All CVEs — page 106 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows unauthenticated attackers to include and execute arbitrary PHP code via the `vcv-template` parameter, leading to potential code execution and data breaches.
The flaw is an Origin Validation Error in the YOP Poll plugin for WordPress, allowing unauthenticated attackers to steal a REST nonce and change the Administrator's email and password, leading to full account takeover.
Path traversal vulnerability allows attackers to access sensitive files. This flaw is critical as it can lead to data theft or system compromise.
SQL Injection vulnerability allows attackers to execute arbitrary SQL commands, potentially leading to data theft or corruption.
SQL Injection vulnerability allows attackers to execute arbitrary SQL commands, potentially leading to data theft or corruption.
The flaw is an Improper Authentication vulnerability in DIAEnergie that allows Authentication Bypass, enabling unauthorized access to the system. This matters because it can lead to significant data compromise and operational disruption.