All CVEs — page 126 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This flaw allows users with the Subscriber role and above to obtain a valid identity assertion for another user, including administrators, and authenticate as them, due to the plugin not binding the OpenID Connect identity assertion to the correct authorization grant.
The flaw allows unauthenticated attackers to write arbitrary PHP files on the server, leading to Remote Code Execution (RCE) when the caching feature is enabled.
The flaw allows unauthenticated users to extract arbitrary data, including password hashes, by injecting a payment token into a SQL statement without proper sanitization.
The flaw is a stack-based buffer overflow in the copy_msg_element function of the Device Discovery Service in Fast FAC1203R Gigabit Edition 2.0.4, which can lead to remote code execution. This issue is critical as it allows attackers to exploit the vulnerability to gain control over the affected system.