CERT Coordination Center
kb.cert.org
Imported from official source
Carnegie Mellon SEI vulnerability coordination centre.
- Type
- Research institution
- Scope
- US · global
- Website
- kb.cert.org
- Feed
- Atom
Publications 26
-
VU#553437: InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations
An Out-of-bounds Write vulnerability in the InsydeH2O IHISI software used by HP PC BIOS can allow a local attacker with OS kernel privileges to perform arbitrary physical memory writes, including w...
Advisory Cybersecurity -
VU#762428: Authlib library contains a signature‑verification bypass vulnerability
Authlib (versions up to and including 1.7.2) contain a signature‑verification bypass in the JSON Web Signature (JWS) general JSON serialization handling. The JsonWebSignature.deserialize_json() fun...
Advisory Cybersecurity -
VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities
Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.7.2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exp...
Advisory Cybersecurity -
VU#234131: ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise
ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise. ViewSonic ViewBoards a...
Advisory Cybersecurity -
VU#676317: Norwegian Cruise Line door access controller contains an improper authentication vulnerability
Door access controllers used on Norwegian Cruise Line (NCL) ships contain an improper authentication vulnerability that permits a replayed unique identifer (UID) from a radio-frequency identificati...
-
VU#273940: Enterprise Access Management EAM does not rotate RSA keys
Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The prod...
-
VU#754548: Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers
Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or ov...
-
VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass
Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate...
-
VU#280377: Dokploy is vulnerable to OS command injection
Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. The vulnerability s...
-
VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control
Two vulnerabilities in MLflow’s dspy and statsmodels model flavors allow unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies...
-
VU#212479: Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment
A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution withi...
-
VU#369611: ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index
An out-of-bounds (OOB) memory access vulnerability involving unchecked array indexing has been identified in the exllamav3_ext compute unified device architecture (CUDA) extension. Successful explo...
-
VU#687587: AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks
An incorrect permissions assignment vulnerability in the amwrtdrv.sys kernel driver, included with AOMEI Backupper 8.4.0, allows an unprivileged local user to perform arbitrary writes to the physic...
-
VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot
The UEFI Shell program may expose raw memory access capabilities that, if present in platform firmware for debugging or advanced support use cases, could be abused to undermine UEFI Secure Boot pro...
-
VU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability
Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed int...
-
VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability
A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate ...
-
VU#889462: Casdoor authentication server is vulnerable to authorization bypass
Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability affects Casdoor versions up to v4.2.0. The vulnerability allows a n...
-
VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check
A vulnerability in the Hugging Face Transformers library (versions 4.57.0 to 5.16.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The ...
-
VU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers
Overview The Kaltura HTML5 Player V2 Library (mwEmbed / html5lib) contains two vulnerabilities, both involving the same insecure deserialization flaw, that enable arbitrary file read and remote cod...
-
VU#728712: Konami's Metal Gear Online 3 contains a heap-based buffer overflow
Overview Konami's Metal Gear Online 3 video game contains a heap-based buffer overflow that can be triggered by an input‑validation vulnerability that allows match hosts to remotely execute arbitra...
-
VU#756733: Retraction of "Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability"
Overview The Calix GS7 XGS GS5239XG router running firmware EXOS/6.6.47 contains a missing authentication vulnerability that exposes its UPnP (Universal Plug and Play) WANIPConnection service on th...
-
VU#874418: RDK-B WebUI contains multiple vulnerabilities
Overview RDK Central RDK-B WebUI version, rdkb-2025q4-kirkstone, contains multiple vulnerabilities involving memory corruption, improper authentication, race conditions, and insufficient input vali...
-
VU#431093: TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks
Overview Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys. CVE-2026-6727 – A ti...
-
VU#614868: OpenCart ecommerce platform contains directory traversal vulnerability
Overview The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as...
Advisory Cybersecurity -
VU#987105: The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability
Overview A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to ...
Advisory Cybersecurity -
VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations
Overview A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iC...
Advisory Cybersecurity