
CVE Watch
Every published CVE, mapped to engagement reality.
Crawled from cve.org every day. Each entry annotated with the QSearch coverage signal — how many of our agents, skills, and playbooks address the technique. Subscribe via RSS for SIEM pipe, or get the weekly digest by email.
OpenTelemetry.OpAmp.Client is the OpAMP client for OpenTelemetry .NET
OpenTelemetry.OpAmp.Client is the OpAMP client for OpenTelemetry .NET. Prior to 0.2.0-alpha.1, when receiving responses from the OpAMP server over HTTP, the OpAMP client allocates an unbounded buffer to read all bytes from the server, with no upper-bound on the number of bytes consumed. This could cause memory exhaustion in the consuming application if the configured OpAMP server is attacker-controlled (or a network attacker can MitM the connection) and an extremely large body is returned in the response. This vulnerability is fixed in 0.2.0-alpha.1.
opentelemetryCWE-789LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you
LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, when LobeChat processes custom tags in the Render process of src/features/Portal/Artifacts/Body/Renderer/index.tsx, if no type match is found, it will choose to call the default method, HTMLRenderer, for HTML rendering. If an attacker can induce the LLM to output content containing malicious tags, an XSS vulnerability can be created on the client side. Additionally, Lobechat's Electron main process exposes an IPC interface called runCommand, used to invoke system commands. This interface allows arbitrary command execution and does not filter the command parameter. Therefore, if an attacker can obtain a handle to window.parent.electronAPI via XSS and call the runCommand method of the IPC, the ipcMain process can execute arbitrary system commands with the current user's privileges. This vulnerability is fixed in 2.1.48.
CWE-79Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attac...
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
microsoftCWE-73Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
microsoftCWE-73Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
microsoftCWE-284Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
microsoftCWE-416Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
microsoftCWE-416Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
microsoftCWE-1390User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfo...
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
microsoftCWE-451Windows TCP/IP Denial of Service Vulnerability
Windows TCP/IP Denial of Service Vulnerability
microsoftCWE-476Windows TCP/IP Denial of Service Vulnerability
Windows TCP/IP Denial of Service Vulnerability
microsoftCWE-476Windows TCP/IP Denial of Service Vulnerability
Windows TCP/IP Denial of Service Vulnerability
microsoftCWE-476Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attack...
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
microsoftCWE-121Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
microsoftCWE-191Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
microsoftCWE-284Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a...
Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.
microsoftCWE-200Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
microsoftCWE-822Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code lo...
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
microsoftCWE-822Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code lo...
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
microsoftCWE-416Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
microsoftCWE-1220
Weekly digest
Get the curated CVE digest every Monday
One email a week, sent Monday morning CET. The CVEs published or modified in the last seven days, severity-ordered, with the QSearch coverage signal. Unsubscribe with one click — included in every send.
Pipe the CVE feed into your stack.
CVE Watch publishes RSS, Atom, and JSON feeds — wire them into your SIEM, Slack, Discord, or your RSS reader of choice. Or get the curated weekly digest by email.