All CVEs — page 148 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
A SQL injection vulnerability in nocobase v2.1.21 enables attackers to access sensitive database information by injecting malicious SQL statements, posing a critical risk.
The flaw allows authenticated workspace members to bypass sandbox restrictions and perform file operations or execute processes as the sandbox user, due to improper handling of ctypes.CDLL in function-library code.
The flaw allows an authenticated attacker to execute code outside the sandbox by leveraging fexecve, posing a risk to system security.
The flaw allows an attacker to create public ChatShareLinks and PublicFileAccess states for a victim's conversation without proper authentication, exposing sensitive information.
The flaw allows authenticated users to inject control characters into AWS credentials, enabling command execution as root.
The flaw allows a normal user to read victim chat records by misusing application_id and chat_id values, posing a risk to data privacy within the same workspace.
The flaw allows an authenticated user to read or overwrite another user's model parameters in MaxKB AI assistant, potentially altering default settings. This matters because it can lead to unauthorized changes affecting workflows.
The flaw allows a low-privileged user to read cloud metadata or internal HTTP services by importing documents through MaxKB's document import feature due to insecure requests.get calls with verify=False. This matters because it can lead to unauthorized data exposure.
The flaw allows untrusted chat or content to execute arbitrary shell commands, posing a significant risk to system security.
An attacker can obtain another user's application_id by exploiting a vulnerability in MaxKB’s homepage application question-ranking endpoint, allowing them to access sensitive data and potentially execute unauthorized actions.
The flaw allows an attacker to exploit a previously valid, non-permanent application key that remains active after expiration to access and manipulate MCP endpoint functionalities.
An authorization bypass flaw allows a normal user to retrieve hidden tools by knowing another user's active MCP tool_id. This can expose sensitive configuration data.
The flaw allows a workspace user to read or modify content in another user's knowledge base by exploiting improperly authorized document and paragraph routes. This matters because it breaches data isolation and confidentiality.
Users with a low role can still execute tools they are denied access to by binding identifiers through various paths, leading to potential credential exposure.
This flaw in Envoy allows unauthenticated clients to bypass path-based authorization by manipulating URL parameters, potentially gaining unauthorized access to protected routes.
The flaw allows path confusion by not properly normalizing URL segments with semicolons, potentially bypassing security policies.
This flaw allows a remote client to bypass security measures by manipulating path parameters in Envoy, potentially accessing unprotected resources. It matters because it can lead to unauthorized access to sensitive data.
The flaw allows remote attackers to execute arbitrary shell commands via the setServerConfig API endpoint, leading to Remote Code Execution (RCE). This is critical because it can be exploited without authentication, providing full control over the system.
The flaw allows an authenticated user to exploit URL-encoded slashes and parent-directory segments in job IDs to access internal transcription-backend endpoints, potentially exposing sensitive data.
The flaw in Sync-in Server allows unauthenticated attackers to measure response times and enumerate valid usernames or email addresses, enabling credential-stuffing attacks.
The flaw allows a catastrophic-backtracking regular expression pattern to block the server, rendering it unresponsive. This matters because an attacker can exploit this to deny service to all users.