All CVEs — page 12 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The vulnerability allows for open redirect through manipulation of the Success argument in the authorize function of ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717, posing a security risk.
The vulnerability allows for open redirect via manipulation of the Host argument in /login.html, enabling remote attackers to potentially redirect users to malicious sites.
The flaw is an OS Command Injection vulnerability in Tuleap Enterprise Edition from versions 17.3 to 17.5, allowing attackers to execute arbitrary commands on the server, posing a significant security risk.
The flaw in noobaa-core's signature verification logic allows attackers to add unsigned headers, enabling unauthorized CopyObject operations and data copying.
The flaw allows cross-site scripting (XSS) via the getAllGrouped function in Hyve5 Leantime up to version 3.9.8, enabling remote attackers to inject malicious scripts.
The flaw in Neethi allows a server to perform a denial of service by trickling bytes slowly during policy reference fetches, tying up the calling thread indefinitely.
The flaw involves a denial of service vulnerability in Neethi's policy-intersection due to improperly handled WS-Policy documents, leading to excessive CPU usage.
The flaw involves a small WS-Policy document that can cause Neethi to consume excessive CPU and memory during normalization, leading to a denial of service (DoS). This matters because it can disrupt system operations without requiring sophisticated exploitation techniques.
The flaw allows a specially crafted WS-Policy document to cause heap exhaustion due to unbounded content copying, leading to denial of service.
The flaw allows a specially crafted WS-Policy document to exhaust the thread stack, causing a denial of service. This matters because it can disrupt service without requiring sophisticated exploitation.
This vulnerability allows a user to bypass Kubernetes security context by restoring a pod from a malicious checkpointed container, potentially leading to elevated privileges.