| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service confidentiality. |
| Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service confidentiality. |
| Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service confidentiality |
| Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service confidentiality. |
| Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. |
| Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. |
| Use After Free (UAF) vulnerability in the office service. Successful exploitation of this vulnerability may affect service confidentiality. |
| Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. |
| Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. |
| Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verify email endpoint of all versions of Better Auth prior to v1.1.6, potentially allowing attackers to redirect users to malicious websites. This issue affects users relying on email verification links generated by the library. The verify email callback endpoint accepts a `callbackURL` parameter. Unlike other verification methods, email verification only uses JWT to verify and redirect without proper validation of the target domain. The origin checker is bypassed in this scenario because it only checks for `POST` requests. An attacker can manipulate this parameter to redirect users to arbitrary URLs controlled by the attacker. Version 1.1.6 contains a patch for the issue. |
| A Stored Cross-Site Scripting (XSS) vulnerability in the "Rules" functionality of WorldServer v11.8.2 allows a remote authenticated attacker to execute arbitrary JavaScript code. |
| An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file. |
| Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability. |
| Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability. |
| Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability. |
| Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affect availability. |
| Data processing error vulnerability in the package management module. Successful exploitation of this vulnerability may affect availability. |
| Use After Free (UAF) vulnerability in the storage management module. Successful exploitation of this vulnerability may affect availability. |
| Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect availability. |
| Buffer overflow vulnerability in the development framework module. Successful exploitation of this vulnerability may affect availability. |