All CVEs — page 118 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This vulnerability allows an attacker to inject OS commands, leading to arbitrary command execution as the user running the explore command. It matters because it can be exploited to gain full control over the system.
The flaw allows a client to substitute their identity into MQTT topic filters, potentially gaining unauthorized access to other tenants' data. This is due to direct substitution of client ID and username values into pattern-based ACL rules.
This vulnerability allows an attacker to execute arbitrary code via SQL injection in the Moodle Socialwall plugin versions 3.0 to 3.3, posing a critical risk.