All CVEs — page 120 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
LightLLM through 1.2.0 has a remote code execution vulnerability due to an unauthenticated RPyC control channel that deserializes attacker-supplied data, allowing arbitrary code execution with the service account privileges.
The flaw allows unauthenticated attackers to access a Google Cloud service-account private key in the Applications Manager installer, enabling them to impersonate the service account and potentially access or modify cloud resources.
This flaw allows a low-privileged user to obtain an administrator’s API key, enabling them to perform administrator-level actions, which can lead to unauthorized access and data manipulation.
This flaw allows a low-privileged user to execute unauthorized SQL commands, potentially gaining full administrative access and remote code execution, which can lead to complete compromise of the affected system.
The flaw in SunEditor allows event-handler attributes to remain on crafted elements, enabling stored cross-site scripting and potentially leading to data exposure or unauthorized actions.