All CVEs — page 151 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows privileged users to retrieve attacker-selected resources through URL schemes or local file URIs during report rendering, leading to server-side request forgery and potential disclosure of sensitive files including credentials.
The flaw allows unauthorized access to report and label printing functionalities by bypassing permission checks, exposing sensitive data.
The flaw allows any authenticated user to access another user's import session data, exposing sensitive information. This matters because it breaches data privacy despite users being considered trusted within the InvenTree system.
The flaw allows unauthenticated access to plugin settings metadata and non-secret configuration values, posing a risk of sensitive information disclosure.
The flaw allows low-privilege users to enumerate primary keys and disclose sensitive inventory data by exploiting the lack of proper role checks in the InvenTree barcode API endpoint.
The flaw allows an attacker to inject malicious JavaScript into the response, potentially leading to session hijacking and unauthorized actions. It also enables open redirects, which can be used to redirect users to malicious sites.
The flaw allows a low-privileged attacker with local access to insert sensitive information into log files, potentially leading to information disclosure.
The flaw allows an unprivileged user to write arbitrary values to kernel memory through a syscall, potentially leading to privilege escalation or system crashes.
The flaw allows for XSS in Telegram Desktop before version 6.9.4 due to improper handling of HTML export, posing a high risk if exploited.
This vulnerability allows arbitrary command execution on Windows when the envelope address is controlled by an attacker, leading to potential remote code execution as the sending process.
The flaw allows an out-of-bounds write by exploiting a usbredir isochronous OUT stream, potentially leading to arbitrary code execution or data corruption.
Users with edit permissions but without entity ownership can exploit a flaw in Graylog to gain full control over saved searches and dashboards, allowing them to delete or modify content.
The DecompressTarGz function in KubeEdge improperly validates archive entry names, allowing for potential file overwrites or modifications with elevated privileges.
The flaw allows an authenticated user to include shell metacharacters in the ConfigUpdateJob, leading to arbitrary command execution with the privileges of the KubeEdge process.
The flaw allows any authenticated user to restart any machine, even without ADMIN role, by exploiting a misconfigured API endpoint in InvenTree versions prior to 1.4.0.
The flaw allows SSRF attacks by not fully validating server URLs, enabling requests to internal addresses like loopback and cloud metadata.
The flaw allows an authenticated user to read and potentially modify notifiers belonging to other tenants, exposing sensitive credentials and redirecting notifications to attacker-controlled webhooks.
The flaw allows an authenticated low-privileged user to overwrite or delete another tenant's maintenance entry by not verifying group ownership, posing a significant security risk.
The flaw allows any authenticated user to add another account to their group without proper authorization, leading to potential unauthorized access and data exposure.
The flaw allows a user to delete another group's inventory by exploiting the global owner privilege through the X-Tenant header, leading to irreversible data loss.
The flaw in SmallRye Fault Tolerance library causes a memory leak when using ApplyGuard or ApplyFaultTolerance annotations, leading to potential application crashes due to increased memory usage.
The flaw allows any authenticated non-admin user to list and download system-configuration backups, potentially disclosing sensitive information such as password hashes and API tokens.
The flaw allows non-admin users to modify system settings and redirect threat-intelligence downloads, compromising integrity and availability.
The flaw allows any authenticated user to execute arbitrary code as root by manipulating plugin installation and uninstallation tasks, leading to full host compromise.