All CVEs — page 145 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw is a heap buffer overflow in the Net::IDN::Punycode Perl module, which can be exploited by attackers to corrupt the heap. This matters because it can lead to arbitrary code execution or other severe impacts.
The flaw allows unauthenticated users to inject malicious code into form submissions, which could then be executed in the browser of an admin user reviewing the submission, leading to potential remote code execution.
The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection, allowing unauthenticated attackers to inject a PHP Object if specific conditions are met.
The flaw allows unauthenticated attackers to escalate privileges to Administrator by exploiting a chained vulnerability in the Meta Box AIO plugin for WordPress.
A vulnerability in the Gigatech PDV5701 1.0.31_240305_112640 WebSocket Service allows for missing authentication, enabling remote attackers to exploit it.
The flaw allows SQL injection via manipulation of the operator argument in Yonyou U8cloud 5.x's OpenAPI module, enabling remote code execution.
The flaw is a SQL injection vulnerability in Yonyou KSOA 9.0 due to improper argument handling in search_list.jsp, allowing remote attackers to execute arbitrary SQL commands. This matters because it can lead to data theft or corruption.
The flaw allows unauthenticated attackers to craft a malicious link that can exfiltrate sensitive information from an authenticated user's session in SAP Fiori Launchpad.
The flaw allows for os command injection through manipulation of the argument command in OctoPrint's Command API, enabling remote code execution.
The vulnerability allows path traversal through manipulation of the filename argument in OctoPrint's File Download API, enabling unauthorized access to files.