All CVEs — page 147 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows user-controlled display names to contain HTML, enabling script injection in post actions. This can lead to cross-site scripting (XSS) attacks.
The flaw allows a low-privileged authenticated user to create items under a share ID before acceptance, potentially injecting content into shared folders without proper authorization.
The flaw allows a low-privileged user to publish an image/svg+xml attachment with executable script content that can access same-origin data and perform actions with the victim's session if they are authenticated.
The flaw allows an attacker to gain access to a local user's Joplin account by exploiting SAML authentication, potentially leading to unauthorized access or modifications of notes and settings.
The flaw allows a low-privileged user to inject malicious JavaScript via crafted HTML notes, potentially leading to script execution in the Joplin Server origin.
This vulnerability allows an attacker to cause a denial of service by manipulating frame lengths in control responses, leading to buffer overflows and incorrect data processing.
The flaw involves a race condition in the nonce generation for secure storage operations, leading to nonce reuse with the same key, which can result in plaintext leakage and authentication key exposure.
The flaw allows for argument injection in package changelog retrieval through improperly handled user input, posing a medium security risk.
The vulnerability in Moore Threads MTT S80 Driver Package up to 340.150 allows for a heap-based buffer overflow, which can lead to remote code execution if exploited.
The flaw in libstoragemgmt allows an attacker to cause a stack buffer overflow by providing malformed SCSI VPD page 0x80 data, leading to potential denial of service.
The flaw involves an integer overflow in FalkorDB's Redis module v4.20.1, allowing attackers to cause a Denial of Service via crafted input, which could disrupt service availability.
The flaw involves improper error handling in FalkorDB v4.20.1's GRAPH.EFFECT component, leading to a Denial of Service (DoS). This matters because attackers can exploit it to disrupt service without needing specific privileges.
The flaw in FalkorDB's graph.UDF module allows unauthorized read operations, but no write commands are registered, leading to potential data exposure and integrity issues.
The flaw in FalkorDB (Redis module) v4.20.1 to v4.20.4 involves a buffer overflow in the _Decode_GrB_Matrix function, allowing attackers to cause a Denial of Service (DoS) via crafted input. This vulnerability is significant because it can lead to service disruption without requiring user interaction.
The flaw in FalkorDB (Redis module) allows attackers to cause a Denial of Service via a stack overflow from a crafted input, impacting system availability.
The flaw in FalkorDB (Redis module) allows out-of-bounds read leading to Denial of Service via crafted input, posing a significant risk.
The flaw in FalkorDB (Redis module) allows attackers to cause a Denial of Service via a stack overflow from a crafted input, compromising system availability.
The vulnerability allows attackers to execute arbitrary code via a crafted payload, posing a critical risk due to remote code execution capabilities.
This vulnerability allows attackers to execute arbitrary code via a crafted payload, posing a critical risk due to remote code execution capabilities.