| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending it to the attacker-controlled server. DICOMweb data sources are not impacted. |
| A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api reads the target IP from vmi.Status.Interfaces[0].IP and passes it directly to net.Dial() without validation. For VMIs using non-masquerade network bindings (bridge or secondary-only), this IP is reported by the QEMU guest agent running inside the VM and is fully controllable by the VM owner. An attacker with kubevirt.io:edit permissions can create a VM with a modified guest agent that reports an arbitrary IP address, then request port-forward to establish a bidirectional TCP tunnel from virt-api's cluster-internal network position to any routable destination, bypassing NetworkPolicy isolation. |
| remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability. |
| An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no permissions) to force arbitrary file downloads into the app's scoped storage. The resulting files appear in the application's trusted Received interface. These conditions establish a vector for arbitrary code execution if the payload is an APK file, or a denial-of-service condition through resource exhaustion from oversized transfers. |
| An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensitive information via supplying a crafted HTTP request. |
| An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request. |
| A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl. |
| Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine. |
| Unauthenticated Local File Inclusion in Modernee <= 1.6.0 versions. |
| Unauthenticated Local File Inclusion in Planty <= 1.14.0 versions. |
| Unauthenticated Local File Inclusion in Nexio <= 1.10.0 versions. |
| Unauthenticated Local File Inclusion in MaxiNet <= 1.2.10 versions. |
| Unauthenticated Local File Inclusion in Iona <= 1.0.8 versions. |
| Unauthenticated Local File Inclusion in CopyPress <= 1.4.5 versions. |
| Unauthenticated Local File Inclusion in Especio <= 1.0 versions. |
| Unauthenticated Local File Inclusion in Abelle <= 1.22 versions. |
| Unauthenticated Local File Inclusion in Mission <= 1.22 versions. |
| Unauthenticated Local File Inclusion in Dom <= 1.24 versions. |
| Unauthenticated Local File Inclusion in Putter <= 1.17 versions. |
| Unauthenticated Local File Inclusion in Medeus <= 1.14 versions. |