All CVEs — page 150 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows a use-after-free condition in Envoy's HTTP external-authorization client, leading to potential process crashes under production traffic.
The flaw allows a low-privileged attacker with local access to exploit an Incorrect Permission Assignment for Critical Resource vulnerability in Dell Command | Monitor (DCM) versions prior to 10.13.2, potentially leading to Elevation of Privileges.
The flaw allows dereferencing of a null pointer in Envoy's connection pool allocation logic, potentially leading to worker crashes under specific conditions.
This vulnerability allows authenticated users to bypass authorization checks and manipulate user-role mappings, leading to potential privilege escalation and access control modifications.
The flaw allows authenticated users to manipulate other users' business objects by bypassing authorization checks, potentially leading to unauthorized data modification or deletion.
The flaw allows authenticated users to modify tenant system configurations, potentially leading to unauthorized changes in company identity, stock rules, approval behavior, and printing settings.
This vulnerability allows authenticated users to read other tenants' records by exploiting a tenant isolation bypass in jshERP through version 3.6, potentially exposing sensitive data.
The flaw allows authenticated users to modify role button-permission definitions without proper authorization checks, enabling them to overwrite configurations for any role in the tenant.
The flaw allows authenticated users to retrieve unsalted MD5 password hashes, enabling attackers to perform offline cracking or direct authentication bypass.
This vulnerability allows authenticated users to reset any other user's password, enabling unauthorized access to accounts, including administrative ones.
The vulnerability in jshERP 3.6 allows authenticated users to escalate their privileges by sending a POST request to the updateOneValueByKeyIdAndType endpoint, granting themselves arbitrary roles, including tenant administrator.
The flaw in ColorFul iGameCenter 1.0.3.4 involves an untrusted pointer dereference in the ene.sys library, allowing local exploitation. This vulnerability is significant due to its high impact on confidentiality, integrity, and availability.
This flaw allows a jump host key to be stored for a target address, enabling interception of user traffic and certificate authentication when exploited.
The flaw allows an attacker to use a leaked HTTP API token from prohibited network locations, potentially gaining unauthorized access. This matters because it can lead to data breaches or system compromise.
This vulnerability allows a low-privileged local attacker to exploit incorrect default permissions, leading to information disclosure.
The flaw is an Incorrect Default Permissions vulnerability in Dell Command | Intel vPro Out of Band versions prior to 4.7.2, allowing a low-privileged attacker with local access to potentially exploit it for Information Disclosure.
The flaw allows any authenticated user to subscribe to real-time terminal input and output streams of proxied sessions, including sensitive data like credentials and commands.
The flaw allows an attacker to authorize themselves as another user by manipulating headers in a proxied request, potentially leading to unauthorized access.