All CVEs — page 13 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw allows for authorization bypass through manipulation of the ID argument in the User Profile API, enabling unauthorized access to user data.
A vulnerability allows for missing authentication by manipulating the argument roleId in the Role Permission API's /role-permission/permission endpoint, posing a risk to system security.
The flaw allows unauthenticated users to mark their own orders as paid by using a genuine transaction from a payment sandbox they control, bypassing order verification.
The flaw allows unauthenticated users to create arbitrary published posts and taxonomy terms by exploiting a lack of authorization and nonce checks in the import routine.
The flaw allows unauthenticated users to execute arbitrary shortcodes by nesting them, potentially leading to remote code execution or data leakage.
The flaw allows unauthenticated users to manipulate item prices in the RestroPress WordPress plugin, potentially placing orders with arbitrary totals or zero value.
The flaw allows a user with sufficient privileges to perform unintended operations on the host filesystem by exploiting container checkpoint and restore functionality.
The vulnerability allows manipulation of the argument roleId to improperly control resource identifiers, potentially leading to unauthorized access or data exposure.
The flaw allows for memory exhaustion due to uncontrolled decompression of data with high compression ratios, potentially leading to denial of service.
The flaw allows users to bypass mandatory two-factor authentication by manually visiting a session restart link, gaining unauthorized access.
The flaw allows administrators with limited privileges to read or modify sensitive client configurations in the master realm by accessing them through a controlled realm, potentially exposing client credentials.
The flaw allows a delegated administrator with limited viewing privileges to access full user profiles and roles, exposing sensitive information.
The flaw allows write-what-where conditions through manipulation of PhysicalAddress/Size arguments in BioStar BIOS Update Utility 1.9.7.3, enabling local attackers to exploit it.
A cross-site scripting vulnerability exists in xxl-job versions up to 3.4.2/3.5.0 due to improper input handling, allowing attackers to inject malicious scripts via job names or authors.
The flaw allows SQL injection by manipulating the filter argument in drogonframework's makeCriteria function, posing a high risk due to remote exploitability.
The flaw allows an attacker to access a user’s session by controlling a privileged WebView, posing a high security risk.
The vulnerability allows SQL injection through manipulation of the sort argument in the Mapper::orderBy function, posing a high risk due to remote exploitability.