All CVEs — page 11 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw allows an attacker to inject arbitrary Stata commands by embedding newline characters in package arguments, leading to full OS-level RCE. This matters because it exploits a lack of input validation and can be executed without special configuration.
The flaw allows an authenticated internal user to view sensitive information from source control child processes, including command-line arguments and material paths, which could be exploited for unauthorized access.
The flaw allows authenticated users to guess job IDs and retrieve status for jobs in pipelines they shouldn't have access to, potentially exposing sensitive information.
A stored cross-site scripting vulnerability in Aureus ERP before 1.6.0 allows users to inject malicious markup via Chatter field-change logs, potentially leading to client-side code execution when viewed by other users.
The vulnerability allows any authenticated user to create or delete alerts on systems they shouldn't have access to, potentially disclosing sensitive information.
The vulnerability allows unauthenticated attackers to perform a Denial-of-Service attack on the Thinkst Canary honeypot Redis service by exploiting its enabled state.
The flaw allows agents with agent-management privilege to escalate their role to administrator, gaining full administrative control.
The flaw allows authenticated agents to access restricted saved replies, potentially exposing sensitive information across support groups.
The flaw allows attackers with ROLE_AGENT to inject malicious scripts via the SwiftMailer configuration identifier parameter, leading to cross-site scripting (XSS) attacks.