All CVEs — page 10 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw allows a malicious package to write executable files outside the intended directory or overwrite existing entry points, leading to potential code execution with user privileges.
The flaw allows a remote attacker to inject arbitrary JavaScript into an authenticated user's session via unsanitized clickable links on the msg_info page, leading to potential data theft or manipulation.
The flaw is a cross-site scripting (XSS) vulnerability in CuteNews v.2.1.2 that allows remote unauthenticated attackers to inject malicious scripts via URL parameters, potentially leading to information disclosure or user manipulation.
This vulnerability allows remote authenticated users to execute arbitrary code by uploading a file with a dangerous type, leading to potential remote server access.
The flaw allows for an allow-list bypass via java.lang.reflect.Proxy due to missing resolveProxyClass() override in MINA 2.0.X and 2.1.X branches, enabling potential remote code execution.
The flaw is a stack-based buffer overflow in fetchmail when NTLM support is enabled, allowing a malicious server to potentially execute arbitrary code or cause service disruption.
The flaw allows authenticated users with Author-level privileges or higher to inject arbitrary HTML elements by supplying malicious wrapper attribute values, leading to cross-site scripting attacks.
This flaw allows an attacker to maintain access after a user logs out if they have a valid bearer token, posing a significant security risk.
This vulnerability allows an attacker to bypass intended authentication by using a session cookie and an explicit bearer token, with Airflow resolving the caller from the cookie instead of the token.
The flaw in pki-core allows wildcard ACL permissions to override more specific literal permissions, potentially enabling unauthorized access to certificate management functions.
The flaw in openshift/oc-mirror allows for PGP signature verification bypass, enabling remote attackers to forge signatures and mirror malicious release payloads into a disconnected registry.
The flaw allows any authenticated user with asset-read access to enumerate asset events for all Dags in the deployment, including those they are not authorized to see, due to missing access control filters.
The flaw allows any user with OTP 2FA enabled to reuse their TOTP during a 30-second window, potentially leading to unauthorized access.
The flaw allows unauthenticated attackers to perform a denial of service (DoS) by sending specially crafted requests that consume excessive CPU resources.
The flaw allows unauthenticated attackers to create a full admin account by exploiting a race condition in the onboarding process.
The flaw allows pipeline group administrators to test connections for source control materials outside their authorized scope, potentially exposing credentials. It also enables resolution of external secrets managed by secret-management plugins.
The flaw allows a local unprivileged user to replace a target directory with a Windows junction and symlink, enabling arbitrary privileged file deletion which can lead to SYSTEM privileges.