All CVEs — page 132 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw in LTSecurity LTK3500SF involves hard-coded weak credentials, allowing dictionary-based cracking tools to recover root and guest account passwords, which can then be used to gain root-level access via Telnet and SSH services.
The flaw allows unauthenticated remote code execution due to deserialization of untrusted data, posing a significant security risk.
The flaw allows unauthenticated remote code execution due to insufficient integrity checks, making it a critical vulnerability that can be exploited to gain full control over the system.
The flaw allows attackers to inject malicious scripts into article content, which can be executed in the context of the victim's browser, leading to potential data exfiltration or manipulation.
The flaw is a SQL injection vulnerability in the PageAction.verify endpoint of MCMS 6.1.1 through 6.2.1, allowing attackers to execute arbitrary SQL commands and potentially gain full control over the database.
The flaw is a Server-Side Request Forgery (SSRF) vulnerability in Adobe Experience Manager Forms JEE that allows a low-privileged attacker to gain elevated access to internal resources, potentially leading to privilege escalation.
The flaw is a Server-Side Request Forgery (SSRF) vulnerability in Adobe Experience Manager Forms JEE that could allow attackers with high privileges to gain elevated access to internal resources. This matters because it can lead to unauthorized access and data exposure.