All CVEs — page 153 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows an authenticated user to replace the UnsubscribeURL with an internal URL, leading to potential exposure of sensitive data and credentials.
The flaw allows a malicious package to write an executable wrapper outside the intended directory or overwrite another entry point, leading to potential code execution with the installing user's privileges.
The flaw allows a remote attacker to inject arbitrary JavaScript into an authenticated user's session via unsanitized clickable links on the msg_info page, leading to potential data theft or manipulation.
CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) allowing attackers to forge requests and potentially access internal services or networks.
The flaw is a cross-site scripting (XSS) vulnerability in CuteNews v.2.1.2 that allows remote unauthenticated attackers to inject malicious scripts via URL parameters, potentially leading to information disclosure or user manipulation.
This vulnerability allows remote authenticated users to execute arbitrary code by uploading a file with a dangerous type, leading to potential remote server access.
This flaw allows for an allow-list bypass via java.lang.reflect.Proxy, enabling unauthorized access. It matters because it can lead to remote code execution or data leakage.
The flaw is a stack-based buffer overflow in fetchmail when NTLM support is enabled, allowing a malicious server to potentially execute arbitrary code or cause service disruption.
The flaw allows authenticated users with Author-level privileges or higher to inject arbitrary HTML elements by supplying malicious wrapper attribute values, leading to cross-site scripting attacks.
The flaw allows an attacker to maintain access to an Apache Airflow instance after a user logs out, as the logout endpoint does not revoke the token when presented via an Authorization header, leaving the token valid for up to 24 hours.
This vulnerability allows an attacker to bypass intended authentication by using a session cookie and an explicit bearer token, with Airflow resolving the caller from the cookie instead of the token.
The flaw in pki-core allows wildcard ACL permissions to override more specific literal permissions, potentially enabling unauthorized access to certificate management functions.
The flaw in openshift/oc-mirror allows for PGP signature verification bypass, enabling remote attackers to forge signatures and mirror malicious release payloads into a disconnected registry.
The flaw allows any authenticated user with asset-read access to enumerate asset events for all Dags in the deployment, including those they are not authorized to see, due to missing access control filters.
The flaw allows any user with OTP 2FA enabled to reuse their TOTP during a 30-second window, potentially leading to unauthorized access.
The flaw allows unauthenticated attackers to perform a denial of service (DoS) by sending specially crafted requests that consume excessive CPU resources.
The flaw allows unauthenticated attackers to create a full admin account by exploiting a race condition in the onboarding process.
The flaw allows pipeline group administrators to test connections for source control materials outside their authorized scope, potentially exposing credentials. It also enables resolution of external secrets managed by secret-management plugins.
The flaw allows a local unprivileged user to replace a target directory with a Windows junction and symlink, enabling arbitrary privileged file deletion which can lead to SYSTEM privileges.