================================================================================
 QUERY RESULT COMPARISON: COSINE vs TAUMODE
================================================================================

QUERY TYPE: BEST QUERY (Highest Top Score)
QUERY TEXT: integer overflow leading to heap corruption in video codec
--------------------------------------------------------------------------------
RANK 1:
  [Cosine] Score: 0.8789
           Title: Docker Desktop for Windows Incorrect Permission Assignment Privilege Escalation Vulnerabilities
           Text:  CVE-2025-14740 | Docker Desktop for Windows Incorrect Permission Assignment Privilege Escalation Vulnerabilities | Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling of the C:\ProgramData\DockerDesktop directory. The installer cre...

  [taumode] Score: 0.9491
            Title: Docker Desktop for Windows Incorrect Permission Assignment Privilege Escalation Vulnerabilities
            Text:  CVE-2025-14740 | Docker Desktop for Windows Incorrect Permission Assignment Privilege Escalation Vulnerabilities | Docker Desktop for Windows contains multiple incorrect permission assignment vulnerabilities in the installer's handling of the C:\ProgramData\DockerDesktop directory. The installer cre...
----------------------------------------
RANK 2:
  [Cosine] Score: 0.8726
           Title: (no title)
           Text:  CVE-2026-24516 | A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner component (internal/troubleshooting/actioner/actioner.go) processes metadata from the metadata service endpoint and executes commands specified in the TroubleshootingAg...

  [taumode] Score: 0.9456
            Title: OS Command Injection in Chamilo LMS 1.11.36
            Text:  CVE-2026-32892 | OS Command Injection in Chamilo LMS 1.11.36 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path val...
----------------------------------------
RANK 3:
  [Cosine] Score: 0.8705
           Title: OS Command Injection in Chamilo LMS 1.11.36
           Text:  CVE-2026-32892 | OS Command Injection in Chamilo LMS 1.11.36 | Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains an OS Command Injection vulnerability in the file move function. The move() function in fileManage.lib.php passes user-controlled path val...

  [taumode] Score: 0.9437
            Title: ceph: fix multifs mds auth caps issue
            Text:  CVE-2025-40362 | ceph: fix multifs mds auth caps issue | In the Linux kernel, the following vulnerability has been resolved:  ceph: fix multifs mds auth caps issue  The mds auth caps check should also validate the fsname along with the associated caps. Not doing so would result in applying the mds a...
----------------------------------------
RANK 4:
  [Cosine] Score: 0.8660
           Title: ceph: fix multifs mds auth caps issue
           Text:  CVE-2025-40362 | ceph: fix multifs mds auth caps issue | In the Linux kernel, the following vulnerability has been resolved:  ceph: fix multifs mds auth caps issue  The mds auth caps check should also validate the fsname along with the associated caps. Not doing so would result in applying the mds a...

  [taumode] Score: 0.9431
            Title: Cryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC paths
            Text:  CVE-2026-32310 | Cryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC paths | Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault configuration is parsed before its integrity is verified, and the masterkeyfile ...
----------------------------------------
RANK 5:
  [Cosine] Score: 0.8649
           Title: Cryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC paths
           Text:  CVE-2026-32310 | Cryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC paths | Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault configuration is parsed before its integrity is verified, and the masterkeyfile ...

  [taumode] Score: 0.9430
            Title: argo-workflows Zip Slip path traversal allows arbitrary file write and container configuration overwrite
            Text:  CVE-2025-62156 | argo-workflows Zip Slip path traversal allows arbitrary file write and container configuration overwrite | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 conta...
----------------------------------------
RANK 6:
  [Cosine] Score: 0.8645
           Title: argo-workflows Zip Slip path traversal allows arbitrary file write and container configuration overwrite
           Text:  CVE-2025-62156 | argo-workflows Zip Slip path traversal allows arbitrary file write and container configuration overwrite | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Versions prior to 3.6.12 and versions 3.7.0 through 3.7.2 conta...

  [taumode] Score: 0.9427
            Title: B2 Command Line Tool TOCTOU application key disclosure 
            Text:  CVE-2022-23653 | B2 Command Line Tool TOCTOU application key disclosure  | B2 Command Line Tool is the official command line tool for the backblaze cloud storage service. Linux and Mac releases of the B2 command-line tool version 3.2.0 and below contain a key disclosure vulnerability that, in certai...
----------------------------------------
RANK 7:
  [Cosine] Score: 0.8636
           Title: B2 Command Line Tool TOCTOU application key disclosure 
           Text:  CVE-2022-23653 | B2 Command Line Tool TOCTOU application key disclosure  | B2 Command Line Tool is the official command line tool for the backblaze cloud storage service. Linux and Mac releases of the B2 command-line tool version 3.2.0 and below contain a key disclosure vulnerability that, in certai...

  [taumode] Score: 0.9410
            Title: (no title)
            Text:  CVE-2020-5846 | An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with the base64-encoded pathname in the X-RSW-custom-encode-path HTTP header, and the content in the HTTP request body. It is possible to upl...
----------------------------------------
RANK 8:
  [Cosine] Score: 0.8597
           Title: (no title)
           Text:  CVE-2020-5846 | An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.3.0.30 via a "PUT /obs/obm7/file/upload" request with the base64-encoded pathname in the X-RSW-custom-encode-path HTTP header, and the content in the HTTP request body. It is possible to upl...

  [taumode] Score: 0.9405
            Title: Canto <= 3.1.1 - Missing Authorization to Unauthenticated File Upload
            Text:  CVE-2026-3335 | Canto <= 3.1.1 - Missing Authorization to Unauthenticated File Upload | The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via the `/wp-content/plugins/canto/includes/lib/copy-media.php` file. This is due to the file bein...
----------------------------------------
RANK 9:
  [Cosine] Score: 0.8584
           Title: Canto <= 3.1.1 - Missing Authorization to Unauthenticated File Upload
           Text:  CVE-2026-3335 | Canto <= 3.1.1 - Missing Authorization to Unauthenticated File Upload | The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via the `/wp-content/plugins/canto/includes/lib/copy-media.php` file. This is due to the file bein...

  [taumode] Score: 0.9400
            Title: (no title)
            Text:  CVE-2019-9745 | CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This tool communicates with a service (Recognition Update Client Service) via an insecure communication channel (Named Pipe). The data (JSON) sent via this channel is used ...
----------------------------------------
RANK 10:
  [Cosine] Score: 0.8571
           Title: (no title)
           Text:  CVE-2019-9745 | CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This tool communicates with a service (Recognition Update Client Service) via an insecure communication channel (Named Pipe). The data (JSON) sent via this channel is used ...

  [taumode] Score: 0.9399
            Title: (no title)
            Text:  CVE-2025-45582 | GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a crit...
----------------------------------------
RANK 11:
  [Cosine] Score: 0.8569
           Title: (no title)
           Text:  CVE-2025-45582 | GNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the victim must extract an archive that contains a ../ symlink to a critical directory. Second, the victim must extract an archive that contains a crit...

  [taumode] Score: 0.9398
            Title: Wildfire has Arbitrary File Upload via Directory Traversal in UploadFileAction
            Text:  CVE-2025-66480 | Wildfire has Arbitrary File Upload via Directory Traversal in UploadFileAction | Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component related to the file upload functionality found in com.x...
----------------------------------------
RANK 12:
  [Cosine] Score: 0.8568
           Title: Wildfire has Arbitrary File Upload via Directory Traversal in UploadFileAction
           Text:  CVE-2025-66480 | Wildfire has Arbitrary File Upload via Directory Traversal in UploadFileAction | Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component related to the file upload functionality found in com.x...

  [taumode] Score: 0.9393
            Title: Backstage has a Possible Symlink Path Traversal in Scaffolder Actions
            Text:  CVE-2026-24046 | Backstage has a Possible Symlink Path Traversal in Scaffolder Actions | Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to cre...
----------------------------------------
RANK 13:
  [Cosine] Score: 0.8562
           Title: (no title)
           Text:  CVE-2023-22809 | In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege es...

  [taumode] Score: 0.9391
            Title: Partial path traversal vulnerability in Support Bundle feature of Graylog
            Text:  CVE-2023-41044 | Partial path traversal vulnerability in Support Bundle feature of Graylog | Graylog is a free and open log management platform. A partial path traversal vulnerability exists in Graylog's `Support Bundle` feature. The vulnerability is caused by incorrect user input validation in an H...
----------------------------------------
RANK 14:
  [Cosine] Score: 0.8556
           Title: Backstage has a Possible Symlink Path Traversal in Scaffolder Actions
           Text:  CVE-2026-24046 | Backstage has a Possible Symlink Path Traversal in Scaffolder Actions | Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to cre...

  [taumode] Score: 0.9387
            Title: Path traversal vulnerability in Simple Archive Format package import in DSpace
            Text:  CVE-2022-31195 | Path traversal vulnerability in Simple Archive Format package import in DSpace | DSpace open source software is a repository application which provides durable access to digital resources. In affected versions the ItemImportServiceImpl is vulnerable to a path traversal vulnerability...
----------------------------------------
RANK 15:
  [Cosine] Score: 0.8551
           Title: Partial path traversal vulnerability in Support Bundle feature of Graylog
           Text:  CVE-2023-41044 | Partial path traversal vulnerability in Support Bundle feature of Graylog | Graylog is a free and open log management platform. A partial path traversal vulnerability exists in Graylog's `Support Bundle` feature. The vulnerability is caused by incorrect user input validation in an H...

  [taumode] Score: 0.9383
            Title: (no title)
            Text:  CVE-2020-6754 | dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g., .jsp...
----------------------------------------
RANK 16:
  [Cosine] Score: 0.8540
           Title: Path traversal vulnerability in Simple Archive Format package import in DSpace
           Text:  CVE-2022-31195 | Path traversal vulnerability in Simple Archive Format package import in DSpace | DSpace open source software is a repository application which provides durable access to digital resources. In affected versions the ItemImportServiceImpl is vulnerable to a path traversal vulnerability...

  [taumode] Score: 0.9383
            Title: n8n Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition
            Text:  CVE-2026-33663 | n8n Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition | n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with the `global:member` role could exploit cha...
----------------------------------------
RANK 17:
  [Cosine] Score: 0.8534
           Title: n8n Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition
           Text:  CVE-2026-33663 | n8n Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypass in Community Edition | n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with the `global:member` role could exploit cha...

  [taumode] Score: 0.9382
            Title: Wazuh's vulnerability in host_deny AR script allows arbitrary command execution
            Text:  CVE-2023-50260 | Wazuh's vulnerability in host_deny AR script allows arbitrary command execution | Wazuh is a free and open source platform used for threat prevention, detection, and response. A wrong validation in the `host_deny` script allows to write any string in the `hosts.deny` file, which can...
----------------------------------------
RANK 18:
  [Cosine] Score: 0.8532
           Title: (no title)
           Text:  CVE-2020-6754 | dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g., .jsp...

  [taumode] Score: 0.9382
            Title: (no title)
            Text:  CVE-2007-0345 | The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which ...
----------------------------------------
RANK 19:
  [Cosine] Score: 0.8530
           Title: Wazuh's vulnerability in host_deny AR script allows arbitrary command execution
           Text:  CVE-2023-50260 | Wazuh's vulnerability in host_deny AR script allows arbitrary command execution | Wazuh is a free and open source platform used for threat prevention, detection, and response. A wrong validation in the `host_deny` script allows to write any string in the `hosts.deny` file, which can...

  [taumode] Score: 0.9381
            Title: Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint
            Text:  CVE-2021-32635 | Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint | Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container ...
----------------------------------------
RANK 20:
  [Cosine] Score: 0.8529
           Title: (no title)
           Text:  CVE-2007-0345 | The (1) Activity Monitor.app/Contents/Resources/pmTool, (2) Keychain Access.app/Contents/Resources/kcproxy, and (3) ODBC Administrator.app/Contents/Resources/iodbcadmintool programs in /Applications/Utilities/ in Mac OS X 10.4.8 have weak permissions (writable by admin group), which ...

  [taumode] Score: 0.9379
            Title: (no title)
            Text:  CVE-2006-3935 | system/workplace/views/admin/admin-main.jsp in Alkacon OpenCms before 6.2.2 does not restrict access to administrator functions, which allows remote authenticated users to (1) send broadcast messages to all users (/workplace/broadcast), (2) list all users (/accounts/users), (3) add w...
----------------------------------------
RANK 21:
  [Cosine] Score: 0.8526
           Title: Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint
           Text:  CVE-2021-32635 | Action Commands (run/shell/exec) Against Library URIs Ignore Configured Remote Endpoint | Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `singularity` action commands (`run`/`shell`/`exec`) specifying a container ...

  [taumode] Score: 0.9379
            Title: Missing Role Based Access Control for the REST handlers in bleve/http package
            Text:  CVE-2022-31022 | Missing Role Based Access Control for the REST handlers in bleve/http package | Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP methods pave way for exploitation of a node’s filesyst...
----------------------------------------
RANK 22:
  [Cosine] Score: 0.8523
           Title: (no title)
           Text:  CVE-2006-3935 | system/workplace/views/admin/admin-main.jsp in Alkacon OpenCms before 6.2.2 does not restrict access to administrator functions, which allows remote authenticated users to (1) send broadcast messages to all users (/workplace/broadcast), (2) list all users (/accounts/users), (3) add w...

  [taumode] Score: 0.9377
            Title: Path Traversal Vulnerability in GHOSTS Photo Retrieval Endpoint
            Text:  CVE-2025-27092 | Path Traversal Vulnerability in GHOSTS Photo Retrieval Endpoint | GHOSTS is an open source user simulation framework for cyber experimentation, simulation, training, and exercise. A path traversal vulnerability was discovered in GHOSTS version 8.0.0.0 that allows an attacker to acce...
----------------------------------------
RANK 23:
  [Cosine] Score: 0.8523
           Title: Missing Role Based Access Control for the REST handlers in bleve/http package
           Text:  CVE-2022-31022 | Missing Role Based Access Control for the REST handlers in bleve/http package | Bleve is a text indexing library for go. Bleve includes HTTP utilities under bleve/http package, that are used by its sample application. These HTTP methods pave way for exploitation of a node’s filesyst...

  [taumode] Score: 0.9376
            Title: (no title)
            Text:  CVE-2020-15843 | ActFax Version 7.10 Build 0335 (2020-05-25) is susceptible to a privilege escalation vulnerability due to insecure folder permissions on %PROGRAMFILES%\ActiveFax\Client\, %PROGRAMFILES%\ActiveFax\Install\ and %PROGRAMFILES%\ActiveFax\Terminal\. The folder permissions allow "Full Con...
----------------------------------------
RANK 24:
  [Cosine] Score: 0.8517
           Title: Path Traversal Vulnerability in GHOSTS Photo Retrieval Endpoint
           Text:  CVE-2025-27092 | Path Traversal Vulnerability in GHOSTS Photo Retrieval Endpoint | GHOSTS is an open source user simulation framework for cyber experimentation, simulation, training, and exercise. A path traversal vulnerability was discovered in GHOSTS version 8.0.0.0 that allows an attacker to acce...

  [taumode] Score: 0.9375
            Title: (no title)
            Text:  CVE-2007-6495 | inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1) db, (2) www, (3) Special, and (4) log at arbitrary locations under the web root via a modified Dirroot parameter in an AddUser action...
----------------------------------------
RANK 25:
  [Cosine] Score: 0.8516
           Title: (no title)
           Text:  CVE-2020-15843 | ActFax Version 7.10 Build 0335 (2020-05-25) is susceptible to a privilege escalation vulnerability due to insecure folder permissions on %PROGRAMFILES%\ActiveFax\Client\, %PROGRAMFILES%\ActiveFax\Install\ and %PROGRAMFILES%\ActiveFax\Terminal\. The folder permissions allow "Full Con...

  [taumode] Score: 0.9374
            Title: GitHub Action tj-actions/verify-changed-files is vulnerable to command injection in output filenames
            Text:  CVE-2023-52137 | GitHub Action tj-actions/verify-changed-files is vulnerable to command injection in output filenames | The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execut...
----------------------------------------
================================================================================

QUERY TYPE: WORST QUERY (Lowest Top Score)
QUERY TEXT: stack-based buffer overflow in DHCP client
--------------------------------------------------------------------------------
RANK 1:
  [Cosine] Score: 0.7406
           Title: (no title)
           Text:  CVE-2009-4003 | Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, leading to a heap-based buffer overflow; and might allow remote attackers to execute arbitrary code via (2) a...

  [taumode] Score: 0.8768
            Title: fbcon: fix integer overflow in fbcon_do_set_font
            Text:  CVE-2025-39967 | fbcon: fix integer overflow in fbcon_do_set_font | In the Linux kernel, the following vulnerability has been resolved:  fbcon: fix integer overflow in fbcon_do_set_font  Fix integer overflow vulnerabilities in fbcon_do_set_font() where font size calculations could overflow when hand...
----------------------------------------
RANK 2:
  [Cosine] Score: 0.7402
           Title: (no title)
           Text:  CVE-2016-3945 | Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 4.0.6 and earlier, when -b mode is enabled, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted TIFF image, which triggers...

  [taumode] Score: 0.8754
            Title: (no title)
            Text:  CVE-2009-0136 | Multiple array index errors in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via an Audible Audio (.aa) file with a crafted (1) nle...
----------------------------------------
RANK 3:
  [Cosine] Score: 0.7388
           Title: (no title)
           Text:  CVE-2012-2665 | Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a...

  [taumode] Score: 0.8754
            Title: (no title)
            Text:  CVE-2012-2800 | Unspecified vulnerability in the ff_ivi_process_empty_tile function in libavcodec/ivi_common.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors in which the "tile size ... mismatches parameters" and triggers "writing in...
----------------------------------------
RANK 4:
  [Cosine] Score: 0.7376
           Title: HID: multitouch: fix slab out-of-bounds access in mt_report_fixup()
           Text:  CVE-2025-39806 | HID: multitouch: fix slab out-of-bounds access in mt_report_fixup() | In the Linux kernel, the following vulnerability has been resolved:  HID: multitouch: fix slab out-of-bounds access in mt_report_fixup()  A malicious HID device can trigger a slab out-of-bounds during mt_report_fi...

  [taumode] Score: 0.8747
            Title: (no title)
            Text:  CVE-2012-1530 | Heap-based buffer overflow in the XSLT engine in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing an XSL file that triggers memor...
----------------------------------------
RANK 5:
  [Cosine] Score: 0.7353
           Title: (no title)
           Text:  CVE-2009-0583 | Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based ...

  [taumode] Score: 0.8726
            Title: (no title)
            Text:  CVE-2009-4003 | Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, leading to a heap-based buffer overflow; and might allow remote attackers to execute arbitrary code via (2) a...
----------------------------------------
RANK 6:
  [Cosine] Score: 0.7345
           Title: (no title)
           Text:  CVE-2012-4405 | Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code...

  [taumode] Score: 0.8725
            Title: (no title)
            Text:  CVE-2013-5688 | Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated users to read arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the file parameter in a (1) download or (2) get_content action, or (3) upload arbit...
----------------------------------------
RANK 7:
  [Cosine] Score: 0.7329
           Title: (no title)
           Text:  CVE-2009-1869 | Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an AVM2...

  [taumode] Score: 0.8725
            Title: (no title)
            Text:  CVE-2016-3945 | Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 4.0.6 and earlier, when -b mode is enabled, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted TIFF image, which triggers...
----------------------------------------
RANK 8:
  [Cosine] Score: 0.7329
           Title: HID: core: fix shift-out-of-bounds in hid_report_raw_event
           Text:  CVE-2022-48978 | HID: core: fix shift-out-of-bounds in hid_report_raw_event | In the Linux kernel, the following vulnerability has been resolved:  HID: core: fix shift-out-of-bounds in hid_report_raw_event  Syzbot reported shift-out-of-bounds in hid_report_raw_event.  microsoft 0003:045E:07DA.0001: ...

  [taumode] Score: 0.8718
            Title: (no title)
            Text:  CVE-2012-2665 | Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a...
----------------------------------------
RANK 9:
  [Cosine] Score: 0.7324
           Title: (no title)
           Text:  CVE-2006-1540 | MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated ...

  [taumode] Score: 0.8715
            Title: (no title)
            Text:  CVE-2016-9296 | A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z applications...
----------------------------------------
RANK 10:
  [Cosine] Score: 0.7319
           Title: (no title)
           Text:  CVE-2012-2795 | Multiple unspecified vulnerabilities in libavcodec/wmalosslessdec.c in FFmpeg before 0.11 have unknown impact and attack vectors related to (1) size of "mclms arrays," (2) "a get_bits(0) in decode_ac_filter," and (3) "too many bits in decode_channel_residues()." | n/a n/a...

  [taumode] Score: 0.8714
            Title: HID: multitouch: fix slab out-of-bounds access in mt_report_fixup()
            Text:  CVE-2025-39806 | HID: multitouch: fix slab out-of-bounds access in mt_report_fixup() | In the Linux kernel, the following vulnerability has been resolved:  HID: multitouch: fix slab out-of-bounds access in mt_report_fixup()  A malicious HID device can trigger a slab out-of-bounds during mt_report_fi...
----------------------------------------
RANK 11:
  [Cosine] Score: 0.7317
           Title: (no title)
           Text:  CVE-2009-0690 | The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a negative value for the stream offset in a JPEG2000 (aka JPX) stream, which allows remote attackers to cause a denial of service (memory corruption and applica...

  [taumode] Score: 0.8713
            Title: (no title)
            Text:  CVE-2012-4944 | Multiple unrestricted file upload vulnerabilities in Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary code by uploading a file via an unspecified page. | n/a n/a...
----------------------------------------
RANK 12:
  [Cosine] Score: 0.7314
           Title: (no title)
           Text:  CVE-2007-4344 | Multiple input validation errors in ACD ACDSee Photo Manager 9.0 build 108, Pro Photo Manager 8.1 build 99, and Photo Editor 4.0 build 195 allow user-assisted remote attackers to execute arbitrary code via a long section string in (1) a PSP image to the ID_PSP.apl plug-in or (2) an L...

  [taumode] Score: 0.8712
            Title: (no title)
            Text:  CVE-2012-2571 | Multiple cross-site scripting (XSS) vulnerabilities in WinWebMail Server 3.8.1.6 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a SCRIPT element, (2) a crafted Cascading Style Sheets (CSS) expression property, (3) a CSS expression pr...
----------------------------------------
RANK 13:
  [Cosine] Score: 0.7310
           Title: (no title)
           Text:  CVE-2014-9670 | Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values...

  [taumode] Score: 0.8704
            Title: (no title)
            Text:  CVE-2009-0583 | Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based ...
----------------------------------------
RANK 14:
  [Cosine] Score: 0.7306
           Title: (no title)
           Text:  CVE-2010-3000 | Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allow remote attackers to execute arbitrary code via crafted (1) HX_FLV_META_AMF_TYPE_MIXEDARRAY or (2) HX_FLV_META_AMF_TYPE_ARRAY dat...

  [taumode] Score: 0.8703
            Title: (no title)
            Text:  CVE-2009-2548 | Format string vulnerability in Armed Assault (aka ArmA) 1.14 and earlier, and 1.16 beta, and Armed Assault II 1.02 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) nickname and (2) dat...
----------------------------------------
RANK 15:
  [Cosine] Score: 0.7291
           Title: (no title)
           Text:  CVE-2009-0792 | Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based ...

  [taumode] Score: 0.8702
            Title: (no title)
            Text:  CVE-2012-5324 | Multiple buffer overflows in the Pdf Printer Preferences ActiveX Control in pdfxctrl.dll in Tracker Software PDF-XChange 3.60.0128 allow remote attackers to execute arbitrary code via a long string in the (1) sub_path parameter to the StoreInRegistry function or (2) sub_key parameter...
----------------------------------------
RANK 16:
  [Cosine] Score: 0.7290
           Title: (no title)
           Text:  CVE-2013-0003 | Buffer overflow in a System.DirectoryServices.Protocols (S.DS.P) namespace method in Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework a...

  [taumode] Score: 0.8700
            Title: (no title)
            Text:  CVE-2012-4405 | Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code...
----------------------------------------
RANK 17:
  [Cosine] Score: 0.7284
           Title: apparmor: fix side-effect bug in match_char() macro usage
           Text:  CVE-2026-23406 | apparmor: fix side-effect bug in match_char() macro usage | In the Linux kernel, the following vulnerability has been resolved:  apparmor: fix side-effect bug in match_char() macro usage  The match_char() macro evaluates its character parameter multiple times when traversing differe...

  [taumode] Score: 0.8696
            Title: Reference binding to null in `ParameterizedTruncatedNormal`
            Text:  CVE-2021-29568 | Reference binding to null in `ParameterizedTruncatedNormal` | TensorFlow is an end-to-end open source platform for machine learning. An attacker can trigger undefined behavior by binding to null pointer in `tf.raw_ops.ParameterizedTruncatedNormal`. This is because the implementation...
----------------------------------------
RANK 18:
  [Cosine] Score: 0.7280
           Title: sch_cake: Fix out of bounds when parsing TCP options and header
           Text:  CVE-2021-47243 | sch_cake: Fix out of bounds when parsing TCP options and header | In the Linux kernel, the following vulnerability has been resolved:  sch_cake: Fix out of bounds when parsing TCP options and header  The TCP option parser in cake qdisc (cake_get_tcpopt and cake_tcph_may_drop) could ...

  [taumode] Score: 0.8696
            Title: HID: core: fix shift-out-of-bounds in hid_report_raw_event
            Text:  CVE-2022-48978 | HID: core: fix shift-out-of-bounds in hid_report_raw_event | In the Linux kernel, the following vulnerability has been resolved:  HID: core: fix shift-out-of-bounds in hid_report_raw_event  Syzbot reported shift-out-of-bounds in hid_report_raw_event.  microsoft 0003:045E:07DA.0001: ...
----------------------------------------
RANK 19:
  [Cosine] Score: 0.7279
           Title: (no title)
           Text:  CVE-2017-8312 | Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file. | VideoLAN VLC...

  [taumode] Score: 0.8694
            Title: (no title)
            Text:  CVE-2009-1869 | Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an AVM2...
----------------------------------------
RANK 20:
  [Cosine] Score: 0.7279
           Title: (no title)
           Text:  CVE-2013-0862 | Multiple integer overflows in the process_frame_obj function in libavcodec/sanm.c in FFmpeg before 1.1.2 allow remote attackers to have an unspecified impact via crafted image dimensions in LucasArts Smush video data, which triggers an out-of-bounds array access. | n/a n/a...

  [taumode] Score: 0.8693
            Title: mtd: spi-nor: Fix shift-out-of-bounds in spi_nor_set_erase_type
            Text:  CVE-2023-54295 | mtd: spi-nor: Fix shift-out-of-bounds in spi_nor_set_erase_type | In the Linux kernel, the following vulnerability has been resolved:  mtd: spi-nor: Fix shift-out-of-bounds in spi_nor_set_erase_type  spi_nor_set_erase_type() was used either to set or to mask out an erase type. When ...
----------------------------------------
RANK 21:
  [Cosine] Score: 0.7271
           Title: (no title)
           Text:  CVE-2011-1567 | Multiple stack-based buffer overflows in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted (1) ListAll, (2) Write File, (...

  [taumode] Score: 0.8693
            Title: (no title)
            Text:  CVE-2006-1540 | MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated ...
----------------------------------------
RANK 22:
  [Cosine] Score: 0.7269
           Title: apparmor: fix missing bounds check on DEFAULT table in verify_dfa()
           Text:  CVE-2026-23407 | apparmor: fix missing bounds check on DEFAULT table in verify_dfa() | In the Linux kernel, the following vulnerability has been resolved:  apparmor: fix missing bounds check on DEFAULT table in verify_dfa()  The verify_dfa() function only checks DEFAULT_TABLE bounds when the state i...

  [taumode] Score: 0.8693
            Title: (no title)
            Text:  CVE-2008-0456 | CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduc...
----------------------------------------
RANK 23:
  [Cosine] Score: 0.7263
           Title: iio: light: Add check for array bounds in veml6075_read_int_time_ms
           Text:  CVE-2025-40114 | iio: light: Add check for array bounds in veml6075_read_int_time_ms | In the Linux kernel, the following vulnerability has been resolved:  iio: light: Add check for array bounds in veml6075_read_int_time_ms  The array contains only 5 elements, but the index calculated by veml6075_re...

  [taumode] Score: 0.8690
            Title: (no title)
            Text:  CVE-2009-1935 | Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimization feature in the pipe implementation in FreeBSD 7.1 through 7.2 and 6.3 through 6.4 allows local users to bypass virtual-to-physical address lookups and read sensitive inform...
----------------------------------------
RANK 24:
  [Cosine] Score: 0.7263
           Title: drm/xe: Fix an out-of-bounds shift when invalidating TLB
           Text:  CVE-2025-37761 | drm/xe: Fix an out-of-bounds shift when invalidating TLB | In the Linux kernel, the following vulnerability has been resolved:  drm/xe: Fix an out-of-bounds shift when invalidating TLB  When the size of the range invalidated is larger than rounddown_pow_of_two(ULONG_MAX), The functi...

  [taumode] Score: 0.8689
            Title: (no title)
            Text:  CVE-2009-0690 | The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a negative value for the stream offset in a JPEG2000 (aka JPX) stream, which allows remote attackers to cause a denial of service (memory corruption and applica...
----------------------------------------
RANK 25:
  [Cosine] Score: 0.7260
           Title: (no title)
           Text:  CVE-2013-3940 | Integer overflow in the Graphics Device Interface (GDI) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remo...

  [taumode] Score: 0.8688
            Title: (no title)
            Text:  CVE-2007-4344 | Multiple input validation errors in ACD ACDSee Photo Manager 9.0 build 108, Pro Photo Manager 8.1 build 99, and Photo Editor 4.0 build 195 allow user-assisted remote attackers to execute arbitrary code via a long section string in (1) a PSP image to the ID_PSP.apl plug-in or (2) an L...
----------------------------------------
================================================================================

QUERY TYPE: SAMPLE QUERY (Median Score)
QUERY TEXT: double free vulnerability in archive extraction library
--------------------------------------------------------------------------------
RANK 1:
  [Cosine] Score: 0.8414
           Title: (no title)
           Text:  CVE-2014-7864 | Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 through 11.5 build 11400 and IT360 10.5 and earlier allow remote attackers and remote authenticated users to execute arbitrary SQL commands via the (1) custo...

  [taumode] Score: 0.9322
            Title: LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID
            Text:  CVE-2026-5234 | LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID | The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.3.2. The vulnerability e...
----------------------------------------
RANK 2:
  [Cosine] Score: 0.8391
           Title: LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID
           Text:  CVE-2026-5234 | LatePoint <= 5.3.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID | The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.3.2. The vulnerability e...

  [taumode] Score: 0.9322
            Title: (no title)
            Text:  CVE-2023-45503 | SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via crafted payload to resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUs...
----------------------------------------
RANK 3:
  [Cosine] Score: 0.8390
           Title: (no title)
           Text:  CVE-2023-45503 | SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via crafted payload to resetPassword, forgotPasswordProcess, saveUser, saveRole, deleteUs...

  [taumode] Score: 0.9296
            Title: (no title)
            Text:  CVE-2012-4347 | Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) logFile parameter in a logs action to brightmail/export or (2) localBackupFileSelect...
----------------------------------------
RANK 4:
  [Cosine] Score: 0.8379
           Title: (no title)
           Text:  CVE-2005-2865 | Multiple PHP remote file inclusion vulnerabilities in aMember Pro 2.3.4 allow remote attackers to execute arbitrary PHP code via the config[root_dir] parameter to (1) mysql.inc.php, (2) efsnet.inc.php, (3) theinternetcommerce.inc.php, (4) cdg.inc.php, (5) compuworld.inc.php, (6) dire...

  [taumode] Score: 0.9287
            Title: (no title)
            Text:  CVE-2023-46350 | SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods IdxrmanufacturerFunctions::g...
----------------------------------------
RANK 5:
  [Cosine] Score: 0.8345
           Title: (no title)
           Text:  CVE-2019-19034 | Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute arbitrary commands on the AssetExplorer Server with NT AUTHORI...

  [taumode] Score: 0.9286
            Title: (no title)
            Text:  CVE-2012-1289 | Multiple directory traversal vulnerabilities in SAP NetWeaver 7.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the logfilename parameter to (1) b2b/admin/log.jsp or (2) b2b/admin/log_view.jsp in the Internet Sales (crm.b2b) component, or (3) ipc/admi...
----------------------------------------
RANK 6:
  [Cosine] Score: 0.8325
           Title: (no title)
           Text:  CVE-2012-4347 | Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) logFile parameter in a logs action to brightmail/export or (2) localBackupFileSelect...

  [taumode] Score: 0.9284
            Title: (no title)
            Text:  CVE-2013-7216 | Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp. | n/a n/a...
----------------------------------------
RANK 7:
  [Cosine] Score: 0.8320
           Title: (no title)
           Text:  CVE-2015-9226 | Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands via the download parameter in the (1) check_download and possibly (2) check_filename function in upload/admin2/model/products/model_admin_download.php or remote au...

  [taumode] Score: 0.9284
            Title: (no title)
            Text:  CVE-2025-63390 | An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authentication checks, allowing unauthenticated remote attackers to enumerate and retrieve detailed information about all configured worksp...
----------------------------------------
RANK 8:
  [Cosine] Score: 0.8308
           Title: (no title)
           Text:  CVE-2019-6716 | An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a remote attacker to enumerate internal Active Directory usernames and group names, and alter back-end server jobs (backup and synchronization jobs...

  [taumode] Score: 0.9282
            Title: (no title)
            Text:  CVE-2006-5303 | Secure Computing SafeWord RemoteAccess 2.1 allows local users to obtain the UserCenter webportal password, database encryption keys, and signing keys by reading (1) base-64 encoded data in SERVERS\Web\Tomcat\usercenter\WEB-INF\login.conf and (2) plaintext data in SERVERS\Shared\signe...
----------------------------------------
RANK 9:
  [Cosine] Score: 0.8306
           Title: (no title)
           Text:  CVE-2023-46350 | SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods IdxrmanufacturerFunctions::g...

  [taumode] Score: 0.9278
            Title: (no title)
            Text:  CVE-2019-13382 | UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations that points...
----------------------------------------
RANK 10:
  [Cosine] Score: 0.8300
           Title: (no title)
           Text:  CVE-2012-1289 | Multiple directory traversal vulnerabilities in SAP NetWeaver 7.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the logfilename parameter to (1) b2b/admin/log.jsp or (2) b2b/admin/log_view.jsp in the Internet Sales (crm.b2b) component, or (3) ipc/admi...

  [taumode] Score: 0.9276
            Title: Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS
            Text:  CVE-2025-40659 | Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or...
----------------------------------------
RANK 11:
  [Cosine] Score: 0.8299
           Title: (no title)
           Text:  CVE-2013-7216 | Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp. | n/a n/a...

  [taumode] Score: 0.9274
            Title: Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS
            Text:  CVE-2025-40660 | Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or...
----------------------------------------
RANK 12:
  [Cosine] Score: 0.8295
           Title: (no title)
           Text:  CVE-2025-63390 | An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authentication checks, allowing unauthenticated remote attackers to enumerate and retrieve detailed information about all configured worksp...

  [taumode] Score: 0.9273
            Title: (no title)
            Text:  CVE-2009-1553 | Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) applications/applications.jsf, (2) configuration/configuration.jsf, (3) customMBea...
----------------------------------------
RANK 13:
  [Cosine] Score: 0.8291
           Title: (no title)
           Text:  CVE-2006-5303 | Secure Computing SafeWord RemoteAccess 2.1 allows local users to obtain the UserCenter webportal password, database encryption keys, and signing keys by reading (1) base-64 encoded data in SERVERS\Web\Tomcat\usercenter\WEB-INF\login.conf and (2) plaintext data in SERVERS\Shared\signe...

  [taumode] Score: 0.9261
            Title: Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS
            Text:  CVE-2025-40658 | Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or...
----------------------------------------
RANK 14:
  [Cosine] Score: 0.8286
           Title: Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS
           Text:  CVE-2025-40659 | Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or...

  [taumode] Score: 0.9260
            Title: (no title)
            Text:  CVE-2017-5965 | The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIP archive in which a .asp file has a ..\ in its pathname, visiting sitecore/shell/applications/install/dialogs/Upload%20Package/UploadPackage2.a...
----------------------------------------
RANK 15:
  [Cosine] Score: 0.8285
           Title: (no title)
           Text:  CVE-2012-3469 | Multiple SQL injection vulnerabilities in the Ushahidi Platform before 2.5 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the messages admin functionality in application/controllers/admin/messages.php, (2) application/libraries/api/MY_Checkin_Api_...

  [taumode] Score: 0.9259
            Title: (no title)
            Text:  CVE-2016-0492 | Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerabil...
----------------------------------------
RANK 16:
  [Cosine] Score: 0.8282
           Title: (no title)
           Text:  CVE-2019-13382 | UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations that points...

  [taumode] Score: 0.9256
            Title: (no title)
            Text:  CVE-2022-29597 | Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the ability to reference internal system files within requests made to the RRSWeb/maint/ShowDocument/ShowDocument.aspx page. The server will successfully...
----------------------------------------
RANK 17:
  [Cosine] Score: 0.8280
           Title: Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS
           Text:  CVE-2025-40660 | Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or...

  [taumode] Score: 0.9255
            Title: (no title)
            Text:  CVE-2019-11030 | Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Mirasys.Common.Utils.Security.DataCrypt method in Common.dll in AuditTrailService in SMServer.exe. This method triggers insecure deserialization within the .NET garbage collector, in which a gadget (contained in a serial...
----------------------------------------
RANK 18:
  [Cosine] Score: 0.8279
           Title: (no title)
           Text:  CVE-2014-9145 | Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an edit action to dapur/index.php; (2) cat, (3) user, or (4) level parameter to dapur/apps/app_article/controller/article_list.php; or (5) e...

  [taumode] Score: 0.9254
            Title: Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS
            Text:  CVE-2025-40661 | Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or...
----------------------------------------
RANK 19:
  [Cosine] Score: 0.8275
           Title: (no title)
           Text:  CVE-2006-3172 | Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL with a trailing slash (/) character in the (1) lang_path parameter to (a) cms/plugins/col_man/column.inc.php, (b) cms/plugins/poll/poll.inc.php, ...

  [taumode] Score: 0.9254
            Title: (no title)
            Text:  CVE-2006-5600 | Axalto Protiva 1.1, possibly only non-commercial versions, stores passwords in plaintext in files with insecure permissions, which allows local users to gain privileges by reading the passwords from (1) KeyTool\keytool.config or (2) webapps\protiva\WEB-INF\classes\authserver.config. ...
----------------------------------------
RANK 20:
  [Cosine] Score: 0.8272
           Title: (no title)
           Text:  CVE-2009-1553 | Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) applications/applications.jsf, (2) configuration/configuration.jsf, (3) customMBea...

  [taumode] Score: 0.9252
            Title: Read/Write Permissions for Everyone on Configuration File
            Text:  CVE-2024-36495 | Read/Write Permissions for Everyone on Configuration File | The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access to, path to file:    C:\ProgramData\WINSelect\WINSelect.w...
----------------------------------------
RANK 21:
  [Cosine] Score: 0.8264
           Title: (no title)
           Text:  CVE-2013-4882 | Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (ePO) extension for McAfee Agent (MA) 4.5 and 4.6, allow remote authenticated users to execute arbitrary SQL commands via the uid parameter to (1) core/showRegistered...

  [taumode] Score: 0.9251
            Title: (no title)
            Text:  CVE-2022-31662 | VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with network access may be able to access arbitrary files. | n/a VMware Workspace ONE Access, Access Connector, Identity Manager, vIDM Connecto...
----------------------------------------
RANK 22:
  [Cosine] Score: 0.8263
           Title: (no title)
           Text:  CVE-2009-4666 | Multiple PHP remote file inclusion vulnerabilities in Webradev Download Protect 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[RootPath] parameter to (1) Framework/EmailTemplates.class.php, (2) Customers/PDPEmailReplaceConstants.class.php, and (3) A...

  [taumode] Score: 0.9250
            Title: (no title)
            Text:  CVE-2021-44877 | Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Incorrect Access Control. The Systeam application is an ERP system that uses a mixed architecture based on SaaS tenant and user management, and on-premise database and web application counterparts. A broken access control vu...
----------------------------------------
RANK 23:
  [Cosine] Score: 0.8252
           Title: Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS
           Text:  CVE-2025-40658 | Insecure Direct Object Reference (IDOR) vulnerability in DM Corporative CMS | An Insecure Direct Object Reference (IDOR) vulnerability has been found in DM Corporative CMS. This vulnerability allows an attacker to access the private area setting the option parameter equal to 0, 1 or...

  [taumode] Score: 0.9250
            Title: (no title)
            Text:  CVE-2006-4575 | Multiple SQL injection vulnerabilities in The Address Book 1.04e allow remote attackers to execute arbitrary SQL commands via the (1) lastname, (2) firstname, (3) passwordOld, (4) passwordNew, (5) id, (6) language, (7) defaultLetter, (8) newuserPass, (9) newuserType, (10) newuserEmai...
----------------------------------------
RANK 24:
  [Cosine] Score: 0.8245
           Title: (no title)
           Text:  CVE-2019-8927 | An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfig.jsp file via these GET parameters: devSrc, emailId, excWeekModify, filterFlag, getFilter, mailReport, mset, popup, rep_schedule, rep...

  [taumode] Score: 0.9249
            Title: (no title)
            Text:  CVE-2013-4883 | Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extension for the McAfee Agent (MA) 4.5 through 4.6, allow remote attackers to inject arbitrary web script or HTML via the (1) instanceId parameter core/loadDisplayType.d...
----------------------------------------
RANK 25:
  [Cosine] Score: 0.8243
           Title: (no title)
           Text:  CVE-2008-1969 | Multiple cross-site scripting (XSS) vulnerabilities in Cezanne 6.5.1 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) LookUPId and (2) CbFun parameters to (a) CFLookUP.asp; (3) TitleParms, (4) WidgetsHeights, (5) WidgetsLinks, and (6) WidgetsTitles para...

  [taumode] Score: 0.9249
            Title: (no title)
            Text:  CVE-2006-6974 | Headstart Solutions DeskPRO stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) list files in the includes/ directory; obtain the SQL username and password via a direct request for (2) config.php and (3) config.php.ba...
----------------------------------------
================================================================================

