All CVEs — page 117 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This vulnerability allows unauthorized access to the XML Web Publishing interface by bypassing the Custom Web Publishing with XML setting through an extended privilege header, posing a significant security risk.
This vulnerability allows an attacker to read process memory during thumbnail generation in FileMaker WebDirect by uploading a specially crafted image file to a container field. This can lead to sensitive information disclosure.
The flaw allows a remote attacker to execute arbitrary code by exploiting the MLflow statsmodel flavor's lack of deserialization security control.
The flaw allows a remote attacker to execute arbitrary code by crafting a specific MLmodel artifact, due to the lack of proper deserialization security control.
The flaw allows attackers to inject arbitrary JavaScript code by manipulating the operationId parameter, leading to remote code execution.
The flaw allows code injection in the form-data serializer, enabling attackers to inject malicious ${...} expressions that can be executed during the generation of FormData bodies.
The flaw allows attackers to inject JavaScript by exploiting crafted media-type keys in OpenAPI specifications, leading to remote code execution.
The flaw allows attackers to inject arbitrary JavaScript expressions via OpenAPI schema defaults, leading to remote code execution.
The flaw allows code injection by failing to escape OpenAPI path values, enabling arbitrary JavaScript code execution.
The flaw allows the MQTT broker to start without configured authentication or authorization, potentially exposing the system to unauthorized access.