All CVEs — page 130 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The lwIP library contains a double free vulnerability that could lead to system crashes, denial of service, memory corruption, or code execution.
This vulnerability allows authenticated non-guest users to execute arbitrary code by exploiting Java deserialization in the HTTP invoker endpoint, leading to remote code execution.
The flaw allows authenticated users to write to the default install directory, posing a risk of unauthorized code execution or data modification.
This vulnerability allows attackers to execute arbitrary recursive directory deletion by exploiting missing path validation in the Worktree.remove component of openCode v1.18.26, posing a critical risk to system integrity.
The flaw allows an authenticated low-privileged user to upload a .php file, leading to arbitrary code execution on the server due to lack of proper file extension validation and content checks.
CMSimple 5.24 lacks CSRF protection, allowing unauthenticated attackers to inject and execute arbitrary PHP code via specially crafted content-save requests.