;</span><br />  <span class="token punctuation">}</span><br /><span class="token punctuation">}</span><span class="token punctuation">)</span><span class="token punctuation">;</span></code></pre>
</div><figure>
  <video autoplay="" loop="" muted="" playsinline="">      <source src="https://storage.googleapis.com/web-dev-uploads/video/8WbTDNrhLsU0El80frMBGE4eMCD3/SVtll3ShgNigvkVLu7cn.mp4" type="video/mp4" />    </video>
  <figcaption>
    Sharing a screenshot to SVGcode.
  </figcaption>
</figure>
<h2 id="conclusion">Conclusion <a class="w-headline-link" href="https://web.dev/svgcode/#conclusion">#</a></h2>
<p>Alright, this was a quick tour through some of the advanced app features in SVGcode. I hope this app
can become an essential tool for your image processing needs alongside other amazing apps like
<a href="https://squoosh.app/" rel="noopener">Squoosh</a> or <a href="https://jakearchibald.github.io/svgomg/" rel="noopener">SVGOMG</a>.</p>
<p>SVGcode is available at <a href="https://svgco.de/" rel="noopener">svgco.de</a>. See what I did there? You can
<a href="https://github.com/tomayac/SVGcode" rel="noopener">review its source code on GitHub</a>. Note that since Potrace is
GPL-licensed, so is SVGcode. And with that, happy vectorizing! I hope SVGcode will be useful, and
some of its features can inspire your next app.</p>
<h2 id="acknowledgements">Acknowledgements <a class="w-headline-link" href="https://web.dev/svgcode/#acknowledgements">#</a></h2>
<p>This article was reviewed by <a href="https://github.com/jpmedley" rel="noopener">Joe Medley</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Is WebAssembly Really Safe? -- Wasm VM Escape and RCE Vulnerabilities Have Been Found in New Way]]></title>
<description><![CDATA[$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('QWsSNRQN7v8');
									});]]></description>
<link>https://tsecurity.de/de/1710877/it-security-video/is-webassembly-really-safe-wasm-vm-escape-and-rce-vulnerabilities-have-been-found-in-new-way/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1710877/it-security-video/is-webassembly-really-safe-wasm-vm-escape-and-rce-vulnerabilities-have-been-found-in-new-way/</guid>
<pubDate>Mon, 28 Nov 2022 20:03:54 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/QWsSNRQN7v8/hqdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<div id="ytplayer_QWsSNRQN7v8"></div>

					<script>
									$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('QWsSNRQN7v8');
									}); 
									</script>]]></content:encoded>
</item>
<item>
<title><![CDATA[Datenbank SQLite 3.40 läuft mit WebAssembly im Browser]]></title>
<description><![CDATA[Neben einer WASM-Variante bietet die schlanke Datenbank im aktuellen Release eine Erweiterung zum Reparieren defekter Datenbankdateien.]]></description>
<link>https://tsecurity.de/de/1698587/it-nachrichten/datenbank-sqlite-340-laeuft-mit-webassembly-im-browser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1698587/it-nachrichten/datenbank-sqlite-340-laeuft-mit-webassembly-im-browser/</guid>
<pubDate>Thu, 17 Nov 2022 17:04:19 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Neben einer WASM-Variante bietet die schlanke Datenbank im aktuellen Release eine Erweiterung zum Reparieren defekter Datenbankdateien.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-39392]]></title>
<description><![CDATA[Wasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator when the allocator is configured to give WebAssembly instances a maximum of zero pages of memory. In this configuration, the virtual memory mappi...]]></description>
<link>https://tsecurity.de/de/1693526/sicherheitsluecken/cve-2022-39392/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1693526/sicherheitsluecken/cve-2022-39392/</guid>
<pubDate>Sun, 13 Nov 2022 06:34:30 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator when the allocator is configured to give WebAssembly instances a maximum of zero pages of memory. In this configuration, the virtual memory mapping for WebAssembly memories did not meet the compiler-required configuration requirements for safely executing WebAssembly modules. Wasmtime's default settings require virtual memory page faults to indicate that wasm reads/writes are out-of-bounds, but the pooling allocator's configuration would not create an appropriate virtual memory mapping for this meaning out of bounds reads/writes can successfully read/write memory unrelated to the wasm sandbox within range of the base address of the memory mapping created by the pooling allocator. This bug is not applicable with the default settings of the `wasmtime` crate. This bug can only be triggered by setting `InstanceLimits::memory_pages` to zero. This is expected to be a very rare configuration since this means that wasm modules cannot allocate any pages of linear memory. All wasm modules produced by all current toolchains are highly likely to use linear memory, so it's expected to be unlikely that this configuration is set to zero by any production embedding of Wasmtime. This bug has been patched and users should upgrade to Wasmtime 2.0.2. This bug can be worked around by increasing the `memory_pages` allotment when configuring the pooling allocator to a value greater than zero. If an embedding wishes to still prevent memory from actually being used then the `Store::limiter` method can be used to dynamically disallow growth of memory beyond 0 bytes large. Note that the default `memory_pages` value is greater than zero.]]></content:encoded>
</item>
<item>
<title><![CDATA[Technische Vorschau von Docker+Wasm ist verfügbar]]></title>
<description><![CDATA[Die technische Vorschau von Docker+Wasm ist verfügbar. Die neue Version soll es Entwicklern erleichtern, Anwendungen zu erstellen, die auf Wasm-Runtimes abzielen.]]></description>
<link>https://tsecurity.de/de/1682799/android-tipps/technische-vorschau-von-docker-wasm-ist-verfuegbar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1682799/android-tipps/technische-vorschau-von-docker-wasm-ist-verfuegbar/</guid>
<pubDate>Wed, 02 Nov 2022 17:00:11 +0100</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die technische Vorschau von Docker+Wasm ist verfügbar. Die neue Version soll es Entwicklern erleichtern, Anwendungen zu erstellen, die auf Wasm-Runtimes abzielen.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-43280]]></title>
<description><![CDATA[wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.]]></description>
<link>https://tsecurity.de/de/1678819/sicherheitsluecken/cve-2022-43280/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1678819/sicherheitsluecken/cve-2022-43280/</guid>
<pubDate>Sat, 29 Oct 2022 01:19:36 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr-&gt;GetReturnCallDropKeepCount.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-43281]]></title>
<description><![CDATA[wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector::size() at /bits/stl_vector.h.]]></description>
<link>https://tsecurity.de/de/1678820/sicherheitsluecken/cve-2022-43281/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1678820/sicherheitsluecken/cve-2022-43281/</guid>
<pubDate>Sat, 29 Oct 2022 01:19:36 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector&lt;wabt::Type, std::allocator&lt;wabt::Type&gt;&gt;::size() at /bits/stl_vector.h.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-43282]]></title>
<description><![CDATA[wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount.]]></description>
<link>https://tsecurity.de/de/1678821/sicherheitsluecken/cve-2022-43282/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1678821/sicherheitsluecken/cve-2022-43282/</guid>
<pubDate>Sat, 29 Oct 2022 01:19:36 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr-&gt;GetReturnCallDropKeepCount.]]></content:encoded>
</item>
<item>
<title><![CDATA[KubeCon 2022: Cloud-Native Zertifizierungen und Wasm rücken in den Fokus]]></title>
<description><![CDATA[Die CNCF öffnete ihre nordamerikanische Hausmesse wieder für Publikum vor Ort. Neben Fortschritten bei CNCF-Initiativen spielt WebAssembly eine größere Rolle.]]></description>
<link>https://tsecurity.de/de/1677035/it-nachrichten/kubecon-2022-cloud-native-zertifizierungen-und-wasm-ruecken-in-den-fokus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1677035/it-nachrichten/kubecon-2022-cloud-native-zertifizierungen-und-wasm-ruecken-in-den-fokus/</guid>
<pubDate>Thu, 27 Oct 2022 12:05:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die CNCF öffnete ihre nordamerikanische Hausmesse wieder für Publikum vor Ort. Neben Fortschritten bei CNCF-Initiativen spielt WebAssembly eine größere Rolle.]]></content:encoded>
</item>
<item>
<title><![CDATA[Docker will das Entwickeln von Wasm-Anwendungen vereinfachen]]></title>
<description><![CDATA[Als komplementäre Technologie zu Linux-Containern integriert Docker WebAssembly in sein Desktop-Werkzeug – zunächst als Technical Preview.]]></description>
<link>https://tsecurity.de/de/1675843/it-nachrichten/docker-will-das-entwickeln-von-wasm-anwendungen-vereinfachen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1675843/it-nachrichten/docker-will-das-entwickeln-von-wasm-anwendungen-vereinfachen/</guid>
<pubDate>Wed, 26 Oct 2022 11:19:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Als komplementäre Technologie zu Linux-Containern integriert Docker WebAssembly in sein Desktop-Werkzeug – zunächst als Technical Preview.]]></content:encoded>
</item>
<item>
<title><![CDATA[New Version of Windows 95 JavaScript App Runs On Basically Any Platform]]></title>
<description><![CDATA[An anonymous reader quotes a report from BetaNews: Slack developer Felix Rieseberg released Windows 95 as an Electron app four years ago, updating it shortly afterwards to allow it to run gaming classics like Doom. Now he rolls out a new version which can run on any Windows, Mac or Linux system. ...]]></description>
<link>https://tsecurity.de/de/1671677/it-security-nachrichten/new-version-of-windows-95-javascript-app-runs-on-basically-any-platform/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1671677/it-security-nachrichten/new-version-of-windows-95-javascript-app-runs-on-basically-any-platform/</guid>
<pubDate>Sat, 22 Oct 2022 06:03:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from BetaNews: Slack developer Felix Rieseberg released Windows 95 as an Electron app four years ago, updating it shortly afterwards to allow it to run gaming classics like Doom. Now he rolls out a new version which can run on any Windows, Mac or Linux system. Based on the Electron framework, Rieseberg's Windows 95 is written entirely in JavaScript, so it doesn't run as smoothly as it would if it was a native app, but you shouldn't let that put you off.
 
This is the second update of the year, which brings it up to version 3.1.1 and includes two important changes: 
- Upgraded from Electron v18 to Electron v21 (and with it, Chrome and Node.js) - Upgraded v86 (sound is back!)
 
The earlier update (in June) brought the software up to 3.0.0 and introduced the following changes:
 - Upgraded from Electron v11 Electron v18 (and with it, Chrome and Node.js) - Upgraded v86 (now using WASM) - Upgraded various smaller dependencies - Much better scaling on all platforms - On Windows, the link to OSFMount was broken and is now fixed. - On Windows, you can now see a prettier installation animation. - On Windows, windows95 will have a proper icon in the Programs &amp; Features menu. You can download the latest version of the Windows 95 app for Windows, macOS, and Linux at their respective links.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=New+Version+of+Windows+95+JavaScript+App+Runs+On+Basically+Any+Platform%3A+https%3A%2F%2Fbit.ly%2F3TJHjA0"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Ftech.slashdot.org%2Fstory%2F22%2F10%2F21%2F229219%2Fnew-version-of-windows-95-javascript-app-runs-on-basically-any-platform%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://tech.slashdot.org/story/22/10/21/229219/new-version-of-windows-95-javascript-app-runs-on-basically-any-platform?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-31740 | Mozilla Thunderbird up to 91.9 on ARM64 WASM allocation of resources (Bug 1766806)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in  Mozilla Thunderbird up to 91.9. Affected is an unknown function of the component WASM. The manipulation leads to allocation of resources.

This vulnerability is traded as CVE-2022-31740. It is possible to launch the attack remote...]]></description>
<link>https://tsecurity.de/de/1647652/sicherheitsluecken/cve-2022-31740-mozilla-thunderbird-up-to-919-on-arm64-wasm-allocation-of-resources-bug-1766806/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1647652/sicherheitsluecken/cve-2022-31740-mozilla-thunderbird-up-to-919-on-arm64-wasm-allocation-of-resources-bug-1766806/</guid>
<pubDate>Fri, 30 Sep 2022 12:05:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as problematic, was found in  Mozilla Thunderbird up to 91.9. Affected is an unknown function of the component <em>WASM</em>. The manipulation leads to allocation of resources.

This vulnerability is traded as <a href="https://vuldb.com/?source_cve.209964">CVE-2022-31740</a>. It is possible to launch the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-31740 | Mozilla Firefox up to 100 on ARM64 WASM allocation of resources (Bug 1766806)]]></title>
<description><![CDATA[A vulnerability was found in  Mozilla Firefox up to 100. It has been rated as problematic. This issue affects some unknown processing of the component WASM Handler. The manipulation leads to allocation of resources.

The identification of this vulnerability is CVE-2022-31740. The attack may be in...]]></description>
<link>https://tsecurity.de/de/1647486/sicherheitsluecken/cve-2022-31740-mozilla-firefox-up-to-100-on-arm64-wasm-allocation-of-resources-bug-1766806/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1647486/sicherheitsluecken/cve-2022-31740-mozilla-firefox-up-to-100-on-arm64-wasm-allocation-of-resources-bug-1766806/</guid>
<pubDate>Fri, 30 Sep 2022 10:50:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in  Mozilla Firefox up to 100. It has been rated as problematic. This issue affects some unknown processing of the component <em>WASM Handler</em>. The manipulation leads to allocation of resources.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.209951">CVE-2022-31740</a>. The attack may be initiated remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2022-09-26 - Firefox, 0 AD a26, Gradience, Linux Firmware, Wine Staging]]></title>
<description><![CDATA[Hello community,
Another testing branch update with some usual package updates for you.
Don’t miss out on 20% discount this weekend on all of our Merch! manjaro.myspreadshop.net

Firefox is now at 105.0.1


0 AD got its 26th Alpha released
We added gradience to change the look of Adwaita, with ea...]]></description>
<link>https://tsecurity.de/de/1642378/unix-server/testing-update-2022-09-26-firefox-0-ad-a26-gradience-linux-firmware-wine-staging/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1642378/unix-server/testing-update-2022-09-26-firefox-0-ad-a26-gradience-linux-firmware-wine-staging/</guid>
<pubDate>Mon, 26 Sep 2022 10:05:03 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello community,</p>
<p>Another <strong>testing</strong> branch update with some usual package updates for you.</p>
<p><img src="https://forum.manjaro.org/uploads/default/original/3X/4/7/47d9b81abe409180df1e4085a852a6e8a2dd2045.jpeg" alt="image" data-base62-sha1="afCmpMIeKecNh8ZvOjArh5vpZ09" width="680" height="383"><br><strong>Don’t miss out on 20% discount this weekend on all of our Merch! <a href="https://t.co/5feWQXkPGQ">manjaro.myspreadshop.net</a></strong></p>
<ul><li>
<strong>Firefox</strong> is now at <a href="https://www.mozilla.org/en-US/firefox/105.0.1/releasenotes/">105.0.1</a>
</li>
<li>
<strong>0 AD</strong> got its <a href="https://play0ad.com/new-release-0-a-d-alpha-26-zhuangzi/">26th Alpha</a> released</li>
<li>We added <a href="https://github.com/GradienceTeam/Gradience/blob/main/README.md">gradience</a> to change the look of Adwaita, with ease</li>
<li>monthly <strong>Linux Firmware</strong> update got added</li>
<li>
<strong>Wine Staging</strong> is now also at <a href="https://www.winehq.org/mailman3/hyperkitty/list/wine-devel@winehq.org/thread/3Z5ZTUBPNWIRQHS7XW4DRJWIX5I6KI3N/">7.18</a>
</li>
<li>Some <strong>KDE-git</strong> updates as usual</li>
</ul><h2>
<a name="additional-info-1" class="anchor" href="https://forum.manjaro.org/#additional-info-1"></a>Additional Info</h2>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2022-09-26-firefox-0-ad-a26-gradience-linux-firmware-wine-staging/122694/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr><p><strong>Our current supported kernels</strong></p>
<ul><li>linux419 4.19.259</li>
<li>linux54 5.4.214</li>
<li>linux510 5.10.145</li>
<li>linux515 5.15.70</li>
<li>linux518 5.18.19 [EOL]</li>
<li>linux519 5.19.11</li>
<li>linux60 6.0.0rc6</li>
<li>linux515-rt 5.15.55_rt48</li>
<li>linux519-rt 5.19.0_rt10</li>
</ul><p><strong>Package changes</strong> (Mon Sep 26 08:39:51 CEST 2022)</p>
<ul><li>testing community x86_64:  220 new and 214 removed package(s)</li>
<li>testing core x86_64:  13 new and 13 removed package(s)</li>
<li>testing extra x86_64:  141 new and 141 removed package(s)</li>
<li>testing kde-unstable x86_64:  108 new and 108 removed package(s)</li>
<li>testing multilib x86_64:  3 new and 3 removed package(s)</li>
</ul><pre><code class="lang-auto">

-------------------------------------------------------------------------------
                             PACKAGE           2022-09-24           2022-09-25
-------------------------------------------------------------------------------
  gnome-shell-extension-dash-to-dock                 73-1                 74-1
 gnome-shell-extension-gnome-ui-tune              1.6.3-1              1.7.1-1
                           gradience                    -              0.3.0-2
                     python-anyascii                    -              0.3.1-2
                     python-cssutils                    -              2.6.0-1
     python-material-color-utilities                    -              0.1.5-2


:: Different sync package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-09-24           2022-09-25
-------------------------------------------------------------------------------
                                 0ad             a25.b-10                a26-1
                            0ad-data              a25.b-1                a26-1
                       android-tools             31.0.3-7             33.0.3-1
                        android-udev           20220611-1           20220903-1
                             arch-hs          0.10.2.0-59          0.10.2.0-60
                               atril             1.26.0-1             1.26.0-2
                             aws-cli            1.25.71-1            1.25.81-1
                               broot             1.14.3-1             1.15.0-1
                      cargo-binstall             0.13.1-1             0.13.3-1
                          cargo-edit             0.11.1-1             0.11.2-1
                           clash-ghc             1.6.3-31              1.6.4-1
                     consul-template             0.29.1-1             0.29.2-1
                                  ct              0.9.3-1              0.9.4-1
                           dart-sass             1.54.9-1             1.55.0-1
                          dhall-bash           1.0.40-102           1.0.40-103
                                 din                 54-1                 55-1
                               drone             2.12.1-1             2.13.0-1
                           drone-oss             2.12.1-1             2.13.0-1
           firefox-developer-edition            106.0b3-1            106.0b4-1
  firefox-developer-edition-i18n-ach            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-af            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-an            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-ar            106.0b3-1            106.0b4-1
  firefox-developer-edition-i18n-ast            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-az            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-be            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-bg            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-bn            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-br            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-bs            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-ca            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-ca-valencia      106.0b3-1            106.0b4-1
  firefox-developer-edition-i18n-cak            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-cs            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-cy            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-da            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-de            106.0b3-1            106.0b4-1
  firefox-developer-edition-i18n-dsb            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-el            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-en-ca            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-en-gb            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-en-us            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-eo            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-es-ar            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-es-cl            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-es-es            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-es-mx            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-et            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-eu            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-fa            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-ff            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-fi            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-fr            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-fy-nl            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-ga-ie            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-gd            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-gl            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-gn            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-gu-in            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-he            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-hi-in            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-hr            106.0b3-1            106.0b4-1
  firefox-developer-edition-i18n-hsb            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-hu            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-hy-am            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-ia            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-id            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-is            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-it            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-ja            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-ka            106.0b3-1            106.0b4-1
  firefox-developer-edition-i18n-kab            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-kk            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-km            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-kn            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-ko            106.0b3-1            106.0b4-1
  firefox-developer-edition-i18n-lij            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-lt            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-lv            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-mk            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-mr            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-ms            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-my            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-nb-no            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-ne-np            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-nl            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-nn-no            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-oc            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-pa-in            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-pl            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-pt-br            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-pt-pt            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-rm            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-ro            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-ru            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-si            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-sk            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-sl            106.0b3-1            106.0b4-1
  firefox-developer-edition-i18n-son            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-sq            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-sr            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-sv-se            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-ta            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-te            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-th            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-tl            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-tr            106.0b3-1            106.0b4-1
  firefox-developer-edition-i18n-trs            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-uk            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-ur            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-uz            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-vi            106.0b3-1            106.0b4-1
   firefox-developer-edition-i18n-xh            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-zh-cn            106.0b3-1            106.0b4-1
firefox-developer-edition-i18n-zh-tw            106.0b3-1            106.0b4-1
                           git-cliff              0.9.1-1              0.9.2-1
                          github-cli             2.15.0-1             2.16.0-1
                     gloobus-preview          0.4.5.336-3          0.4.5.336-4
                              gopass             1.14.6-1             1.14.7-1
                      grafana-zabbix              4.2.9-1             4.2.10-1
                             haproxy              2.6.5-2              2.6.6-1
               haskell-binary-parser           0.5.7.2-38           0.5.7.2-39
                     haskell-butcher          1.3.3.2-243          1.3.3.2-244
   haskell-bytestring-strict-builder           0.4.5.6-24           0.4.5.6-25
                   haskell-clash-lib             1.6.3-31              1.6.4-1
               haskell-clash-prelude             1.6.3-29              1.6.4-1
              haskell-deferred-folds          0.9.18.2-27          0.9.18.2-28
                       haskell-deque            0.4.4-106            0.4.4-107
                       haskell-hasql           1.5.0.3-29           1.5.0.3-30
    haskell-hasql-dynamic-statements            0.3.1-176            0.3.1-177
             haskell-hasql-implicits           0.1.0.5-14           0.1.0.5-15
         haskell-hasql-notifications           0.2.0.2-10           0.2.0.2-11
                  haskell-hasql-pool           0.5.2.2-96           0.5.2.2-97
           haskell-hasql-transaction          1.0.1.1-115          1.0.1.1-116
           haskell-isomorphism-class            0.1.0.7-2            0.1.0.7-3
          haskell-neat-interpolation           0.5.1.3-86           0.5.1.3-87
           haskell-postgresql-binary         0.12.4.1-143         0.12.4.1-144
                         haskell-ptr          0.16.8.3-19          0.16.8.3-20
                      haskell-rebase           1.16.0.1-2             1.16.1-1
                    haskell-rerebase           1.16.0.1-2             1.16.1-1
                 haskell-strict-list             0.1.7-45             0.1.7-46
                    haskell-summoner          2.0.1.1-361          2.0.1.1-362
                haskell-summoner-tui          2.0.1.1-409          2.0.1.1-410
                haskell-text-builder             0.6.7-20             0.6.7-21
            haskell-text-builder-dev             0.3.3-11             0.3.3-12
              haskell-vector-builder           0.3.8.4-29           0.3.8.4-30
                               i3-wm               4.21-1               4.21-2
                                 k9s             0.26.3-1             0.26.5-1
                           kdiskmark              2.3.0-2              3.1.2-1
                      knative-client              1.4.0-1              1.7.0-1
                         kubeconform             0.4.13-2             0.4.14-2
                            kubeseal             0.18.1-1             0.18.5-1
                       libtraceevent            1:1.6.2-1            1:1.6.3-1
                  libtraceevent-docs            1:1.6.2-1            1:1.6.3-1
                          libtracefs              1.4.2-1              1.5.0-1
                     libtracefs-docs              1.4.2-1              1.5.0-1
                                 lxd                5.5-2                5.6-1
                              marked             4.0.17-1             4.0.19-1
                               mimir              2.2.0-1              2.3.0-1
                            minikube             1.26.1-1             1.27.0-1
               netfilter-fullconenat      r73.0cf3b48-238      r73.0cf3b48-239
                            newsboat               2.28-1               2.29-1
             nextcloud-app-bookmarks           1:11.0.1-1           1:11.0.3-1
              nextcloud-app-contacts              4.2.0-1              4.2.1-1
                   npm-check-updates             16.3.1-1             16.3.2-1
                                nrpe              4.0.3-3              4.1.0-1
                                 oil             0.12.5-1             0.12.6-1
                   openapi-generator              6.1.0-1              6.2.0-1
                         pdfarranger              1.9.0-2              1.9.1-1
                      perl-path-tiny              0.122-2              0.124-1
                            plantuml           1.2022.6-1           1.2022.7-1
                           postgrest             9.0.1-51             9.0.1-52
                              pulumi             3.39.3-1             3.40.1-1
               python-ansible-compat              2.2.0-1              2.2.1-1
                      python-bincopy            17.10.3-1            17.14.0-1
                        python-boto3            1.24.70-1            1.24.80-1
                     python-botocore            1.27.70-1            1.27.80-1
                      python-certifi         2022.09.14-1         2022.09.24-1
                   python-diff-cover              6.5.1-1              7.0.1-1
                       python-dnslib             0.9.20-1             0.9.21-1
                    python-executing              1.0.0-1              1.1.0-1
                        python-faker              9.3.1-1              9.4.0-1
               python-fastjsonschema             2.16.1-1             2.16.2-1
                      python-libtmux             0.15.3-1             0.15.4-1
                 python-phonenumbers            8.12.55-1            8.12.56-1
                      python-psycopg              3.1.1-1              3.1.2-1
       python-pytest-shell-utilities              1.6.0-1              1.7.0-1
                     python-redbaron              0.9.2-6              0.9.2-7
          python-setuptools-markdown              0.4.1-7              0.4.1-8
                       python-sphinx              5.1.1-2              5.2.1-1
                        python-spsdk              1.7.0-1              1.7.1-1
                       python-stestr              4.0.0-1              4.0.1-1
                     python-watchdog              2.0.0-1              2.0.1-1
                               rekor             0.12.0-1             0.12.1-1
                             rocksdb              7.5.3-1              7.6.0-1
                               rtirq           20210329-1           20220923-1
                                salt             3004.2-1               3005-1
                             shotcut           22.06.23-1           22.09.23-1
                         spire-agent              1.4.0-1              1.4.2-1
                        spire-server              1.4.0-1              1.4.2-1
                               stack            2.7.5-163            2.7.5-164
                           terraform              1.2.9-1              1.3.0-1
                          terragrunt             0.38.9-1            0.38.12-1
                               tmuxp             1.14.0-1             1.15.2-1
                             traefik              2.8.4-1              2.8.7-1
                             unbound             1.16.2-1             1.16.3-1
         v2ray-domain-list-community     20220923145559-1     20220924145006-1
                               wails              2.0.0-1              2.0.0-2
                         x42-plugins           20220914-1           20220923-1
                             xfsdump             3.1.10-2             3.1.11-1
                             xreader              3.4.5-1              3.4.5-2
                         xsecurelock              1.7.0-2              1.8.0-1
                  mod-lv2-extensions                    -         2022.09.25-1
                 python-pytoolconfig                    -              1.2.2-3


:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-09-24           2022-09-25
-------------------------------------------------------------------------------
                           amd-ucode   20220815.8413c63-1   20220913.f09bebf-1
                      linux-firmware   20220815.8413c63-1   20220913.f09bebf-1
                linux-firmware-bnx2x   20220815.8413c63-1   20220913.f09bebf-1
             linux-firmware-liquidio   20220815.8413c63-1   20220913.f09bebf-1
              linux-firmware-marvell   20220815.8413c63-1   20220913.f09bebf-1
             linux-firmware-mellanox   20220815.8413c63-1   20220913.f09bebf-1
                  linux-firmware-nfp   20220815.8413c63-1   20220913.f09bebf-1
                 linux-firmware-qcom   20220815.8413c63-1   20220913.f09bebf-1
               linux-firmware-qlogic   20220815.8413c63-1   20220913.f09bebf-1
               linux-firmware-whence   20220815.8413c63-1   20220913.f09bebf-1
                              pacman             6.0.1-14             6.0.1-15


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-09-24           2022-09-25
-------------------------------------------------------------------------------
                          libnghttp2             1.49.0-1             1.50.0-1
                              tzdata              2022c-1              2022d-1


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-09-24           2022-09-25
-------------------------------------------------------------------------------
                                 aom              3.4.0-1              3.5.0-1
                            aom-docs              3.4.0-1              3.5.0-1
                              evince               42.3-1               42.3-2
                     evince-lib-docs               42.3-1               42.3-2
                           evolution             3.44.4-1             3.44.4-2
                evolution-bogofilter             3.44.4-1             3.44.4-2
              evolution-spamassassin             3.44.4-1             3.44.4-2
                             firefox              105.0-2            105.0.1-1
                    firefox-i18n-ach              105.0-1            105.0.1-1
                     firefox-i18n-af              105.0-1            105.0.1-1
                     firefox-i18n-an              105.0-1            105.0.1-1
                     firefox-i18n-ar              105.0-1            105.0.1-1
                    firefox-i18n-ast              105.0-1            105.0.1-1
                     firefox-i18n-az              105.0-1            105.0.1-1
                     firefox-i18n-be              105.0-1            105.0.1-1
                     firefox-i18n-bg              105.0-1            105.0.1-1
                     firefox-i18n-bn              105.0-1            105.0.1-1
                     firefox-i18n-br              105.0-1            105.0.1-1
                     firefox-i18n-bs              105.0-1            105.0.1-1
                     firefox-i18n-ca              105.0-1            105.0.1-1
            firefox-i18n-ca-valencia              105.0-1            105.0.1-1
                    firefox-i18n-cak              105.0-1            105.0.1-1
                     firefox-i18n-cs              105.0-1            105.0.1-1
                     firefox-i18n-cy              105.0-1            105.0.1-1
                     firefox-i18n-da              105.0-1            105.0.1-1
                     firefox-i18n-de              105.0-1            105.0.1-1
                    firefox-i18n-dsb              105.0-1            105.0.1-1
                     firefox-i18n-el              105.0-1            105.0.1-1
                  firefox-i18n-en-ca              105.0-1            105.0.1-1
                  firefox-i18n-en-gb              105.0-1            105.0.1-1
                  firefox-i18n-en-us              105.0-1            105.0.1-1
                     firefox-i18n-eo              105.0-1            105.0.1-1
                  firefox-i18n-es-ar              105.0-1            105.0.1-1
                  firefox-i18n-es-cl              105.0-1            105.0.1-1
                  firefox-i18n-es-es              105.0-1            105.0.1-1
                  firefox-i18n-es-mx              105.0-1            105.0.1-1
                     firefox-i18n-et              105.0-1            105.0.1-1
                     firefox-i18n-eu              105.0-1            105.0.1-1
                     firefox-i18n-fa              105.0-1            105.0.1-1
                     firefox-i18n-ff              105.0-1            105.0.1-1
                     firefox-i18n-fi              105.0-1            105.0.1-1
                     firefox-i18n-fr              105.0-1            105.0.1-1
                  firefox-i18n-fy-nl              105.0-1            105.0.1-1
                  firefox-i18n-ga-ie              105.0-1            105.0.1-1
                     firefox-i18n-gd              105.0-1            105.0.1-1
                     firefox-i18n-gl              105.0-1            105.0.1-1
                     firefox-i18n-gn              105.0-1            105.0.1-1
                  firefox-i18n-gu-in              105.0-1            105.0.1-1
                     firefox-i18n-he              105.0-1            105.0.1-1
                  firefox-i18n-hi-in              105.0-1            105.0.1-1
                     firefox-i18n-hr              105.0-1            105.0.1-1
                    firefox-i18n-hsb              105.0-1            105.0.1-1
                     firefox-i18n-hu              105.0-1            105.0.1-1
                  firefox-i18n-hy-am              105.0-1            105.0.1-1
                     firefox-i18n-ia              105.0-1            105.0.1-1
                     firefox-i18n-id              105.0-1            105.0.1-1
                     firefox-i18n-is              105.0-1            105.0.1-1
                     firefox-i18n-it              105.0-1            105.0.1-1
                     firefox-i18n-ja              105.0-1            105.0.1-1
                     firefox-i18n-ka              105.0-1            105.0.1-1
                    firefox-i18n-kab              105.0-1            105.0.1-1
                     firefox-i18n-kk              105.0-1            105.0.1-1
                     firefox-i18n-km              105.0-1            105.0.1-1
                     firefox-i18n-kn              105.0-1            105.0.1-1
                     firefox-i18n-ko              105.0-1            105.0.1-1
                    firefox-i18n-lij              105.0-1            105.0.1-1
                     firefox-i18n-lt              105.0-1            105.0.1-1
                     firefox-i18n-lv              105.0-1            105.0.1-1
                     firefox-i18n-mk              105.0-1            105.0.1-1
                     firefox-i18n-mr              105.0-1            105.0.1-1
                     firefox-i18n-ms              105.0-1            105.0.1-1
                     firefox-i18n-my              105.0-1            105.0.1-1
                  firefox-i18n-nb-no              105.0-1            105.0.1-1
                  firefox-i18n-ne-np              105.0-1            105.0.1-1
                     firefox-i18n-nl              105.0-1            105.0.1-1
                  firefox-i18n-nn-no              105.0-1            105.0.1-1
                     firefox-i18n-oc              105.0-1            105.0.1-1
                  firefox-i18n-pa-in              105.0-1            105.0.1-1
                     firefox-i18n-pl              105.0-1            105.0.1-1
                  firefox-i18n-pt-br              105.0-1            105.0.1-1
                  firefox-i18n-pt-pt              105.0-1            105.0.1-1
                     firefox-i18n-rm              105.0-1            105.0.1-1
                     firefox-i18n-ro              105.0-1            105.0.1-1
                     firefox-i18n-ru              105.0-1            105.0.1-1
                    firefox-i18n-sco              105.0-1            105.0.1-1
                     firefox-i18n-si              105.0-1            105.0.1-1
                     firefox-i18n-sk              105.0-1            105.0.1-1
                     firefox-i18n-sl              105.0-1            105.0.1-1
                    firefox-i18n-son              105.0-1            105.0.1-1
                     firefox-i18n-sq              105.0-1            105.0.1-1
                     firefox-i18n-sr              105.0-1            105.0.1-1
                  firefox-i18n-sv-se              105.0-1            105.0.1-1
                    firefox-i18n-szl              105.0-1            105.0.1-1
                     firefox-i18n-ta              105.0-1            105.0.1-1
                     firefox-i18n-te              105.0-1            105.0.1-1
                     firefox-i18n-th              105.0-1            105.0.1-1
                     firefox-i18n-tl              105.0-1            105.0.1-1
                     firefox-i18n-tr              105.0-1            105.0.1-1
                    firefox-i18n-trs              105.0-1            105.0.1-1
                     firefox-i18n-uk              105.0-1            105.0.1-1
                     firefox-i18n-ur              105.0-1            105.0.1-1
                     firefox-i18n-uz              105.0-1            105.0.1-1
                     firefox-i18n-vi              105.0-1            105.0.1-1
                     firefox-i18n-xh              105.0-1            105.0.1-1
                  firefox-i18n-zh-cn              105.0-1            105.0.1-1
                  firefox-i18n-zh-tw              105.0-1            105.0.1-1
                            ghostpcl             9.56.1-1             10.0.0-1
                         ghostscript             9.56.1-1             10.0.0-1
                            ghostxps             9.56.1-1             10.0.0-1
                                gimp            2.10.32-1            2.10.32-2
                              glibmm             2.66.4-1             2.66.5-1
                         glibmm-2.68             2.72.1-1             2.74.0-1
                    glibmm-2.68-docs             2.72.1-1             2.74.0-1
                         glibmm-docs             2.66.4-1             2.66.5-1
               gobject-introspection             1.72.0-1             1.74.0-1
       gobject-introspection-runtime             1.72.0-1             1.74.0-1
                            graphviz              5.0.1-1              5.0.1-2
                      gtksourceview5              5.4.2-1              5.6.1-1
                 gtksourceview5-docs              5.4.2-1              5.6.1-1
                         imagemagick           7.1.0.48-2           7.1.0.49-1
                     imagemagick-doc           7.1.0.48-2           7.1.0.49-1
                     lib32-rust-libs           1:1.63.0-1           1:1.64.0-1
                            libfido2             1.11.0-1             1.12.0-1
                              libgee             0.20.5-2             0.20.6-1
                             libgxps              0.3.2-1              0.3.2-2
                          libopenmpt              0.6.5-2              0.6.6-2
                          libspectre             0.2.10-1             0.2.10-2
                            libwnck3               40.1-1               43.0-1
          perl-net-dns-resolver-mock         1.20200215-5         1.20220817-1
                         python-mako              1.2.2-1              1.2.3-1
                                rust           1:1.63.0-1           1:1.64.0-1
                           rust-musl           1:1.63.0-1           1:1.64.0-1
                            rust-src           1:1.63.0-1           1:1.64.0-1
                           rust-wasm           1:1.63.0-1           1:1.64.0-1
                        sof-firmware              2.2.1-1              2.2.2-1
                           sof-tools              2.2.1-1              2.2.2-1
                tracker-miners 1:2.3.5+r3+gd9d61d87f-2 1:2.3.5+r3+gd9d61d87f-3
                            tracker3              3.3.3-1              3.4.0-1
                       tracker3-docs              3.3.3-1              3.4.0-1
                     tracker3-miners              3.3.1-2              3.4.0-2
                       xorg-xkbprint              1.0.5-1              1.0.5-2


:: Different overlay package(s) in repository kde-unstable x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-09-24           2022-09-25
-------------------------------------------------------------------------------
                      akonadiconsole22.08.1.r1621.g627ef5b-122.08.1.r1622.gd61279f-1
                           akregator22.08.1.r6467.g269a82b3-122.08.1.r6469.geb5b0792-1
                           alligator 22.06.r53.g3533c4b-1 22.06.r55.gfd54bbd-1
                           angelfish 22.06.r60.g516a931-1 22.06.r62.gb136825-1
                                 ark22.08.1.r4843.g3e2f5298-122.08.1.r4844.g68e3d95b-1
                         audiocd-kio22.08.1.r1108.gde52745-122.08.1.r1110.g6f34356-1
                        aura-browser        r85.ad7280d-1        r88.87af7f6-1
                             blinken22.08.1.r684.g7ce780d-122.08.1.r685.gf7cdbef-1
                              breeze5.25.5.r2459.g1548737f-15.25.5.r2464.g125e36ff-1
                        breeze-icons5.98.0.r1919.ge88c5b7b-15.98.0.r1920.gcbf7f375-1
                     calendarsupport22.08.1.r729.g3cdcfff-122.08.1.r731.ga65decc-1
                           calindori 22.06.r20.gcc4435e-1 22.06.r21.g5d901d9-1
                             dolphin22.08.1.r7090.g6c65d06bc-122.08.1.r7092.gc9271bf5b-1
                               elisa22.08.1.r3037.g32f5640b-122.08.1.r3038.g0588e7b7-1
                          elisa-qtmm22.08.1.r3037.g32f5640b-122.08.1.r3038.g0588e7b7-1
                          eventviews22.08.1.r878.g3175478-122.08.1.r879.g1d17fab-1
                     incidenceeditor22.08.1.r929.g5936c21-122.08.1.r931.g2358aa2-1
                            index-fm  2.2.0.r3.g08b7662-1  2.2.0.r4.g67e61ac-1
                                 k3b1:22.08.1.r6820.g06791702e-11:22.08.1.r6823.g4e56f8909-1
               kaccounts-integration22.08.1.r1286.ged86f13-122.08.1.r1287.g00e49fc-1
                   kactivities-stats5.98.0.r419.g6d112a4-15.98.0.r420.g4694833-1
                        kaddressbook22.08.1.r6242.g27b84992-122.08.1.r6243.g50ef406e-1
                              kalarm22.08.1.r8004.gd6c9eea4-122.08.1.r8005.gf1b3d8c7-1
                            kalgebra22.08.1.r2080.g4b39929-122.08.1.r2081.ga37dc18-1
                              kapman22.08.1.r669.g6d4383e-122.08.1.r670.g201ccba-1
                                kate22.08.1.r19586.g20c8b60ea-122.08.1.r19593.g6daa2d968-1
                             katomic22.08.1.r976.g51140f8-122.08.1.r977.gd4e0654-1
                               kcalc22.08.1.r1633.g0a89eec-122.08.1.r1635.g55fa699-1
                       kcalendarcore5.98.0.r1347.g3febe4523-15.98.0.r1348.gaf6a43f79-1
                           kcalutils22.08.1.r985.g73a2337f5-122.08.1.r986.g31a671fed-1
                              kclock 22.06.r44.gf9de383-1 22.06.r45.gb44ddba-1
                           kcontacts1:5.98.0.r3349.ga80a7142-11:5.98.0.r3350.g1d757eba-1
                     kde-dev-scripts22.08.1.r4158.gd1575f5-122.08.1.r4160.g17634bd-1
                      kdebugsettings22.08.1.r967.ge3488f0-122.08.1.r968.ged282d1-1
                          kdeconnect22.08.1.r3542.gdbf8b07c-122.08.1.r3543.gae0815ea-1
              kdenetwork-filesharing22.08.1.r985.g34f8836-122.08.1.r986.gd919ec9-1
                       kdepim-addons22.08.1.r4849.g01efbdf34-122.08.1.r4851.g8be4c5d14-1
                      kdepim-runtime22.08.1.r15600.g57a31df55-122.08.1.r15601.g69d9b7267-1
                    kdeplasma-addons5.25.5.r9039.g4353fcb11-15.25.5.r9043.g91c86c213-1
                                 kdf22.08.1.r876.gd8e3425-122.08.1.r877.g5302240-1
                       kfilemetadata5.98.0.r876.gca96468-15.98.0.r878.g076fde9-1
                           kholidays1:5.98.0.r1060.g6f1fe68-11:5.98.0.r1061.g2ddf774-1
                 kidentitymanagement22.08.1.r3903.ga0406ad1-122.08.1.r3905.ga2b6587b-1
                       kimageformats5.98.0.r435.g2f27dff-15.98.0.r436.ga8a477a-1
                         kinfocenter5.25.5.r2158.gb05c2fd6-15.25.5.r2160.ga8b8b300-1
                                 kio5.98.0.r5706.g0b5eb5566-15.98.0.r5708.g2abe1c559-1
                          kio-gdrive22.08.1.r641.g7278f5f-122.08.1.r644.g6c8de22-1
                     kirigami-addons 1:0.3.r16.gbd37cc5-1 1:0.3.r18.gdd44157-1
                           kirigami25.98.0.r3347.gb88f096b-15.98.0.r3350.g80e885e7-1
                          kitinerary22.08.1.r2396.g3410116a-122.08.1.r2398.gb7737678-1
                               kmail22.08.1.r26534.g8582350b7-122.08.1.r26536.g2619a74db-1
                           knewstuff5.98.0.r1388.g35320e38-15.98.0.r1389.gceba876e-1
                              knotes22.08.1.r3696.g84b67a8b-122.08.1.r3697.g75f66b45-1
                      knotifications5.98.0.r759.g6281974-15.98.0.r760.g0450e43-1
                                koko 22.06.r25.g9f352ee-1 22.06.r26.g4ce78c2-1
                            kongress 22.06.r30.g9639f36-1 22.06.r31.g407d497-1
                             konsole22.08.1.r8617.g2b3d46fa-122.08.1.r8618.gf4b6cabf-1
                             kontact22.08.1.r5570.g59802d96-122.08.1.r5571.gd5c7202f-1
                    kontactinterface22.08.1.r708.g18d6cdb-122.08.1.r709.gcbb50d8-1
                              kopete22.08.1.r16451.gf605ed945-122.08.1.r16452.gac28f78d7-1
                          korganizer22.08.1.r11797.g4f7fab3f2-122.08.1.r11799.g2f889ce4c-1
                        kpimtextedit22.08.1.r1624.gf3cdc48-122.08.1.r1626.g4078c88-1
                    kpublictransport22.08.1.r2046.g1bc888f3-122.08.1.r2048.ga806a78c-1
                           krecorder 22.06.r25.gc263a6c-1 22.06.r26.gbc44a47-1
                             krunner5.98.0.r788.g6daf35c-15.98.0.r789.g780337b-1
                             kscreen5.25.5.r1538.g07f2f68-15.25.5.r1539.g1b2d0cc-1
                               ksmtp22.08.1.r460.gf14c06f-122.08.1.r461.ge8b0fc8-1
                            ksquares22.08.1.r574.g7cc207d-122.08.1.r575.g8f62c7e-1
                          ksystemlog22.08.1.r754.gcf2dfea-122.08.1.r755.gabb98ec-1
                         ktexteditor5.98.0.r3545.gfa13320b-15.98.0.r3546.gd1744032-1
                            kweather 22.06.r78.g561d6ec-1 22.06.r80.g365c352-1
                                kwin5.25.5.r23219.g16a5831fe-15.25.5.r23223.g95742bf2e-1
                              kwrite22.08.1.r19586.g20c8b60ea-122.08.1.r19593.g6daa2d968-1
                           libksieve22.08.1.r1741.g02a50cf6-122.08.1.r1743.ge82dad2e-1
                        libksysguard5.25.5.r2434.gc3655d6-15.25.5.r2435.gab3ed19-1
                          mailcommon22.08.1.r1292.gfbf2167-122.08.1.r1293.g77b4c0c-1
                     maliit-keyboard 2.3.1.r0.g9673c8e8-12.3.1.r13.gf11efc9b-1
                        markdownpart22.08.1.r135.g218c38e-122.08.1.r136.g47c7fd1-1
                            maui-pix  2.2.0.r8.g5ef7ce1-1  2.2.0.r9.g7747d4a-1
                             mauikit2.2.0.r14.ge1516871-12.2.0.r15.gc53db67f-1
                          messagelib22.08.1.r6672.ge88ab7359-122.08.1.r6674.g9e64161d7-1
                             neochat22.06.r141.ge28d1918-122.06.r145.g36880d00-1
                            palapeli22.08.1.r1313.g145d8bf-122.08.1.r1314.g5915c28-1
                   pim-data-exporter22.08.1.r2786.g5709df23-122.08.1.r2788.g14a1e296-1
                    pim-sieve-editor22.08.1.r1653.gaf93fbd-122.08.1.r1654.g826da88-1
                        plank-player        r55.9aa61fa-1        r58.462bbe5-1
                    plasma-bigscreen      r513.g885deff-1      r516.g5832ea2-1
                      plasma-desktop5.25.5.r9658.gbd676333c-15.25.5.r9662.g2664a3a94-1
                       plasma-dialer22.06.r119.g3461f97-122.06.r122.g393a28e-1
                    plasma-framework5.98.0.r16427.g3ec8b097c-15.98.0.r16430.g2900b2708-1
                       plasma-mobile5.25.5.r1980.ge11f31f48-15.25.5.r1987.gfd5eb22a0-1
                    plasma-mobile-nm5.25.5.r3336.ge914305c-15.25.5.r3338.ga6133e39-1
                         plasma-nano5.25.5.r196.ge5b051c-15.25.5.r197.geac37be-1
                           plasma-nm5.25.5.r3336.ge914305c-15.25.5.r3338.ga6133e39-1
                           plasma-pa5.25.5.r1090.g0fee41e-15.25.5.r1092.gf2c0944-1
            plasma-remotecontrollers      r133.g4411c9c-1      r134.g95b2ed3-1
                     plasma-settings 22.06.r97.g5afcbb0-1 22.06.r98.g2435afe-1
                plasma-systemmonitor5.25.5.r627.gbfe2062-15.25.5.r629.ge0d0209-1
              plasma-wayland-session5.25.5.r12389.gef57cd3d5-15.25.5.r12397.geb1d7431d-1
                    plasma-workspace5.25.5.r12389.gef57cd3d5-15.25.5.r12397.geb1d7431d-1
                          plasmatube 22.06.r32.g4594844-1 22.06.r33.g39ba9cb-1
                          qmlkonsole 22.06.r43.g6f19359-1 22.06.r45.gf1e4b6c-1
                  qqc2-desktop-style5.98.0.r675.ga03c9b4-15.98.0.r676.g6cc2cf2-1
                            spacebar 22.06.r76.g538438b-1 22.06.r77.g3fb4b99-1
                           spectacle22.08.1.r1388.ge431fdd-122.08.1.r1389.gfbf17f3-1
                      systemsettings5.25.5.r2718.gb3ce91ba-15.25.5.r2719.g68c53794-1
                             tokodon 22.06.r37.g9f22197-1 22.06.r39.gfb56fe5-1
                               vvave  2.2.0.r4.g2686e9c-1  2.2.0.r5.g6f2e7db-1


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-09-24           2022-09-25
-------------------------------------------------------------------------------
                          lib32-gtk2            2.24.33-1            2.24.33-2
                    lib32-libnghttp2             1.49.0-1             1.50.0-1
                        wine-staging               7.17-1               7.18-1


</code></pre>
<p><a href="https://forum.manjaro.org/t/testing-update-2022-09-26-firefox-0-ad-a26-gradience-linux-firmware-wine-staging/122694/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul><li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul><p><small>2 posts - 1 participant</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2022-09-26-firefox-0-ad-a26-gradience-linux-firmware-wine-staging/122694">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome WebGL Uniform Integer Overflows]]></title>
<description><![CDATA[The WebGL implementation for setting uniform values with an ArrayBuffer argument do not properly handle large buffer sizes. As WASM now allows allocating large ArrayBuffers, this can lead to buffer overflows when writing to the GPU command buffer.]]></description>
<link>https://tsecurity.de/de/1591655/it-security-tools/chrome-webgl-uniform-integer-overflows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1591655/it-security-tools/chrome-webgl-uniform-integer-overflows/</guid>
<pubDate>Thu, 04 Aug 2022 17:48:13 +0200</pubDate>
<category>💾 IT Security Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The WebGL implementation for setting uniform values with an ArrayBuffer argument do not properly handle large buffer sizes. As WASM now allows allocating large ArrayBuffers, this can lead to buffer overflows when writing to the GPU command buffer.]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2022-07-27 - Kernels, Cinnamon, AMDVLK, Firefox 103]]></title>
<description><![CDATA[Hello community,
Another testing branch update with some usual updates for you.
Cinnamon 5.4 brings a new version of the Mutter window manager
Some of our Kernels got updated
Some more Cinnamon updates

AMDVLK is now at 2022.Q3.1


Firefox 103 improved performance on high-refresh rate monitors (1...]]></description>
<link>https://tsecurity.de/de/1583521/unix-server/testing-update-2022-07-27-kernels-cinnamon-amdvlk-firefox-103/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1583521/unix-server/testing-update-2022-07-27-kernels-cinnamon-amdvlk-firefox-103/</guid>
<pubDate>Wed, 27 Jul 2022 12:34:37 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello community,</p>
<p>Another <strong>testing</strong> branch update with some usual updates for you.</p>
<p><img src="https://forum.manjaro.org/uploads/default/original/3X/6/6/66363c2b9fb022078fffc2e6c5432a7ce459de36.png" alt="image" data-base62-sha1="eAcTNH2f4i2oTHC0t1mCLhdDUpg" width="300" height="168"><br><em><a href="https://www.makeuseof.com/cinnamon-desktop-5-4-released/">Cinnamon 5.4</a> brings a new version of the Mutter window manager</em></p>
<ul><li>Some of our <strong>Kernels</strong> got updated</li>
<li>Some more <strong>Cinnamon</strong> updates</li>
<li>
<strong>AMDVLK</strong> is now at <a href="https://www.phoronix.com/forums/forum/linux-graphics-x-org-drivers/open-source-amd-linux/1335652-amdvlk-2022-q3-1-released-with-fixes-minor-enhancements/page2#post1335736">2022.Q3.1</a>
</li>
<li>
<strong>Firefox</strong> <a href="https://www.mozilla.org/en-US/firefox/103.0/releasenotes/">103</a> improved performance on high-refresh rate monitors (120Hz+)</li>
<li>Regular <strong>KDE-git</strong>, <strong>Haskell</strong> and <strong>Python</strong> updates</li>
</ul><h2>
<a name="additional-info-1" class="anchor" href="https://forum.manjaro.org/#additional-info-1"></a>Additional Info</h2>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2022-07-27-kernels-cinnamon-amdvlk-firefox-103/117704/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr><p><strong>Our current supported kernels</strong></p>
<ul><li>linux419 4.19.253</li>
<li>linux54 5.4.207</li>
<li>linux510 5.10.133</li>
<li>linux515 5.15.57</li>
<li>linux517 5.17.15 (EOL)</li>
<li>linux518 5.18.14</li>
<li>linux519 5.19-rc7</li>
<li>linux515-rt 5.15.55_rt48</li>
<li>linux518-rt 5.18.0_rt11</li>
</ul><p><strong>Package Changes</strong> (Mon Jul 25 17:06:10 CEST 2022)</p>
<pre><code class="lang-auto">:: Different overlay package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-25           2022-07-27
-------------------------------------------------------------------------------
                   nautilus-terminal            4.0.4-0.1            4.0.6-0.1

:: Different sync package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-25           2022-07-27
-------------------------------------------------------------------------------
                             arch-hs          0.10.2.0-14          0.10.2.0-15
                            audacity            1:2.4.1-9            1:3.1.3-1
                                bear             3.0.19-7             3.0.20-1
                           blueberry              1.4.6-1              1.4.8-1
                      cargo-generate             0.15.2-1             0.16.0-1
                       cargo-nextest             0.9.29-1             0.9.30-1
                      cargo-zigbuild             0.11.2-1             0.11.3-1
                                cgal                5.4-1                5.5-1
                           clash-ghc              1.6.3-2              1.6.3-3
                              conmon            1:2.1.2-1            1:2.1.3-1
                              dagger             0.2.25-1             0.2.26-1
                         debootstrap            1.0.126-1            1.0.127-1
              deepin-desktop-schemas             5.10.2-2             5.10.6-2
                     deepin-launcher             5.5.11-1           5.5.19.1-1
                         easyeffects              6.2.7-1              6.2.8-1
                            electron             19.0.9-1             19.0.9-2
                firefox-adblock-plus               3.13-1             3.14.1-1
           firefox-developer-edition            103.0b9-1            104.0b1-1
  firefox-developer-edition-i18n-ach            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-af            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-an            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-ar            103.0b9-1            104.0b1-1
  firefox-developer-edition-i18n-ast            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-az            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-be            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-bg            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-bn            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-br            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-bs            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-ca            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-ca-valencia      103.0b9-1            104.0b1-1
  firefox-developer-edition-i18n-cak            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-cs            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-cy            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-da            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-de            103.0b9-1            104.0b1-1
  firefox-developer-edition-i18n-dsb            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-el            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-en-ca            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-en-gb            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-en-us            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-eo            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-es-ar            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-es-cl            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-es-es            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-es-mx            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-et            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-eu            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-fa            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-ff            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-fi            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-fr            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-fy-nl            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-ga-ie            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-gd            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-gl            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-gn            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-gu-in            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-he            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-hi-in            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-hr            103.0b9-1            104.0b1-1
  firefox-developer-edition-i18n-hsb            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-hu            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-hy-am            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-ia            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-id            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-is            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-it            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-ja            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-ka            103.0b9-1            104.0b1-1
  firefox-developer-edition-i18n-kab            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-kk            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-km            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-kn            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-ko            103.0b9-1            104.0b1-1
  firefox-developer-edition-i18n-lij            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-lt            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-lv            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-mk            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-mr            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-ms            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-my            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-nb-no            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-ne-np            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-nl            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-nn-no            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-oc            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-pa-in            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-pl            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-pt-br            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-pt-pt            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-rm            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-ro            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-ru            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-si            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-sk            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-sl            103.0b9-1            104.0b1-1
  firefox-developer-edition-i18n-son            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-sq            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-sr            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-sv-se            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-ta            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-te            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-th            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-tl            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-tr            103.0b9-1            104.0b1-1
  firefox-developer-edition-i18n-trs            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-uk            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-ur            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-uz            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-vi            103.0b9-1            104.0b1-1
   firefox-developer-edition-i18n-xh            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-zh-cn            103.0b9-1            104.0b1-1
firefox-developer-edition-i18n-zh-tw            103.0b9-1            104.0b1-1
                                grex              1.3.0-1              1.4.0-1
                             haproxy              2.6.0-1              2.6.2-1
                    haskell-aeson-qq             0.8.4-67             0.8.4-68
                          haskell-ci           0.12.1-267           0.12.1-268
                    haskell-citeproc                0.7-4                0.7-5
                   haskell-clash-lib              1.6.3-2              1.6.3-3
               haskell-clash-prelude              1.6.3-2              1.6.3-3
                  haskell-commonmark              0.2.2-5              0.2.2-6
       haskell-commonmark-extensions            0.2.3.2-2            0.2.3.2-3
           haskell-commonmark-pandoc           0.2.1.2-59           0.2.1.2-60
                   haskell-esqueleto            3.5.3.0-2            3.5.3.0-3
                     haskell-githash          0.1.6.2-120          0.1.6.2-121
                      haskell-hakyll          4.15.1.1-86          4.15.1.1-87
                        haskell-here           1.2.13-305           1.2.13-306
                       haskell-hpack             0.34.7-4             0.34.7-5
              haskell-hspec-wai-json           0.11.0-298           0.11.0-299
                 haskell-interpolate            0.2.1-218            0.2.1-219
    haskell-interpolatedstring-perl6            1.0.2-220            1.0.2-221
             haskell-language-server          1.3.0.0-236          1.3.0.0-237
             haskell-optparse-simple          0.1.1.4-152          0.1.1.4-153
                      haskell-pantry              0.5.6-2              0.5.6-3
            haskell-persistent-mysql         2.13.0.1-189         2.13.0.1-190
       haskell-persistent-postgresql         2.13.0.3-178         2.13.0.3-179
               haskell-persistent-qq          2.12.0.2-45          2.12.0.2-46
                    haskell-src-meta            0.8.10-14            0.8.10-15
                       haskell-store            0.7.14-32            0.7.14-33
                    haskell-text-icu           0.8.0.1-24            0.8.0.2-1
                  haskell-th-desugar            1.13.1-12            1.13.1-13
              haskell-th-expand-syns           0.4.9.0-37           0.4.10.0-1
                  haskell-th-orphans            0.13.13-7            0.13.13-8
               haskell-th-reify-many            0.1.10-53            0.1.10-54
                haskell-th-utilities           0.2.4.3-79           0.2.4.3-80
           haskell-unicode-collation           0.1.3.2-11           0.1.3.2-12
          haskell-unicode-transforms           0.4.0.1-18           0.4.0.1-19
                             hledger              1.25-70              1.25-71
                          hledger-ui              1.25-91              1.25-92
                         hledger-web             1.25-109             1.25-110
                                 hut              0.1.0-3              0.2.0-1
                                  jc             1.20.2-1             1.20.4-1
                             jenkins              2.360-1              2.361-1
                                just              1.2.0-1              1.3.0-1
                               kicad              6.0.6-2              6.0.7-1
                    kicad-library-3d              6.0.6-1              6.0.7-1
                       kicad-library              6.0.6-1              6.0.7-1
                          libstrophe           1:0.12.0-1           1:0.12.1-1
                      libstrophe-doc           1:0.12.0-1           1:0.12.1-1
                           liquidsfz              0.3.0-1              0.3.1-1
                 lua-language-server              3.5.0-1              3.5.1-1
                          lua-socket            1:3.0.0-1            1:3.1.0-1
                        lua51-socket            1:3.0.0-1            1:3.1.0-1
                        lua52-socket            1:3.0.0-1            1:3.1.0-1
                        lua53-socket            1:3.0.0-1            1:3.1.0-1
                                 lv2             1.18.4-2             1.18.6-1
                              mayavi              4.7.4-2              4.8.0-1
                                 mpv           1:0.34.1-4           1:0.34.1-5
                                mxml                3.3-1              3.3.1-1
                                 nnn                4.5-1                4.6-1
                             nushell             0.65.0-1             0.66.0-1
                                 oil             0.11.0-1             0.12.0-1
                         openvswitch             2.16.1-3             2.16.4-1
                              pandoc              2.18-11              2.18-12
                     pandoc-crossref         0.3.12.2-138         0.3.12.2-139
                            patchelf             0.14.5-1             0.15.0-1
                  perl-www-mechanize               2.10-1               2.12-1
                           postgrest             9.0.0-10             9.0.0-11
                             pyright            1.1.263-1            1.1.264-1
           python-aws-sam-translator             1.47.0-1             1.48.0-1
                    python-executing              0.8.3-1              0.9.1-1
                 python-flake8-isort              4.1.1-2              4.1.2-1
                        python-minio             7.1.10-1             7.1.11-1
                          python-pdm             1.15.4-2              2.0.3-1
                   python-pdm-pep517           1:0.12.7-1            1:1.0.2-1
                    python-pywayland             0.4.13-1             0.4.14-1
                    python-pywlroots            0.15.18-1            0.15.19-1
                        python-qiniu              7.8.0-1              7.9.0-1
                       python-sphinx              5.0.2-3              5.1.1-1
               python-sphinx-autoapi              1.8.4-3              1.9.0-1
                                qgis             3.26.0-2             3.26.1-1
                      rime-cantonese     0.0.0.20211213-1     0.0.0.20220105-1
                       ruby-diff-lcs              1.4.4-2              1.5.0-1
                 ruby-multipart-post              2.1.1-3              2.2.3-1
                  ruby-rake-compiler              1.1.1-2              1.2.0-1
                          ruby-rspec             3.10.0-1             3.11.0-1
                     ruby-rspec-core             3.10.1-1             3.11.0-1
             ruby-rspec-expectations             3.10.1-1             3.11.0-1
                    ruby-rspec-mocks             3.10.2-1             3.11.1-1
                  ruby-rspec-support             3.10.2-1             3.11.0-1
                       rust-analyzer           20220718-1           20220725-1
                                serd            0.30.12-2            0.30.14-1
                          shellcheck            0.8.0-146            0.8.0-147
                      signal-desktop             5.51.0-1             5.51.1-1
                              skopeo              1.9.0-1              1.9.1-1
                                sord            0.16.10-2            0.16.12-3
                              sratom             0.6.10-3             0.6.12-1
                               stack            2.7.5-104            2.7.5-106
                            startdde             5.8.29-1             5.9.32-1
                          strawberry              1.0.6-1              1.0.7-1
                   teamspeak3-server             3.13.6-1             3.13.7-1
                         timescaledb              2.7.0-1              2.7.2-1
             timescaledb-old-upgrade              2.7.0-1              2.7.2-1
                               trivy             0.30.2-1             0.30.4-1
                   ttf-sarasa-gothic             0.36.7-1             0.36.8-1
         v2ray-domain-list-community     20220724131453-1     20220726042225-1
                          warpinator             1.2.12-1             1.2.13-1
                        wasm-bindgen             0.2.81-2             0.2.82-1
                              xmonad             0.17.0-8             0.17.0-9
                      xmonad-contrib             0.17.0-8             0.17.0-9
                             yoshimi              2.2.0-1              2.2.1-1
                                zint             2.10.0-2             2.11.0-1
                             zint-qt             2.10.0-2             2.11.0-1
                       audacity-docs                    -            1:3.1.3-1
                           mxml-docs                    -              3.3.1-1
                      python-unearth                    -              0.5.2-1
                           serd-docs                    -            0.30.14-1
                           sord-docs                    -            0.16.12-3
                         sratom-docs                    -             0.6.12-1


:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-25           2022-07-27
-------------------------------------------------------------------------------
                            linux510           5.10.132-1           5.10.133-1
                    linux510-headers           5.10.132-1           5.10.133-1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-25           2022-07-27
-------------------------------------------------------------------------------
                   archlinux-keyring           20220713-1           20220713-2
                                base                  2-2                  3-1
                              libcap               2.64-1               2.65-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-25           2022-07-27
-------------------------------------------------------------------------------
                      appstream-glib             0.7.18-3                    -
                             firefox              103.0-1                    -
                    firefox-i18n-ach              103.0-1                    -
                     firefox-i18n-af              103.0-1                    -
                     firefox-i18n-an              103.0-1                    -
                     firefox-i18n-ar              103.0-1                    -
                    firefox-i18n-ast              103.0-1                    -
                     firefox-i18n-az              103.0-1                    -
                     firefox-i18n-be              103.0-1                    -
                     firefox-i18n-bg              103.0-1                    -
                     firefox-i18n-bn              103.0-1                    -
                     firefox-i18n-br              103.0-1                    -
                     firefox-i18n-bs              103.0-1                    -
                     firefox-i18n-ca              103.0-1                    -
            firefox-i18n-ca-valencia              103.0-1                    -
                    firefox-i18n-cak              103.0-1                    -
                     firefox-i18n-cs              103.0-1                    -
                     firefox-i18n-cy              103.0-1                    -
                     firefox-i18n-da              103.0-1                    -
                     firefox-i18n-de              103.0-1                    -
                    firefox-i18n-dsb              103.0-1                    -
                     firefox-i18n-el              103.0-1                    -
                  firefox-i18n-en-ca              103.0-1                    -
                  firefox-i18n-en-gb              103.0-1                    -
                  firefox-i18n-en-us              103.0-1                    -
                     firefox-i18n-eo              103.0-1                    -
                  firefox-i18n-es-ar              103.0-1                    -
                  firefox-i18n-es-cl              103.0-1                    -
                  firefox-i18n-es-es              103.0-1                    -
                  firefox-i18n-es-mx              103.0-1                    -
                     firefox-i18n-et              103.0-1                    -
                     firefox-i18n-eu              103.0-1                    -
                     firefox-i18n-fa              103.0-1                    -
                     firefox-i18n-ff              103.0-1                    -
                     firefox-i18n-fi              103.0-1                    -
                     firefox-i18n-fr              103.0-1                    -
                  firefox-i18n-fy-nl              103.0-1                    -
                  firefox-i18n-ga-ie              103.0-1                    -
                     firefox-i18n-gd              103.0-1                    -
                     firefox-i18n-gl              103.0-1                    -
                     firefox-i18n-gn              103.0-1                    -
                  firefox-i18n-gu-in              103.0-1                    -
                     firefox-i18n-he              103.0-1                    -
                  firefox-i18n-hi-in              103.0-1                    -
                     firefox-i18n-hr              103.0-1                    -
                    firefox-i18n-hsb              103.0-1                    -
                     firefox-i18n-hu              103.0-1                    -
                  firefox-i18n-hy-am              103.0-1                    -
                     firefox-i18n-ia              103.0-1                    -
                     firefox-i18n-id              103.0-1                    -
                     firefox-i18n-is              103.0-1                    -
                     firefox-i18n-it              103.0-1                    -
                     firefox-i18n-ja              103.0-1                    -
                     firefox-i18n-ka              103.0-1                    -
                    firefox-i18n-kab              103.0-1                    -
                     firefox-i18n-kk              103.0-1                    -
                     firefox-i18n-km              103.0-1                    -
                     firefox-i18n-kn              103.0-1                    -
                     firefox-i18n-ko              103.0-1                    -
                    firefox-i18n-lij              103.0-1                    -
                     firefox-i18n-lt              103.0-1                    -
                     firefox-i18n-lv              103.0-1                    -
                     firefox-i18n-mk              103.0-1                    -
                     firefox-i18n-mr              103.0-1                    -
                     firefox-i18n-ms              103.0-1                    -
                     firefox-i18n-my              103.0-1                    -
                  firefox-i18n-nb-no              103.0-1                    -
                  firefox-i18n-ne-np              103.0-1                    -
                     firefox-i18n-nl              103.0-1                    -
                  firefox-i18n-nn-no              103.0-1                    -
                     firefox-i18n-oc              103.0-1                    -
                  firefox-i18n-pa-in              103.0-1                    -
                     firefox-i18n-pl              103.0-1                    -
                  firefox-i18n-pt-br              103.0-1                    -
                  firefox-i18n-pt-pt              103.0-1                    -
                     firefox-i18n-rm              103.0-1                    -
                     firefox-i18n-ro              103.0-1                    -
                     firefox-i18n-ru              103.0-1                    -
                    firefox-i18n-sco              103.0-1                    -
                     firefox-i18n-si              103.0-1                    -
                     firefox-i18n-sk              103.0-1                    -
                     firefox-i18n-sl              103.0-1                    -
                    firefox-i18n-son              103.0-1                    -
                     firefox-i18n-sq              103.0-1                    -
                     firefox-i18n-sr              103.0-1                    -
                  firefox-i18n-sv-se              103.0-1                    -
                    firefox-i18n-szl              103.0-1                    -
                     firefox-i18n-ta              103.0-1                    -
                     firefox-i18n-te              103.0-1                    -
                     firefox-i18n-th              103.0-1                    -
                     firefox-i18n-tl              103.0-1                    -
                     firefox-i18n-tr              103.0-1                    -
                    firefox-i18n-trs              103.0-1                    -
                     firefox-i18n-uk              103.0-1                    -
                     firefox-i18n-ur              103.0-1                    -
                     firefox-i18n-uz              103.0-1                    -
                     firefox-i18n-vi              103.0-1                    -
                     firefox-i18n-xh              103.0-1                    -
                  firefox-i18n-zh-cn              103.0-1                    -
                  firefox-i18n-zh-tw              103.0-1                    -
                  linux510-acpi_call             1.2.2-50             1.2.2-51
                   linux510-bbswitch              0.8-151              0.8-152
                linux510-broadcom-wl     6.30.223.271-153     6.30.223.271-154
               linux510-nvidia-390xx           390.151-19           390.151-20
               linux510-nvidia-470xx        470.129.06-18        470.129.06-19
                     linux510-nvidia             515.57-7             515.57-8
                      linux510-r8168          8.049.02-88          8.049.02-89
                  linux510-rtl8723bu          20220114-44          20220114-45
                   linux510-tp_smapi             0.43-151             0.43-152
                linux510-vhba-module          20211218-46          20211218-47
    linux510-virtualbox-host-modules             6.1.36-2             6.1.36-3
                        linux510-zfs              2.1.5-8              2.1.5-9


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-25           2022-07-27
-------------------------------------------------------------------------------
                              amdvlk          2022.Q2.3-1          2022.Q3.1-1
                             firefox            102.0.1-1              103.0-1
                    firefox-i18n-ach            102.0.1-1              103.0-1
                     firefox-i18n-af            102.0.1-1              103.0-1
                     firefox-i18n-an            102.0.1-1              103.0-1
                     firefox-i18n-ar            102.0.1-1              103.0-1
                    firefox-i18n-ast            102.0.1-1              103.0-1
                     firefox-i18n-az            102.0.1-1              103.0-1
                     firefox-i18n-be            102.0.1-1              103.0-1
                     firefox-i18n-bg            102.0.1-1              103.0-1
                     firefox-i18n-bn            102.0.1-1              103.0-1
                     firefox-i18n-br            102.0.1-1              103.0-1
                     firefox-i18n-bs            102.0.1-1              103.0-1
                     firefox-i18n-ca            102.0.1-1              103.0-1
            firefox-i18n-ca-valencia            102.0.1-1              103.0-1
                    firefox-i18n-cak            102.0.1-1              103.0-1
                     firefox-i18n-cs            102.0.1-1              103.0-1
                     firefox-i18n-cy            102.0.1-1              103.0-1
                     firefox-i18n-da            102.0.1-1              103.0-1
                     firefox-i18n-de            102.0.1-1              103.0-1
                    firefox-i18n-dsb            102.0.1-1              103.0-1
                     firefox-i18n-el            102.0.1-1              103.0-1
                  firefox-i18n-en-ca            102.0.1-1              103.0-1
                  firefox-i18n-en-gb            102.0.1-1              103.0-1
                  firefox-i18n-en-us            102.0.1-1              103.0-1
                     firefox-i18n-eo            102.0.1-1              103.0-1
                  firefox-i18n-es-ar            102.0.1-1              103.0-1
                  firefox-i18n-es-cl            102.0.1-1              103.0-1
                  firefox-i18n-es-es            102.0.1-1              103.0-1
                  firefox-i18n-es-mx            102.0.1-1              103.0-1
                     firefox-i18n-et            102.0.1-1              103.0-1
                     firefox-i18n-eu            102.0.1-1              103.0-1
                     firefox-i18n-fa            102.0.1-1              103.0-1
                     firefox-i18n-ff            102.0.1-1              103.0-1
                     firefox-i18n-fi            102.0.1-1              103.0-1
                     firefox-i18n-fr            102.0.1-1              103.0-1
                  firefox-i18n-fy-nl            102.0.1-1              103.0-1
                  firefox-i18n-ga-ie            102.0.1-1              103.0-1
                     firefox-i18n-gd            102.0.1-1              103.0-1
                     firefox-i18n-gl            102.0.1-1              103.0-1
                     firefox-i18n-gn            102.0.1-1              103.0-1
                  firefox-i18n-gu-in            102.0.1-1              103.0-1
                     firefox-i18n-he            102.0.1-1              103.0-1
                  firefox-i18n-hi-in            102.0.1-1              103.0-1
                     firefox-i18n-hr            102.0.1-1              103.0-1
                    firefox-i18n-hsb            102.0.1-1              103.0-1
                     firefox-i18n-hu            102.0.1-1              103.0-1
                  firefox-i18n-hy-am            102.0.1-1              103.0-1
                     firefox-i18n-ia            102.0.1-1              103.0-1
                     firefox-i18n-id            102.0.1-1              103.0-1
                     firefox-i18n-is            102.0.1-1              103.0-1
                     firefox-i18n-it            102.0.1-1              103.0-1
                     firefox-i18n-ja            102.0.1-1              103.0-1
                     firefox-i18n-ka            102.0.1-1              103.0-1
                    firefox-i18n-kab            102.0.1-1              103.0-1
                     firefox-i18n-kk            102.0.1-1              103.0-1
                     firefox-i18n-km            102.0.1-1              103.0-1
                     firefox-i18n-kn            102.0.1-1              103.0-1
                     firefox-i18n-ko            102.0.1-1              103.0-1
                    firefox-i18n-lij            102.0.1-1              103.0-1
                     firefox-i18n-lt            102.0.1-1              103.0-1
                     firefox-i18n-lv            102.0.1-1              103.0-1
                     firefox-i18n-mk            102.0.1-1              103.0-1
                     firefox-i18n-mr            102.0.1-1              103.0-1
                     firefox-i18n-ms            102.0.1-1              103.0-1
                     firefox-i18n-my            102.0.1-1              103.0-1
                  firefox-i18n-nb-no            102.0.1-1              103.0-1
                  firefox-i18n-ne-np            102.0.1-1              103.0-1
                     firefox-i18n-nl            102.0.1-1              103.0-1
                  firefox-i18n-nn-no            102.0.1-1              103.0-1
                     firefox-i18n-oc            102.0.1-1              103.0-1
                  firefox-i18n-pa-in            102.0.1-1              103.0-1
                     firefox-i18n-pl            102.0.1-1              103.0-1
                  firefox-i18n-pt-br            102.0.1-1              103.0-1
                  firefox-i18n-pt-pt            102.0.1-1              103.0-1
                     firefox-i18n-rm            102.0.1-1              103.0-1
                     firefox-i18n-ro            102.0.1-1              103.0-1
                     firefox-i18n-ru            102.0.1-1              103.0-1
                    firefox-i18n-sco            102.0.1-1              103.0-1
                     firefox-i18n-si            102.0.1-1              103.0-1
                     firefox-i18n-sk            102.0.1-1              103.0-1
                     firefox-i18n-sl            102.0.1-1              103.0-1
                    firefox-i18n-son            102.0.1-1              103.0-1
                     firefox-i18n-sq            102.0.1-1              103.0-1
                     firefox-i18n-sr            102.0.1-1              103.0-1
                  firefox-i18n-sv-se            102.0.1-1              103.0-1
                    firefox-i18n-szl            102.0.1-1              103.0-1
                     firefox-i18n-ta            102.0.1-1              103.0-1
                     firefox-i18n-te            102.0.1-1              103.0-1
                     firefox-i18n-th            102.0.1-1              103.0-1
                     firefox-i18n-tl            102.0.1-1              103.0-1
                     firefox-i18n-tr            102.0.1-1              103.0-1
                    firefox-i18n-trs            102.0.1-1              103.0-1
                     firefox-i18n-uk            102.0.1-1              103.0-1
                     firefox-i18n-ur            102.0.1-1              103.0-1
                     firefox-i18n-uz            102.0.1-1              103.0-1
                     firefox-i18n-vi            102.0.1-1              103.0-1
                     firefox-i18n-xh            102.0.1-1              103.0-1
                  firefox-i18n-zh-cn            102.0.1-1              103.0-1
                  firefox-i18n-zh-tw            102.0.1-1              103.0-1
                            harfbuzz              4.4.1-1              5.0.1-1
                        harfbuzz-icu              4.4.1-1              5.0.1-1
                               hwloc              2.7.1-1              2.8.0-1
                           iso-codes             4.10.0-1             4.11.0-1
                              ispell             3.4.04-1             3.4.05-1
                          libplacebo            4.192.1-3            4.208.0-1
                            libspiro         1:20200505-2         1:20220722-1
      mobile-broadband-provider-info           20220511-1           20220725-1
                            protobuf               21.3-2               21.4-1
                             psutils               2.05-1               2.09-1
                          python-pip             22.1.2-1               22.2-1
                     python-protobuf               21.3-2               21.4-1
                            qt5-base    5.15.5+kde+r172-1    5.15.5+kde+r173-1
             qt5-xcb-private-headers    5.15.5+kde+r172-1    5.15.5+kde+r173-1
                                 vlc           3.0.17.4-6           3.0.17.4-7
                      appstream-glib                    -              0.8.0-1


:: Different overlay package(s) in repository kde-unstable x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-25           2022-07-27
-------------------------------------------------------------------------------
                            analitza22.04.3.r2355.g4637e049-122.04.3.r2356.gc2e4500d-1
                             blinken22.04.3.r674.gd2f67e7-122.04.3.r675.g81b9126-1
                           bluedevil1:5.25.3.r2416.g65656cba-11:5.25.3.r2417.gd663974e-1
                              bomber22.04.3.r570.gbe88435-122.04.3.r571.gb7c2acf-1
                             drkonqi5.25.3.r809.g80efd753-15.25.3.r810.g0f572aa3-1
                           filelight22.04.3.r1155.g7d2f734-122.04.3.r1156.gf550312-1
                           itinerary22.04.3.r1962.g49c341b-122.04.3.r1966.gd1cc268-1
                                kalk  22.06.r9.g52b84ad-1 22.06.r10.gb87b5e2-1
                                kate22.04.3.r19258.ge6019e365-122.04.3.r19262.gbb217a488-1
                          kdeconnect22.04.3.r3498.g653a8e34-122.04.3.r3500.g7f21dd91-1
              kdenetwork-filesharing22.04.3.r961.gbc35019-122.04.3.r963.gaf51649-1
                            kdiamond22.04.3.r731.gd2acca8-122.04.3.r732.g6207f90-1
                            keysmith  22.06.r9.gab97a00-1 22.06.r15.gd5d135d-1
                         kgoldrunner22.04.3.r1290.g9270c9b-122.04.3.r1291.gb788199-1
                            khangman22.04.3.r1619.gca39294-122.04.3.r1620.gca5cc28-1
                  khealthcertificate  22.06.r3.g581e0b7-1  22.06.r7.gaabde48-1
                         khelpcenter22.04.3.r2761.gdd3668c6-122.04.3.r2762.g0a2cc6b7-1
                                kigo22.04.3.r576.g0bcdcce-122.04.3.r577.g0aa6d0a-1
                            killbots22.04.3.r800.g5357bac-122.04.3.r801.ge083b35-1
                                 kio5.96.0.r5602.g7b2731691-15.96.0.r5611.geef61d108-1
                          kio-extras22.04.3.r7304.g3cccab5f-122.04.3.r7305.g91951dd0-1
                    kirigami-gallery22.04.3.r258.g9271757-122.04.3.r259.gf983f28-1
                         kitemmodels5.96.0.r613.g8f6edf9-15.96.0.r614.g8d0117c-1
                               kiten22.04.3.r1204.g30d55af-122.04.3.r1205.g49e9ca3-1
                          kitinerary22.04.3.r2329.g8b99159-122.04.3.r2333.gb1b669c-1
                           kleopatra22.04.3.r6698.g6b4d0519-122.04.3.r6703.ge1f59f5b-1
                            klickety22.04.3.r702.gff08b3f-122.04.3.r703.gbc1c850-1
                              klines22.04.3.r827.g87acba4-122.04.3.r828.g003db6c-1
                           kmahjongg22.04.3.r1566.gf89cc0e-122.04.3.r1567.g6df1f7f-1
                              kmines22.04.3.r1772.ga4000b6-122.04.3.r1773.g9b0543f-1
                           kollision22.04.3.r541.g9e8398b-122.04.3.r542.g4223584-1
                         kolourpaint22.04.3.r2425.g8b6d4d1b-122.04.3.r2427.ge3cc390e-1
                            kongress 22.06.r10.ge9b588f-1 22.06.r11.gb6bbb86-1
                            konquest22.04.3.r937.g82baf47-122.04.3.r938.gf977f64-1
                            kpackage5.96.0.r759.ge8b40d7-15.96.0.r760.g74bf92c-1
                             kpmcore22.04.3.r1293.g1ec8b8b-122.04.3.r1294.gf01581f-1
                    kpublictransport22.04.3.r2033.g58994c55-122.04.3.r2038.g704136b5-1
                             kscreen5.25.3.r1493.g6c4cf54-15.25.3.r1496.ga37f3d0-1
                               ksirk22.04.3.r1039.g7fb6e34-122.04.3.r1040.g0f6e3dc-1
                          kspaceduel22.04.3.r679.g9766b8b-122.04.3.r680.g87cab42-1
                          ksystemlog22.04.3.r738.g75a35bc-122.04.3.r740.g581a825-1
                              ktouch22.04.3.r2191.gdfd4dfa-122.04.3.r2193.ga619caa-1
                             kubrick22.04.3.r413.gb7f7406-122.04.3.r415.gd48ca84-1
                      kwalletmanager22.04.3.r1281.g0a849be-122.04.3.r1282.gc6579ba-1
                      kwidgetsaddons5.96.0.r958.ge425aaa3-15.96.0.r959.ge3465ead-1
                                kwin5.25.3.r22835.gacd5bf9a6-15.25.3.r22859.g8407f8858-1
                              kwrite22.04.3.r19258.ge6019e365-122.04.3.r19262.gbb217a488-1
                             kxmlgui5.96.0.r895.g031daa12-15.96.0.r896.g52eb340c-1
                        libkmahjongg22.04.3.r485.g63e3d24-122.04.3.r486.ga227949-1
                          libkscreen5.25.3.r1633.gf6c8db3-15.25.3.r1634.g4004b09-1
                               lskat22.04.3.r861.g5d74e88-122.04.3.r862.g1426b3a-1
                             neochat22.06.r51.g94f32560-122.06.r53.g179a2011-1
                    plasma-framework5.96.0.r16370.ga387a4629-15.96.0.r16374.g5ddb367d0-1
                    plasma-mobile-nm5.25.3.r3294.g141ce673-15.25.3.r3295.gc72282f5-1
            plasma-remotecontrollers       r95.g34feeed-1       r98.ge0096ed-1
                          plasma-sdk5.25.3.r2378.g811d92d1-15.25.3.r2379.gb6c09c2f-1
                     plasma-settings 22.06.r34.gd8092ce-1 22.06.r42.g58bb867-1
                  qqc2-desktop-style5.96.0.r645.g9392730-15.96.0.r646.g1bcaf0b-1
                                step22.04.3.r1200.g64a0495-122.04.3.r1204.gc4ed15b-1
                             sweeper22.04.3.r578.g89755e6-122.04.3.r579.g28430e5-1
                             tokodon 22.06.r19.g4e6865c-1 22.06.r20.g8a95a35-1


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-25           2022-07-27
-------------------------------------------------------------------------------
                        lib32-amdvlk          2022.Q2.3-1          2022.Q3.1-1
                      lib32-harfbuzz              4.4.1-1              5.0.1-1
                  lib32-harfbuzz-icu              4.4.1-1              5.0.1-1
                        lib32-libcap               2.64-1               2.65-1
</code></pre>
<p><a href="https://forum.manjaro.org/t/testing-update-2022-07-27-kernels-cinnamon-amdvlk-firefox-103/117704/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul><li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul><p><small>2 posts - 1 participant</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2022-07-27-kernels-cinnamon-amdvlk-firefox-103/117704">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Increasingly Using WebAssembly Coded Cryptominers to Evade Detection]]></title>
<description><![CDATA[As many as 207 websites have been infected with malicious code designed to launch a cryptocurrency miner by leveraging WebAssembly (Wasm) on the browser.
Web security company Sucuri, which published details of the campaign, said it launched an investigation after one of its clients had their comp...]]></description>
<link>https://tsecurity.de/de/1582757/it-security-nachrichten/hackers-increasingly-using-webassembly-coded-cryptominers-to-evade-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1582757/it-security-nachrichten/hackers-increasingly-using-webassembly-coded-cryptominers-to-evade-detection/</guid>
<pubDate>Tue, 26 Jul 2022 17:48:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As many as 207 websites have been infected with malicious code designed to launch a cryptocurrency miner by leveraging WebAssembly (Wasm) on the browser.
Web security company Sucuri, which published details of the campaign, said it launched an investigation after one of its clients had their computer slowed down significantly every time upon navigating to their own WordPress portal.
This]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2022-34502]]></title>
<description><![CDATA[Radare2 v5.7.0 was discovered to contain a heap buffer overflow via the function consume_encoded_name_new at format/wasm/wasm.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted binary file.]]></description>
<link>https://tsecurity.de/de/1579830/sicherheitsluecken/cve-2022-34502/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1579830/sicherheitsluecken/cve-2022-34502/</guid>
<pubDate>Fri, 22 Jul 2022 18:19:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Radare2 v5.7.0 was discovered to contain a heap buffer overflow via the function consume_encoded_name_new at format/wasm/wasm.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted binary file.]]></content:encoded>
</item>
<item>
<title><![CDATA[[Stable Update] 2022-07-21 - Cinnamon 5.4, Kodi Game-Addons, Pipewire 0.3.56, KDE-Git]]></title>
<description><![CDATA[Hello community,
Another stable branch update with some usual updates for you.

Checkout the store today! From 21st till 24th we offer free standard shipping.

Cinnamon 5.4 series saw a lot of updates

Game-Addons for Kodi got renewed

Pipewire 0.3.56 brings more regression fixes
Regular KDE-git,...]]></description>
<link>https://tsecurity.de/de/1577824/unix-server/stable-update-2022-07-21-cinnamon-54-kodi-game-addons-pipewire-0356-kde-git/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1577824/unix-server/stable-update-2022-07-21-cinnamon-54-kodi-game-addons-pipewire-0356-kde-git/</guid>
<pubDate>Thu, 21 Jul 2022 06:49:55 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello community,</p>
<p>Another <strong>stable</strong> branch update with some usual updates for you.</p>
<p><img src="https://forum.manjaro.org/uploads/default/original/3X/8/8/8807d849adabf5186077586be54980ce0a22c4d1.jpeg" alt="image" data-base62-sha1="jpnK6bYIeO3pP4VGcnd3nxlEQjT" width="640" height="360"></p>
<p><em>Checkout the <a href="https://manjaro.myspreadshop.net/">store</a> today! From 21st till 24th we offer <strong>free standard shipping</strong>.</em></p>
<ul><li>
<strong>Cinnamon</strong> 5.4 series saw a lot of updates</li>
<li>
<strong>Game-Addons</strong> for <strong>Kodi</strong> got renewed</li>
<li>
<strong>Pipewire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/0.3.56">0.3.56</a> brings more regression fixes</li>
<li>Regular <strong>KDE-git</strong>, <strong>Haskell</strong> and <strong>Python</strong> updates</li>
</ul><h2>
<a name="additional-info-1" class="anchor" href="https://forum.manjaro.org/#additional-info-1"></a>Additional Info</h2>

Info about AUR packages <a href="https://forum.manjaro.org/t/stable-update-2022-07-21-cinnamon-5-4-kodi-game-addons-pipewire-0-3-56-kde-git/117185/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr><p><strong>Our current supported kernels</strong></p>
<ul><li>linux419 4.19.252</li>
<li>linux54 5.4.206</li>
<li>linux510 5.10.131</li>
<li>linux515 5.15.55</li>
<li>linux517 5.17.15 (EOL)</li>
<li>linux518 5.18.12</li>
<li>linux519 5.19-rc7</li>
<li>linux515-rt 5.15.49_rt47</li>
<li>linux518-rt 5.18.0_rt11</li>
</ul><p><strong>Package Changes</strong> (Wed Jul 20 05:40:34 CEST 2022)</p>
<ul><li>stable community x86_64:  200 new and 196 removed package(s)</li>
<li>stable core x86_64:  4 new and 4 removed package(s)</li>
<li>stable extra x86_64:  57 new and 58 removed package(s)</li>
<li>stable kde-unstable x86_64:  67 new and 67 removed package(s)</li>
<li>stable multilib x86_64:  8 new and 9 removed package(s)</li>
</ul><pre><code class="lang-auto">:: Different overlay package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-18           2022-07-21
-------------------------------------------------------------------------------
                            cinnamon              5.4.2-1              5.4.3-1
                           os-prober               1.79-1               1.81-1


:: Different sync package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-18           2022-07-21
-------------------------------------------------------------------------------
                             absl-py              1.1.0-1                    -
                             aegisub             3.2.2-51             3.2.2-52
                        ansible-core             2.13.1-1             2.13.2-1
                                apko              0.4.0-1              0.5.0-1
                             baresip              2.5.0-1              2.5.1-1
                           benchmark              1.6.1-2              1.6.2-1
                           bitwarden           2022.6.2-1           2022.6.2-2
                       bitwarden-cli           2022.6.2-1           2022.6.2-2
                             blueman              2.2.5-1              2.3.1-1
                      budgie-desktop             10.6.1-1             10.6.2-1
                             calibre             5.44.0-1              6.1.0-1
                          cargo-edit              0.9.1-1             0.10.1-1
                             catfish             4.16.3-2             4.16.4-1
                               chafa             1.10.3-1             1.12.0-1
                             chezmoi             2.18.1-1             2.19.0-1
             cinnamon-control-center              5.4.3-1              5.4.4-1
                    cinnamon-desktop              5.4.0-1              5.4.1-1
                cinnamon-screensaver              5.4.0-1              5.4.1-1
            cinnamon-settings-daemon              5.4.1-1              5.4.2-1
                                 cjs              5.4.0-1              5.4.1-1
                                code             1.69.1-1             1.69.2-1
                              codec2            1:1.0.4-1            1:1.0.5-1
                              consul             1.12.2-1             1.12.3-1
                               copyq              6.2.0-1              6.2.0-2
                                croc              9.5.6-1              9.6.0-1
                             curtail              1.3.0-1              1.3.1-1
                              dagger             0.2.23-1             0.2.24-1
                      discord-canary            0.0.135-1            0.0.136-1
                              drupal              9.2.9-2              9.4.2-1
                         easyeffects              6.2.6-2              6.2.7-1
                              eslint             8.19.0-1             8.20.0-1
                            evilginx              2.4.0-1              2.4.0-2
                              fabric              2.7.0-1              2.7.1-1
                            geogebra          6.0.720.0-1          6.0.721.0-1
                                  go           2:1.18.3-1           2:1.18.4-1
                            go-tools           4:0.1.11-1           4:0.1.11-2
                               gopls              0.9.0-1              0.9.1-1
                      grafana-zabbix              4.2.8-1              4.2.9-1
                                grpc             1.47.0-1             1.47.1-1
                            grpc-cli             1.47.0-1             1.47.1-1
                               gtest             1.12.0-2             1.12.1-1
                       haskell-brick               0.69-5             0.69.1-1
                haskell-summoner-tui          2.0.1.1-374          2.0.1.1-375
                              hepmc2            2.06.11-1            2.06.11-2
                        hledger-iadd            1.3.17-59            1.3.17-60
                          hledger-ui              1.25-85              1.25-86
                              hwinfo              21.81-1              21.82-1
                               icewm              2.9.7-1              2.9.8-1
                              icmake            9.03.01-1            9.03.01-2
                                 inn              2.6.4-5              2.7.0-1
     intellij-idea-community-edition         4:2022.1.3-1         4:2022.1.4-1
 kodi-addon-game-libretro-beetle-psx          0.9.44.38-6          0.9.44.40-1
    kodi-addon-game-libretro-desmume           0.0.1.17-8           0.0.1.20-1
   kodi-addon-game-libretro-gambatte           0.5.0.31-6           0.5.0.33-1
    kodi-addon-game-libretro-melonds           0.9.3.27-6           0.9.3.29-1
       kodi-addon-game-libretro-mgba          0.10.0.34-6          0.10.0.35-1
   kodi-addon-game-libretro-nestopia          1.51.1.24-6          1.51.1.26-1
kodi-addon-game-libretro-parallel-n64           2.0.0.21-6           2.0.0.23-1
    kodi-addon-game-libretro-scummvm           2.1.1.23-6           2.1.1.25-1
     kodi-addon-game-libretro-snes9x          1.61.0.32-6          1.61.0.34-1
    kodi-addon-game-libretro-yabause          0.9.15.37-6          0.9.15.39-1
               kvantum-theme-materia           20220607-1           20220714-1
                        languagetool                5.7-1                5.8-1
                       libafterimage               1.20-5               1.20-6
                          libclastfm                0.5-6                0.5-7
                       libimagequant             2.17.0-3              4.0.0-1
                              libluv           1.43.0_0-1           1.44.2_0-1
                     libmusicbrainz5              5.1.0-4              5.1.0-5
                 lua-language-server              3.4.2-1              3.5.0-1
                             lua-luv           1.43.0_0-1           1.44.2_0-1
                           lua51-luv           1.43.0_0-1           1.44.2_0-1
                           lua52-luv           1.43.0_0-1           1.44.2_0-1
                           lua53-luv           1.43.0_0-1           1.44.2_0-1
                         materia-kde           20220607-1           20220714-1
                               maude                3.1-1              3.2.1-1
                             menyoki              1.6.0-1              1.6.1-1
                          metasploit              6.2.5-1              6.2.7-1
                               mmctl              7.0.1-1              7.1.0-1
                     molecule-docker              1.1.0-2              2.0.0-1
                              muffin              5.4.1-1              5.4.2-1
                                nemo              5.4.0-1              5.4.1-1
                      nemo-audio-tab              5.4.0-1              5.4.1-1
                        nemo-emblems              5.4.0-1              5.4.1-1
                     nemo-fileroller              5.4.0-1              5.4.1-1
                nemo-image-converter              5.4.0-1              5.4.1-1
                       nemo-pastebin              5.4.0-1              5.4.1-1
                        nemo-preview              5.4.0-1              5.4.1-1
                         nemo-python              5.4.0-1              5.4.1-1
                       nemo-seahorse              5.4.0-1              5.4.1-1
                          nemo-share              5.4.0-1              5.4.1-1
                       nemo-terminal              5.4.0-1              5.4.1-1
                             nerdctl             0.21.0-1             0.22.0-1
                           nextcloud             24.0.2-1             24.0.3-1
                                 nix             2.10.1-1             2.10.3-1
                            nix-docs             2.10.1-1             2.10.3-1
                               nomad              1.3.1-1              1.3.2-1
                 nomad-driver-podman              0.3.0-2              0.4.0-1
                            openfire              4.7.1-1              4.7.2-1
                            openrct2              0.4.0-1              0.4.1-1
                               opera       89.0.4447.48-1       89.0.4447.51-1
                              ospray             2.10.0-2             2.10.0-3
                  perl-finance-quote               1.51-3               1.52-1
                           perl-json               4.06-1               4.07-1
                     perl-json-parse               0.61-1               0.62-1
                            perl-ppi              1.274-2              1.275-1
               perl-software-license           0.104001-2           0.104002-1
                  perl-www-mechanize               2.08-1               2.10-1
                        perl-yaml-pp              0.032-1              0.034-1
                            php-grpc             1.47.0-1             1.47.1-1
                         php-mongodb             1.13.0-2             1.14.0-1
                           php7-grpc             1.47.0-1             1.47.1-1
                        php7-mongodb             1.13.0-2             1.14.0-1
                             pkgdiff              1.7.2-3              1.7.2-4
                            polymake                4.6-6                4.7-1
                         python-aaf2              1.5.0-1              1.6.0-1
                       python-bleach              5.0.0-1              5.0.1-1
                       python-celery              5.2.1-1              5.2.7-1
                 python-cinderclient              8.3.0-1              9.0.0-1
                   python-darkdetect              0.6.0-1              0.7.1-1
              python-designateclient              4.5.1-1              5.0.0-1
                      python-distlib              0.3.4-1              0.3.5-1
                      python-dropbox            11.32.0-1            11.33.0-1
                     python-eventlet             0.33.0-2             0.33.1-1
               python-fastjsonschema             2.15.3-1             2.16.1-1
                python-flask-htmlmin              2.1.0-2              2.2.0-1
                python-flask-migrate              3.0.0-3              3.1.0-1
               python-flask-paranoid                0.2-8              0.3.0-1
           python-flask-security-too              4.1.3-1              4.1.4-1
               python-flask-socketio              5.1.1-1              5.2.0-1
                    python-flask-wtf              1.0.0-1              1.0.1-1
                       python-grpcio             1.47.0-1             1.47.1-1
                   python-heatclient              2.5.1-1              3.0.0-1
                      python-inflect              5.6.1-1              5.6.2-1
                     python-jupymake               0.9-13               0.9-14
                   python-listparser               0.18-5               0.19-1
                     python-markdown              3.3.7-1              3.4.1-1
                  python-mygpoclient                1.8-9                1.9-1
                python-neutronclient              7.8.0-1              8.0.0-1
                        python-nose2             0.11.0-1             0.12.0-1
                       python-orjson              3.7.7-1              3.7.8-1
                       python-owslib             0.25.0-1             0.26.0-1
        python-pallets-sphinx-themes              2.0.1-4              2.0.2-1
                         python-perf              2.3.0-1              2.3.1-1
                python-podcastparser              0.6.7-3              0.6.8-1
                     python-pydrive2             1.10.1-1             1.12.1-1
                        python-pyjwt              2.2.0-3              2.4.0-1
               python-pytest-aiohttp              0.3.0-8              1.0.4-1
                  python-simplebayes              1.5.7-9              1.5.8-1
     python-sphinx-autodoc-typehints             1.12.0-1             1.13.1-1
                python-sphinx-issues              1.2.0-7              3.0.1-1
                  python-swiftclient              4.0.0-1              4.0.1-1
                      python-tempora              5.0.1-2              5.0.2-1
                                qgis             3.24.3-2             3.26.0-1
                            radicale              3.1.7-1              3.1.8-1
                              reaper               6.63-1               6.64-1
                               redis              7.0.3-1              7.0.4-1
                         release-cli             0.11.0-2             0.13.0-1
                              revive              1.1.4-2              1.2.1-1
                            rofimoji              5.4.0-3              5.5.0-1
                       roundcubemail              1.5.2-2              1.5.3-1
                        ruby-bundler             2.3.15-1             2.3.17-1
                       rust-analyzer           20220711-1           20220718-1
                        rxvt-unicode               9.26-3               9.30-1
               rxvt-unicode-terminfo               9.26-3               9.30-1
                               scite              5.2.3-1              5.2.4-1
                           seamonkey            2.53.12-1            2.53.13-1
                         singularity               1.00-4               1.00-5
                            sqlfluff              1.1.0-1              1.2.1-1
                         sstp-client           1:1.0.16-1           1:1.0.17-1
                          strawberry              1.0.5-2              1.0.6-1
                             stunnel               5.64-1               5.65-1
                         superslicer         1:2.4.58.2-3         1:2.4.58.3-1
                            supertux              0.6.3-2              0.6.3-3
                              swappy              1.4.0-1              1.4.0-2
                    systembus-notify                1.1-1                1.1-2
                             taskell           1.11.4-188           1.11.4-189
                         tensorboard              2.9.1-1              2.9.1-2
                                tepl              6.1.2-1            1:6.0.2-1
                     translate-shell           0.9.6.12-2           0.9.6.12-3
                              tt-rss 2:r11220.b59bde7b4-1 2:r11325.8f19423c2-1
                   ttf-sarasa-gothic             0.36.6-1             0.36.7-1
         v2ray-domain-list-community     20220715033720-1     20220719055203-1
                         vaultwarden             1.25.0-1             1.25.1-1
                     vaultwarden-web           2022.6.0-1           2022.6.2-1
                           veracrypt             1.25.9-2             1.25.9-3
                             wesnoth           1:1.16.4-1           1:1.16.5-1
                           wxsqlite3              4.7.8-2              4.8.2-1
                                xapp             2.2.12-1             2.2.13-1
                           xbindkeys              1.8.7-2              1.8.7-3
                           xlockmore               5.69-1               5.70-1
                         xsecurelock              1.7.0-1              1.7.0-2
                              yt-dlp         2022.06.29-1         2022.07.18-1
                                  zk             0.11.0-1             0.11.1-1
                                zola             0.15.3-1             0.16.0-2
                            corectrl                    -              1.2.4-2
                      gtksourceview3                    -1:3.24.11+r28+g73e57b57-1
                        kdesrc-build                    -              22.07-1
                           libptytty                    -                2.0-4
                         python-absl                    -              1.1.0-2
       python-sphinx-bootstrap-theme                    -              0.8.1-3


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-18           2022-07-21
-------------------------------------------------------------------------------
                              hdparm               9.63-2               9.64-1
                             libldap              2.6.2-2              2.6.3-1
                         nilfs-utils              2.2.8-2              2.2.9-1
                            openldap              2.6.2-2              2.6.3-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-18           2022-07-21
-------------------------------------------------------------------------------
                           libnotify              0.8.0-2                    -
                       pipewire-alsa         1:0.3.55-2.0         1:0.3.56-1.0
                       pipewire-jack         1:0.3.55-2.0         1:0.3.56-1.0
                      pipewire-pulse         1:0.3.55-2.0         1:0.3.56-1.0


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-18           2022-07-21
-------------------------------------------------------------------------------
                  alsa-card-profiles           1:0.3.55-2           1:0.3.56-1
                                celt             0.11.3-4                    -
                                gcab                1.4-1                1.4-2
                                 gcr             3.41.0-2             3.41.1-1
                              gmime3              3.2.7-1             3.2.12-1
                         gnome-menus             3.36.0-1             3.36.0-2
                             gnuplot              5.4.3-6              5.4.4-1
                       gnuplot-demos              5.4.3-6              5.4.4-1
                            graphviz              4.0.0-1              5.0.0-1
                 gst-plugin-pipewire           1:0.3.55-2           1:0.3.56-1
                      gtksourceview33.24.11+28+g73e57b57-1                    -
                 ibus-typing-booster            2.15.25-1             2.17.1-1
                               imake              1.0.8-3              1.0.8-4
                              jasper              3.0.4-1              3.0.6-1
                          jasper-doc              3.0.4-1              3.0.6-1
                     lib32-rust-libs           1:1.62.0-1           1:1.62.1-1
                             libbs2b              3.1.0-7              3.1.0-8
                          libcryptui3.12.2+55+ged3b12af-11:3.12.2+r69+g9c70a43b-1
                           libmikmod           3.3.11.1-4           3.3.11.1-6
                           libnotify              0.8.0-2              0.8.1-1
                                meld             3.20.4-2             3.21.2-1
                              mpg123             1.29.3-2             1.30.1-1
              perl-crypt-openssl-rsa               0.32-2               0.33-1
                   perl-crypt-ssleay           0.73_04-16            0.73_06-1
                            pipewire           1:0.3.55-2           1:0.3.56-1
                       pipewire-alsa           1:0.3.55-2           1:0.3.56-1
                       pipewire-docs           1:0.3.55-2           1:0.3.56-1
                       pipewire-jack           1:0.3.55-2           1:0.3.56-1
                      pipewire-pulse           1:0.3.55-2           1:0.3.56-1
                       pipewire-v4l2           1:0.3.55-2           1:0.3.56-1
                   pipewire-x11-bell           1:0.3.55-2           1:0.3.56-1
                   pipewire-zeroconf           1:0.3.55-2           1:0.3.56-1
                          prometheus             2.36.2-1             2.37.0-1
                          protobuf-c              1.4.0-4              1.4.1-1
                               rtkit               0.13-1               0.13-2
                                rust           1:1.62.0-1           1:1.62.1-1
                           rust-musl           1:1.62.0-1           1:1.62.1-1
                            rust-src           1:1.62.0-1           1:1.62.1-1
                           rust-wasm           1:1.62.0-1           1:1.62.1-1
                               samba             4.16.2-1             4.16.3-1
                                 sbc                1.5-2                2.0-1
                   seahorse-nautilus3.11.92+66+g02c81f1-11:3.11.92+r88+g86214b8-1
                                 sip              6.6.2-2              6.6.2-3
                           smbclient             4.16.2-1             4.16.3-1
                               woff2              1.0.2-3              1.0.2-4
                    wxwidgets-common              3.2.0-2              3.2.0-4
                      wxwidgets-gtk3              3.2.0-2              3.2.0-4
                       wxwidgets-qt5              3.2.0-2              3.2.0-4
                  xdg-desktop-portal             1.14.4-1             1.14.5-1
                        zabbix-agent              6.0.5-1              6.2.0-1
                       zabbix-agent2              6.0.5-1              6.2.0-1
                 zabbix-frontend-php              6.0.5-1              6.2.0-1
                        zabbix-proxy              6.0.5-1              6.2.0-1
                       zabbix-server              6.0.5-1              6.2.0-1
                      zita-alsa-pcmi              0.4.0-1              0.5.1-1
                            gcr-docs                    -             3.41.1-1


:: Different overlay package(s) in repository kde-unstable x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-18           2022-07-21
-------------------------------------------------------------------------------
                    akonadi-calendar22.04.3.r2141.g3aea1a4-122.04.3.r2142.gd82e700-1
                    akonadi-contacts22.04.3.r3228.gaae941f7-122.04.3.r3229.ge11e12c3-1
                           alligator 22.06.r21.gd6f7dc5-1 22.06.r22.ge37b88b-1
                            analitza22.04.3.r2352.gb312e7db-122.04.3.r2355.g4637e049-1
                           angelfish 22.06.r20.g4e294ff-1 22.06.r21.g4ab1280-1
                                 ark22.04.3.r4818.g59745c8f-122.04.3.r4820.g239f99d3-1
                         audiocd-kio22.04.3.r1090.gb36c01e-122.04.3.r1092.g5818940-1
                       baloo-widgets22.04.3.r762.g66425c4-122.04.3.r763.gf93b9a3-1
                              breeze5.25.3.r2430.g224f6c37-15.25.3.r2431.gd012df4e-1
                           calindori  22.06.r7.g53c09da-1  22.06.r8.g8553328-1
                              cantor22.04.3.r3366.gc9d7b646-122.04.3.r3368.g4efa9889-1
                           itinerary22.04.3.r1951.g6c85057-122.04.3.r1956.g302bdf8-1
                                 juk22.04.3.r3166.ge471f665-122.04.3.r3167.g03eb4fc3-1
                                kalk  22.06.r8.g7626461-1  22.06.r9.g52b84ad-1
                             kalzium22.04.3.r4370.g254ff1d8-122.04.3.r4373.gfc36b715-1
                               kasts 22.06.r27.gce45074-1 22.06.r29.g91de33f-1
                                kate22.04.3.r19238.g2403075c3-122.04.3.r19242.gf6743520d-1
                              kclock 22.06.r13.g882a72a-1 22.06.r14.g16989c8-1
                             kconfig5.96.0.r964.gd96f19bc-15.96.0.r965.g491f5464-1
                      kdebugsettings22.04.3.r944.ge4f6a25-122.04.3.r946.g5f5c562-1
                                kded5.96.0.r467.gc7a921a-15.96.0.r468.gec9f232-1
                       kdepim-addons22.04.3.r4720.g59b1456d0-122.04.3.r4721.g5eedfcb9c-1
                    kdeplasma-addons5.25.3.r8930.g0d3c669f0-15.25.3.r8931.g7be911900-1
                            keysmith  22.06.r7.gdc845ae-1  22.06.r8.gb74e529-1
                            khangman22.04.3.r1618.gb49b93f-122.04.3.r1619.gca39294-1
                         khelpcenter22.04.3.r2757.g460a5dff-122.04.3.r2758.g1cfa9d78-1
                            khotkeys5.25.3.r2149.g831ed9e-15.25.3.r2151.g292cd1d-1
                         kinfocenter5.25.3.r2123.gc9e7a6cb-15.25.3.r2124.ge928b457-1
                                 kio5.96.0.r5587.gb323a33c9-15.96.0.r5588.g125977a27-1
                          kio-extras22.04.3.r7298.g52a56adc-122.04.3.r7299.g850d9af0-1
                           kleopatra22.04.3.r6676.ged516693-122.04.3.r6677.ga9a3f23b-1
                           kmahjongg22.04.3.r1559.g96f1bbf-122.04.3.r1565.g6d8fc1b-1
                              knotes22.04.3.r3678.ga5bdec93-122.04.3.r3679.g8a127759-1
                                koko  22.06.r6.gdd9222a-1  22.06.r7.g7152f6c-1
                            kongress  22.06.r5.gbaa77e7-1  22.06.r6.gd325480-1
                        konversation22.04.3.r9130.g08bfe884-122.04.3.r9131.g4d441ef8-1
                            kpackage5.96.0.r758.g2cc209e-15.96.0.r759.ge8b40d7-1
                           krecorder  22.06.r8.gb303c3b-1  22.06.r9.g182d96f-1
                                krfb22.04.3.r1507.g2cd15b6-122.04.3.r1511.g5173e7f-1
                            kservice5.96.0.r1023.g5b12b2d-15.96.0.r1024.g7b06291-1
                               ktrip  22.06.r7.g6c20cf6-1  22.06.r8.g162e6ef-1
                            kwayland5.96.0.r1170.ge5fda97-15.96.0.r1172.g5227e3f-1
                            kweather 22.06.r15.g1d904fb-1 22.06.r16.gc572d1b-1
                                kwin5.25.3.r22762.ge801819a2-15.25.3.r22771.ga0c8d4b24-1
                              kwrite22.04.3.r19238.g2403075c3-122.04.3.r19242.gf6743520d-1
                             neochat22.06.r43.gf80039a5-122.06.r47.ga7504876-1
                              oxygen5.25.3.r4497.g489752e0-15.25.3.r4499.g84305086-1
                    plasma-bigscreen      r486.g8952b8f-1      r487.g95c8e34-1
          plasma-browser-integration5.25.3.r1338.g5b57c8be-15.25.3.r1339.g3ba5d473-1
                      plasma-desktop5.25.3.r9428.g582571ad2-15.25.3.r9437.g292b5c635-1
                       plasma-dialer 22.06.r15.g5714110-1 22.06.r16.gf6cf597-1
                        plasma-disks5.25.3.r285.gd2e6d02-15.25.3.r286.g3f58a5f-1
                       plasma-mobile5.25.3.r1911.g29d5afaac-15.25.3.r1912.g5a9802ae5-1
                    plasma-phonebook  22.06.r4.gd3c3687-1  22.06.r5.g62a98d0-1
                     plasma-settings 22.06.r29.gaed5bc7-1 22.06.r30.g1e6d45b-1
                plasma-systemmonitor5.25.3.r594.g30b8d8b-15.25.3.r595.ga6b72e0-1
              plasma-wayland-session5.25.3.r12082.gc07d105ad-15.25.3.r12087.g6ec7a9f0a-1
                    plasma-workspace5.25.3.r12082.gc07d105ad-15.25.3.r12087.g6ec7a9f0a-1
         plasma-workspace-wallpapers5.25.3.r360.g7705661-15.25.3.r361.g2c96c7a-1
                          plasmatube  22.06.r6.g858abe4-1  22.06.r7.g07b6f24-1
                       print-manager22.04.3.r1145.g5d29881-122.04.3.r1147.g66eda1f-1
                             purpose5.96.0.r983.ge4ae404-15.96.0.r984.g51e3a30-1
                          qmlkonsole  22.06.r9.g3b1160f-1 22.06.r10.ga75f5ab-1
                               solid5.96.0.r783.gc6adb1e-15.96.0.r784.g8c9ad6a-1
                           spectacle22.04.3.r1373.gba86116-122.04.3.r1374.gf32cc2f-1
                             tokodon 22.06.r13.g21aae2b-1 22.06.r14.g565052f-1
                         vakzination  22.06.r9.g872245a-1 22.06.r10.gdaac6be-1


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-18           2022-07-21
-------------------------------------------------------------------------------
                          lib32-celt             0.11.3-4                    -
                       lib32-libldap              2.6.2-1              2.6.3-1
                     lib32-libmikmod           3.3.11.1-5           3.3.11.1-6
                         lib32-libnl              3.6.0-1              3.7.0-1
                        lib32-mpg123             1.29.3-1             1.30.1-1
                      lib32-pipewire           1:0.3.55-2           1:0.3.56-1
                 lib32-pipewire-jack           1:0.3.55-2           1:0.3.56-1
                 lib32-pipewire-v4l2           1:0.3.55-2           1:0.3.56-1
                        wine-staging               7.12-1               7.13-1

</code></pre>
<p><a href="https://forum.manjaro.org/t/stable-update-2022-07-21-cinnamon-5-4-kodi-game-addons-pipewire-0-3-56-kde-git/117185/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul><li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul><p><small>2 posts - 1 participant</small></p>
            <p><a href="https://forum.manjaro.org/t/stable-update-2022-07-21-cinnamon-5-4-kodi-game-addons-pipewire-0-3-56-kde-git/117185">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2022-07-20 - Cinnamon 5.4, Kodi-Game-Addons, Pipewire 0.3.56, KDE-Git]]></title>
<description><![CDATA[Hello community,
Another testing branch update with some usual updates for you.

Checkout the store. From 21st till 24th we offer free standard shipping!

Cinnamon 5.4 series saw a lot of updates

Game-Addons for Kodi got renewed

Pipewire 0.3.56 brings more regression fixes
Regular KDE-git, Hask...]]></description>
<link>https://tsecurity.de/de/1576459/unix-server/testing-update-2022-07-20-cinnamon-54-kodi-game-addons-pipewire-0356-kde-git/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1576459/unix-server/testing-update-2022-07-20-cinnamon-54-kodi-game-addons-pipewire-0356-kde-git/</guid>
<pubDate>Wed, 20 Jul 2022 04:19:28 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello community,</p>
<p>Another <strong>testing</strong> branch update with some usual updates for you.</p>
<p><img src="https://forum.manjaro.org/uploads/default/original/3X/8/8/8807d849adabf5186077586be54980ce0a22c4d1.jpeg" alt="image" data-base62-sha1="jpnK6bYIeO3pP4VGcnd3nxlEQjT" width="640" height="360"></p>
<p><em>Checkout the <a href="https://manjaro.myspreadshop.net/">store</a>. From 21st till 24th we offer <strong>free standard shipping</strong>!</em></p>
<ul><li>
<strong>Cinnamon</strong> 5.4 series saw a lot of updates</li>
<li>
<strong>Game-Addons</strong> for <strong>Kodi</strong> got renewed</li>
<li>
<strong>Pipewire</strong> <a href="https://gitlab.freedesktop.org/pipewire/pipewire/-/releases/0.3.56">0.3.56</a> brings more regression fixes</li>
<li>Regular <strong>KDE-git</strong>, <strong>Haskell</strong> and <strong>Python</strong> updates</li>
</ul><h2>
<a name="additional-info-1" class="anchor" href="https://forum.manjaro.org/#additional-info-1"></a>Additional Info</h2>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2022-07-20-cinnamon-5-4-kodi-game-addons-pipewire-0-3-56-kde-git/117094/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr><p><strong>Our current supported kernels</strong></p>
<ul><li>linux419 4.19.252</li>
<li>linux54 5.4.206</li>
<li>linux510 5.10.131</li>
<li>linux515 5.15.55</li>
<li>linux517 5.17.15 (EOL)</li>
<li>linux518 5.18.12</li>
<li>linux519 5.19-rc6</li>
<li>linux515-rt 5.15.49_rt47</li>
<li>linux518-rt 5.18.0_rt11</li>
</ul><p><strong>Package Changes</strong> (Wed Jul 20 05:40:34 CEST 2022)</p>
<ul><li>testing core x86_64:  4 new and 4 removed package(s)</li>
<li>testing multilib x86_64:  8 new and 9 removed package(s)</li>
<li>testing extra x86_64:  54 new and 55 removed package(s)</li>
<li>testing community x86_64:  199 new and 194 removed package(s)</li>
</ul><p><strong>Overlay Package Changes</strong></p>
<ul><li>testing kde-unstable x86_64:  67 new and 67 removed package(s)</li>
<li>testing extra x86_64:  0 new and 1 removed package(s)</li>
<li>testing community x86_64:  2 new and 2 removed package(s)</li>
</ul><pre><code class="lang-auto">:: Different overlay package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-17           2022-07-20
-------------------------------------------------------------------------------
                            cinnamon              5.4.2-1              5.4.3-1
                      discord-canary            0.0.136-1                    -
                           os-prober               1.79-1               1.81-1


:: Different sync package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-17           2022-07-20
-------------------------------------------------------------------------------
                             absl-py              1.1.0-1                    -
                             aegisub             3.2.2-51             3.2.2-52
                        ansible-core             2.13.1-1             2.13.2-1
                                apko              0.4.0-1              0.5.0-1
                             baresip              2.5.0-1              2.5.1-1
                           benchmark              1.6.1-2              1.6.2-1
                           bitwarden           2022.6.2-1           2022.6.2-2
                       bitwarden-cli           2022.6.2-1           2022.6.2-2
                             blueman              2.2.5-1              2.3.1-1
                      budgie-desktop             10.6.1-1             10.6.2-1
                             calibre             5.44.0-1              6.1.0-1
                          cargo-edit              0.9.1-1             0.10.1-1
                             catfish             4.16.3-2             4.16.4-1
                               chafa             1.10.3-1             1.12.0-1
                             chezmoi             2.18.1-1             2.19.0-1
             cinnamon-control-center              5.4.3-1              5.4.4-1
                    cinnamon-desktop              5.4.0-1              5.4.1-1
                cinnamon-screensaver              5.4.0-1              5.4.1-1
            cinnamon-settings-daemon              5.4.1-1              5.4.2-1
                                 cjs              5.4.0-1              5.4.1-1
                                code             1.69.1-1             1.69.2-1
                              codec2            1:1.0.4-1            1:1.0.5-1
                              consul             1.12.2-1             1.12.3-1
                               copyq              6.2.0-1              6.2.0-2
                                croc              9.5.6-1              9.6.0-1
                             curtail              1.3.0-1              1.3.1-1
                              dagger             0.2.23-1             0.2.24-1
                      discord-canary            0.0.135-1            0.0.136-1
                              drupal              9.2.9-2              9.4.2-1
                         easyeffects              6.2.6-2              6.2.7-1
                              eslint             8.19.0-1             8.20.0-1
                            evilginx              2.4.0-1              2.4.0-2
                              fabric              2.7.0-1              2.7.1-1
                            geogebra          6.0.720.0-1          6.0.721.0-1
                                  go           2:1.18.3-1           2:1.18.4-1
                            go-tools           4:0.1.11-1           4:0.1.11-2
                               gopls              0.9.0-1              0.9.1-1
                      grafana-zabbix              4.2.8-1              4.2.9-1
                                grpc             1.47.0-1             1.47.1-1
                            grpc-cli             1.47.0-1             1.47.1-1
                               gtest             1.12.0-2             1.12.1-1
                       haskell-brick               0.69-5             0.69.1-1
                haskell-summoner-tui          2.0.1.1-374          2.0.1.1-375
                              hepmc2            2.06.11-1            2.06.11-2
                        hledger-iadd            1.3.17-59            1.3.17-60
                          hledger-ui              1.25-85              1.25-86
                              hwinfo              21.81-1              21.82-1
                               icewm              2.9.7-1              2.9.8-1
                              icmake            9.03.01-1            9.03.01-2
                                 inn              2.6.4-5              2.7.0-1
     intellij-idea-community-edition         4:2022.1.3-1         4:2022.1.4-1
 kodi-addon-game-libretro-beetle-psx          0.9.44.38-6          0.9.44.40-1
    kodi-addon-game-libretro-desmume           0.0.1.17-8           0.0.1.20-1
   kodi-addon-game-libretro-gambatte           0.5.0.31-6           0.5.0.33-1
    kodi-addon-game-libretro-melonds           0.9.3.27-6           0.9.3.29-1
       kodi-addon-game-libretro-mgba          0.10.0.34-6          0.10.0.35-1
   kodi-addon-game-libretro-nestopia          1.51.1.24-6          1.51.1.26-1
kodi-addon-game-libretro-parallel-n64          2.0.0.21-6           2.0.0.23-1
    kodi-addon-game-libretro-scummvm           2.1.1.23-6           2.1.1.25-1
     kodi-addon-game-libretro-snes9x          1.61.0.32-6          1.61.0.34-1
    kodi-addon-game-libretro-yabause          0.9.15.37-6          0.9.15.39-1
               kvantum-theme-materia           20220607-1           20220714-1
                        languagetool                5.7-1                5.8-1
                       libafterimage               1.20-5               1.20-6
                          libclastfm                0.5-6                0.5-7
                       libimagequant             2.17.0-3              4.0.0-1
                              libluv           1.43.0_0-1           1.44.2_0-1
                     libmusicbrainz5              5.1.0-4              5.1.0-5
                 lua-language-server              3.4.2-1              3.5.0-1
                             lua-luv           1.43.0_0-1           1.44.2_0-1
                           lua51-luv           1.43.0_0-1           1.44.2_0-1
                           lua52-luv           1.43.0_0-1           1.44.2_0-1
                           lua53-luv           1.43.0_0-1           1.44.2_0-1
                         materia-kde           20220607-1           20220714-1
                               maude                3.1-1              3.2.1-1
                             menyoki              1.6.0-1              1.6.1-1
                          metasploit              6.2.5-1              6.2.7-1
                               mmctl              7.0.1-1              7.1.0-1
                     molecule-docker              1.1.0-2              2.0.0-1
                              muffin              5.4.1-1              5.4.2-1
                                nemo              5.4.0-1              5.4.1-1
                      nemo-audio-tab              5.4.0-1              5.4.1-1
                        nemo-emblems              5.4.0-1              5.4.1-1
                     nemo-fileroller              5.4.0-1              5.4.1-1
                nemo-image-converter              5.4.0-1              5.4.1-1
                       nemo-pastebin              5.4.0-1              5.4.1-1
                        nemo-preview              5.4.0-1              5.4.1-1
                         nemo-python              5.4.0-1              5.4.1-1
                       nemo-seahorse              5.4.0-1              5.4.1-1
                          nemo-share              5.4.0-1              5.4.1-1
                       nemo-terminal              5.4.0-1              5.4.1-1
                             nerdctl             0.21.0-1             0.22.0-1
                           nextcloud             24.0.2-1             24.0.3-1
                                 nix             2.10.1-1             2.10.3-1
                            nix-docs             2.10.1-1             2.10.3-1
                               nomad              1.3.1-1              1.3.2-1
                 nomad-driver-podman              0.3.0-2              0.4.0-1
                            openfire              4.7.1-1              4.7.2-1
                            openrct2              0.4.0-1              0.4.1-1
                               opera       89.0.4447.48-1       89.0.4447.51-1
                              ospray             2.10.0-2             2.10.0-3
                  perl-finance-quote               1.51-3               1.52-1
                           perl-json               4.06-1               4.07-1
                     perl-json-parse               0.61-1               0.62-1
                            perl-ppi              1.274-2              1.275-1
               perl-software-license           0.104001-2           0.104002-1
                  perl-www-mechanize               2.08-1               2.10-1
                        perl-yaml-pp              0.032-1              0.034-1
                            php-grpc             1.47.0-1             1.47.1-1
                         php-mongodb             1.13.0-2             1.14.0-1
                           php7-grpc             1.47.0-1             1.47.1-1
                        php7-mongodb             1.13.0-2             1.14.0-1
                             pkgdiff              1.7.2-3              1.7.2-4
                            polymake                4.6-6                4.7-1
                         python-aaf2              1.5.0-1              1.6.0-1
                       python-bleach              5.0.0-1              5.0.1-1
                       python-celery              5.2.1-1              5.2.7-1
                 python-cinderclient              8.3.0-1              9.0.0-1
                   python-darkdetect              0.6.0-1              0.7.1-1
              python-designateclient              4.5.1-1              5.0.0-1
                      python-distlib              0.3.4-1              0.3.5-1
                      python-dropbox            11.32.0-1            11.33.0-1
                     python-eventlet             0.33.0-2             0.33.1-1
               python-fastjsonschema             2.15.3-1             2.16.1-1
                python-flask-htmlmin              2.1.0-2              2.2.0-1
                python-flask-migrate              3.0.0-3              3.1.0-1
               python-flask-paranoid                0.2-8              0.3.0-1
           python-flask-security-too              4.1.3-1              4.1.4-1
               python-flask-socketio              5.1.1-1              5.2.0-1
                    python-flask-wtf              1.0.0-1              1.0.1-1
                       python-grpcio             1.47.0-1             1.47.1-1
                   python-heatclient              2.5.1-1              3.0.0-1
                      python-inflect              5.6.1-1              5.6.2-1
                     python-jupymake               0.9-13               0.9-14
                   python-listparser               0.18-5               0.19-1
                     python-markdown              3.3.7-1              3.4.1-1
                  python-mygpoclient                1.8-9                1.9-1
                python-neutronclient              7.8.0-1              8.0.0-1
                        python-nose2             0.11.0-1             0.12.0-1
                       python-orjson              3.7.7-1              3.7.8-1
                       python-owslib             0.25.0-1             0.26.0-1
        python-pallets-sphinx-themes              2.0.1-4              2.0.2-1
                         python-perf              2.3.0-1              2.3.1-1
                python-podcastparser              0.6.7-3              0.6.8-1
                     python-pydrive2             1.10.1-1             1.12.1-1
                        python-pyjwt              2.2.0-3              2.4.0-1
               python-pytest-aiohttp              0.3.0-8              1.0.4-1
                  python-simplebayes              1.5.7-9              1.5.8-1
     python-sphinx-autodoc-typehints             1.12.0-1             1.13.1-1
                python-sphinx-issues              1.2.0-7              3.0.1-1
                  python-swiftclient              4.0.0-1              4.0.1-1
                      python-tempora              5.0.1-2              5.0.2-1
                                qgis             3.24.3-2             3.26.0-1
                            radicale              3.1.7-1              3.1.8-1
                              reaper               6.63-1               6.64-1
                               redis              7.0.3-1              7.0.4-1
                         release-cli             0.11.0-2             0.13.0-1
                              revive              1.1.4-2              1.2.1-1
                            rofimoji              5.4.0-3              5.5.0-1
                       roundcubemail              1.5.2-2              1.5.3-1
                        ruby-bundler             2.3.15-1             2.3.17-1
                       rust-analyzer           20220711-1           20220718-1
                        rxvt-unicode               9.26-3               9.30-1
               rxvt-unicode-terminfo               9.26-3               9.30-1
                               scite              5.2.3-1              5.2.4-1
                           seamonkey            2.53.12-1            2.53.13-1
                         singularity               1.00-4               1.00-5
                            sqlfluff              1.1.0-1              1.2.1-1
                         sstp-client           1:1.0.16-1           1:1.0.17-1
                          strawberry              1.0.5-2              1.0.6-1
                             stunnel               5.64-1               5.65-1
                         superslicer         1:2.4.58.2-3         1:2.4.58.3-1
                            supertux              0.6.3-2              0.6.3-3
                              swappy              1.4.0-1              1.4.0-2
                    systembus-notify                1.1-1                1.1-2
                             taskell           1.11.4-188           1.11.4-189
                         tensorboard              2.9.1-1              2.9.1-2
                                tepl              6.1.2-1            1:6.0.2-1
                     translate-shell           0.9.6.12-2           0.9.6.12-3
                              tt-rss 2:r11220.b59bde7b4-1 2:r11325.8f19423c2-1
                   ttf-sarasa-gothic             0.36.6-1             0.36.7-1
         v2ray-domain-list-community     20220715033720-1     20220719055203-1
                         vaultwarden             1.25.0-1             1.25.1-1
                     vaultwarden-web           2022.6.0-1           2022.6.2-1
                           veracrypt             1.25.9-2             1.25.9-3
                             wesnoth           1:1.16.4-1           1:1.16.5-1
                           wxsqlite3              4.7.8-2              4.8.2-1
                                xapp             2.2.12-1             2.2.13-1
                           xbindkeys              1.8.7-2              1.8.7-3
                           xlockmore               5.69-1               5.70-1
                         xsecurelock              1.7.0-1              1.7.0-2
                              yt-dlp         2022.06.29-1         2022.07.18-1
                                  zk             0.11.0-1             0.11.1-1
                                zola             0.15.3-1             0.16.0-2
                            corectrl                    -              1.2.4-2
                      gtksourceview3               - 1:3.24.11+r28+g73e57b57-1
                        kdesrc-build                    -              22.07-1
                           libptytty                    -                2.0-4
                         python-absl                    -              1.1.0-2
       python-sphinx-bootstrap-theme                    -              0.8.1-3


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-17           2022-07-20
-------------------------------------------------------------------------------
                              hdparm               9.63-2               9.64-1
                             libldap              2.6.2-2              2.6.3-1
                         nilfs-utils              2.2.8-2              2.2.9-1
                            openldap              2.6.2-2              2.6.3-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-17           2022-07-20
-------------------------------------------------------------------------------
                           libnotify              0.8.0-2                    -


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-17           2022-07-20
-------------------------------------------------------------------------------
                  alsa-card-profiles           1:0.3.55-2           1:0.3.56-1
                                celt             0.11.3-4                    -
                                gcab                1.4-1                1.4-2
                                 gcr             3.41.0-2             3.41.1-1
                              gmime3              3.2.7-1             3.2.12-1
                         gnome-menus             3.36.0-1             3.36.0-2
                             gnuplot              5.4.3-6              5.4.4-1
                       gnuplot-demos              5.4.3-6              5.4.4-1
                            graphviz              4.0.0-1              5.0.0-1
                 gst-plugin-pipewire           1:0.3.55-2           1:0.3.56-1
                      gtksourceview3 3.24.11+28+g73e57b57-1                  -
                 ibus-typing-booster            2.15.25-1             2.17.1-1
                               imake              1.0.8-3              1.0.8-4
                              jasper              3.0.4-1              3.0.6-1
                          jasper-doc              3.0.4-1              3.0.6-1
                     lib32-rust-libs           1:1.62.0-1           1:1.62.1-1
                             libbs2b              3.1.0-7              3.1.0-8
                     libcryptui 3.12.2+55+ged3b12af-1 1:3.12.2+r69+g9c70a43b-1
                           libmikmod           3.3.11.1-4           3.3.11.1-6
                           libnotify              0.8.0-2              0.8.1-1
                                meld             3.20.4-2             3.21.2-1
                              mpg123             1.29.3-2             1.30.1-1
              perl-crypt-openssl-rsa               0.32-2               0.33-1
                   perl-crypt-ssleay           0.73_04-16            0.73_06-1
                            pipewire           1:0.3.55-2           1:0.3.56-1
                       pipewire-alsa           1:0.3.55-2           1:0.3.56-1
                       pipewire-docs           1:0.3.55-2           1:0.3.56-1
                       pipewire-jack           1:0.3.55-2           1:0.3.56-1
                      pipewire-pulse           1:0.3.55-2           1:0.3.56-1
                       pipewire-v4l2           1:0.3.55-2           1:0.3.56-1
                   pipewire-x11-bell           1:0.3.55-2           1:0.3.56-1
                   pipewire-zeroconf           1:0.3.55-2           1:0.3.56-1
                          prometheus             2.36.2-1             2.37.0-1
                          protobuf-c              1.4.0-4              1.4.1-1
                               rtkit               0.13-1               0.13-2
                                rust           1:1.62.0-1           1:1.62.1-1
                           rust-musl           1:1.62.0-1           1:1.62.1-1
                            rust-src           1:1.62.0-1           1:1.62.1-1
                           rust-wasm           1:1.62.0-1           1:1.62.1-1
                               samba             4.16.2-1             4.16.3-1
                                 sbc                1.5-2                2.0-1
              seahorse-nautilus 3.11.92+66+g02c81f1-1 1:3.11.92+r88+g86214b8-1
                                 sip              6.6.2-2              6.6.2-3
                           smbclient             4.16.2-1             4.16.3-1
                               woff2              1.0.2-3              1.0.2-4
                    wxwidgets-common              3.2.0-2              3.2.0-4
                      wxwidgets-gtk3              3.2.0-2              3.2.0-4
                       wxwidgets-qt5              3.2.0-2              3.2.0-4
                  xdg-desktop-portal             1.14.4-1             1.14.5-1
                        zabbix-agent              6.0.5-1              6.2.0-1
                       zabbix-agent2              6.0.5-1              6.2.0-1
                 zabbix-frontend-php              6.0.5-1              6.2.0-1
                        zabbix-proxy              6.0.5-1              6.2.0-1
                       zabbix-server              6.0.5-1              6.2.0-1
                      zita-alsa-pcmi              0.4.0-1              0.5.1-1
                            gcr-docs                    -             3.41.1-1

:: Different overlay package(s) in repository kde-unstable x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-17           2022-07-20
-------------------------------------------------------------------------------
                    akonadi-calendar22.04.3.r2141.g3aea1a4-122.04.3.r2142.gd82e700-1
                    akonadi-contacts22.04.3.r3228.gaae941f7-122.04.3.r3229.ge11e12c3-1
                           alligator 22.06.r21.gd6f7dc5-1 22.06.r22.ge37b88b-1
                            analitza22.04.3.r2352.gb312e7db-122.04.3.r2355.g4637e049-1
                           angelfish 22.06.r20.g4e294ff-1 22.06.r21.g4ab1280-1
                                 ark22.04.3.r4818.g59745c8f-122.04.3.r4820.g239f99d3-1
                         audiocd-kio22.04.3.r1090.gb36c01e-122.04.3.r1092.g5818940-1
                       baloo-widgets22.04.3.r762.g66425c4-122.04.3.r763.gf93b9a3-1
                              breeze5.25.3.r2430.g224f6c37-15.25.3.r2431.gd012df4e-1
                           calindori  22.06.r7.g53c09da-1  22.06.r8.g8553328-1
                              cantor22.04.3.r3366.gc9d7b646-122.04.3.r3368.g4efa9889-1
                           itinerary22.04.3.r1951.g6c85057-122.04.3.r1956.g302bdf8-1
                                 juk22.04.3.r3166.ge471f665-122.04.3.r3167.g03eb4fc3-1
                                kalk  22.06.r8.g7626461-1  22.06.r9.g52b84ad-1
                             kalzium22.04.3.r4370.g254ff1d8-122.04.3.r4373.gfc36b715-1
                               kasts 22.06.r27.gce45074-1 22.06.r29.g91de33f-1
                                kate22.04.3.r19238.g2403075c3-122.04.3.r19242.gf6743520d-1
                              kclock 22.06.r13.g882a72a-1 22.06.r14.g16989c8-1
                             kconfig5.96.0.r964.gd96f19bc-15.96.0.r965.g491f5464-1
                      kdebugsettings22.04.3.r944.ge4f6a25-122.04.3.r946.g5f5c562-1
                                kded5.96.0.r467.gc7a921a-15.96.0.r468.gec9f232-1
                       kdepim-addons22.04.3.r4720.g59b1456d0-122.04.3.r4721.g5eedfcb9c-1
                    kdeplasma-addons5.25.3.r8930.g0d3c669f0-15.25.3.r8931.g7be911900-1
                            keysmith  22.06.r7.gdc845ae-1  22.06.r8.gb74e529-1
                            khangman22.04.3.r1618.gb49b93f-122.04.3.r1619.gca39294-1
                         khelpcenter22.04.3.r2757.g460a5dff-122.04.3.r2758.g1cfa9d78-1
                            khotkeys5.25.3.r2149.g831ed9e-15.25.3.r2151.g292cd1d-1
                         kinfocenter5.25.3.r2123.gc9e7a6cb-15.25.3.r2124.ge928b457-1
                                 kio5.96.0.r5587.gb323a33c9-15.96.0.r5588.g125977a27-1
                          kio-extras22.04.3.r7298.g52a56adc-122.04.3.r7299.g850d9af0-1
                           kleopatra22.04.3.r6676.ged516693-122.04.3.r6677.ga9a3f23b-1
                           kmahjongg22.04.3.r1559.g96f1bbf-122.04.3.r1565.g6d8fc1b-1
                              knotes22.04.3.r3678.ga5bdec93-122.04.3.r3679.g8a127759-1
                                koko  22.06.r6.gdd9222a-1  22.06.r7.g7152f6c-1
                            kongress  22.06.r5.gbaa77e7-1  22.06.r6.gd325480-1
                        konversation22.04.3.r9130.g08bfe884-122.04.3.r9131.g4d441ef8-1
                            kpackage5.96.0.r758.g2cc209e-15.96.0.r759.ge8b40d7-1
                           krecorder  22.06.r8.gb303c3b-1  22.06.r9.g182d96f-1
                                krfb22.04.3.r1507.g2cd15b6-122.04.3.r1511.g5173e7f-1
                            kservice5.96.0.r1023.g5b12b2d-15.96.0.r1024.g7b06291-1
                               ktrip  22.06.r7.g6c20cf6-1  22.06.r8.g162e6ef-1
                            kwayland5.96.0.r1170.ge5fda97-15.96.0.r1172.g5227e3f-1
                            kweather 22.06.r15.g1d904fb-1 22.06.r16.gc572d1b-1
                                kwin5.25.3.r22762.ge801819a2-15.25.3.r22771.ga0c8d4b24-1
                              kwrite22.04.3.r19238.g2403075c3-122.04.3.r19242.gf6743520d-1
                             neochat22.06.r43.gf80039a5-122.06.r47.ga7504876-1
                              oxygen5.25.3.r4497.g489752e0-15.25.3.r4499.g84305086-1
                    plasma-bigscreen      r486.g8952b8f-1      r487.g95c8e34-1
          plasma-browser-integration5.25.3.r1338.g5b57c8be-15.25.3.r1339.g3ba5d473-1
                      plasma-desktop5.25.3.r9428.g582571ad2-15.25.3.r9437.g292b5c635-1
                       plasma-dialer 22.06.r15.g5714110-1 22.06.r16.gf6cf597-1
                        plasma-disks5.25.3.r285.gd2e6d02-15.25.3.r286.g3f58a5f-1
                       plasma-mobile5.25.3.r1911.g29d5afaac-15.25.3.r1912.g5a9802ae5-1
                    plasma-phonebook  22.06.r4.gd3c3687-1  22.06.r5.g62a98d0-1
                     plasma-settings 22.06.r29.gaed5bc7-1 22.06.r30.g1e6d45b-1
                plasma-systemmonitor5.25.3.r594.g30b8d8b-15.25.3.r595.ga6b72e0-1
              plasma-wayland-session5.25.3.r12082.gc07d105ad-15.25.3.r12087.g6ec7a9f0a-1
                    plasma-workspace5.25.3.r12082.gc07d105ad-15.25.3.r12087.g6ec7a9f0a-1
         plasma-workspace-wallpapers5.25.3.r360.g7705661-15.25.3.r361.g2c96c7a-1
                          plasmatube  22.06.r6.g858abe4-1  22.06.r7.g07b6f24-1
                       print-manager22.04.3.r1145.g5d29881-122.04.3.r1147.g66eda1f-1
                             purpose5.96.0.r983.ge4ae404-15.96.0.r984.g51e3a30-1
                          qmlkonsole  22.06.r9.g3b1160f-1 22.06.r10.ga75f5ab-1
                               solid5.96.0.r783.gc6adb1e-15.96.0.r784.g8c9ad6a-1
                           spectacle22.04.3.r1373.gba86116-122.04.3.r1374.gf32cc2f-1
                             tokodon 22.06.r13.g21aae2b-1 22.06.r14.g565052f-1
                         vakzination  22.06.r9.g872245a-1 22.06.r10.gdaac6be-1


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2022-07-17           2022-07-20
-------------------------------------------------------------------------------
                          lib32-celt             0.11.3-4                    -
                       lib32-libldap              2.6.2-1              2.6.3-1
                     lib32-libmikmod           3.3.11.1-5           3.3.11.1-6
                         lib32-libnl              3.6.0-1              3.7.0-1
                        lib32-mpg123             1.29.3-1             1.30.1-1
                      lib32-pipewire           1:0.3.55-2           1:0.3.56-1
                 lib32-pipewire-jack           1:0.3.55-2           1:0.3.56-1
                 lib32-pipewire-v4l2           1:0.3.55-2           1:0.3.56-1
                        wine-staging               7.12-1               7.13-1
</code></pre>
<p><a href="https://forum.manjaro.org/t/testing-update-2022-07-20-cinnamon-5-4-kodi-game-addons-pipewire-0-3-56-kde-git/117094/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul><li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul><p><small>2 posts - 1 participant</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2022-07-20-cinnamon-5-4-kodi-game-addons-pipewire-0-3-56-kde-git/117094">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ask Slashdot:  Does WebAssembly Increase Your Web Browser's Attack Surface?]]></title>
<description><![CDATA[Steve Springett is a conscientious senior security architect. And in 2018, he published an essay on GitHub arguing that from a security engineer's perspective, WebAssembly "increases the attack surface of any browser that supports it." 

Springett wrote that WebAssembly modules are sent in (unsig...]]></description>
<link>https://tsecurity.de/de/1573515/it-security-nachrichten/ask-slashdot-does-webassembly-increase-your-web-browsers-attack-surface/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1573515/it-security-nachrichten/ask-slashdot-does-webassembly-increase-your-web-browsers-attack-surface/</guid>
<pubDate>Sun, 17 Jul 2022 12:18:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Steve Springett is a conscientious senior security architect. And in 2018, he published an essay on GitHub arguing that from a security engineer's perspective, WebAssembly "increases the attack surface of any browser that supports it." 

Springett wrote that WebAssembly modules are sent in (unsigned) binary format — without a transport-layer security mechanism — and rely on browser sandboxing for safety. But the binary format makes it harder to analyze the code, while sandboxing "is prone to breakouts and effectiveness varies largely by implementation. Adobe Flash is an example of a technology that was sandboxed after a series of exploits, yet exploits and breakouts still occurred." Springett even went so far as to offer the commands for switching off WebAssembly in your browser. 

Now Tablizer (Slashdot reader #95,088) wants to know what other Slashdot readers think of Spingett's security concrens around WebAssembly. 

And also offers this suggestion to browser makers:

Browsers should have a way to easily disable WebAssembly — including whitelisting. For example, if you need it for specific gaming site, you can whitelist just that site and not have WASM exposed for other sites.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Ask+Slashdot%3A++Does+WebAssembly+Increase+Your+Web+Browser's+Attack+Surface%3F%3A+https%3A%2F%2Fbit.ly%2F3yEZvla"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fdevelopers.slashdot.org%2Fstory%2F22%2F07%2F16%2F0450218%2Fask-slashdot-does-webassembly-increase-your-web-browsers-attack-surface%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://developers.slashdot.org/story/22/07/16/0450218/ask-slashdot-does-webassembly-increase-your-web-browsers-attack-surface?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,16ms -->