All CVEs — page 156 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows for authorization bypass through manipulation of the ID argument in the User Profile API, enabling unauthorized access to user data.
A vulnerability allows for missing authentication by manipulating the argument roleId in the Role Permission API's /role-permission/permission endpoint, posing a risk to system security.
The flaw allows unauthenticated users to mark their own orders as paid by using a genuine transaction from a payment sandbox they control, bypassing order verification.
The flaw allows unauthenticated users to create arbitrary published posts and taxonomy terms by exploiting a lack of authorization and nonce checks in the import routine.
The flaw allows unauthenticated users to execute arbitrary shortcodes by nesting them, potentially leading to remote code execution or data leakage.
The flaw allows unauthenticated users to manipulate item prices in the RestroPress WordPress plugin, potentially placing orders with arbitrary totals or zero value.
The flaw allows a user with sufficient privileges to perform unintended operations on the host filesystem by exploiting container checkpoint and restore functionality.
The vulnerability allows manipulation of the argument roleId to improperly control resource identifiers, potentially leading to unauthorized access or data exposure.
The flaw allows for memory exhaustion due to uncontrolled decompression of data with high compression ratios, potentially leading to denial of service.
The flaw allows users to bypass mandatory two-factor authentication by manually visiting a session restart link, gaining unauthorized access.
The flaw allows administrators with limited privileges to read or modify sensitive client configurations in the master realm by accessing them through a controlled realm, potentially exposing client credentials.
The flaw allows a delegated administrator with limited viewing privileges to access full user profiles and roles, exposing sensitive information.
The flaw allows an attacker to manipulate the PhysicalAddress/Size argument, leading to a write-what-where condition, which can be exploited locally to gain unauthorized access or control.
A cross-site scripting vulnerability exists in xxl-job versions up to 3.4.2/3.5.0 due to improper input handling, allowing attackers to inject malicious scripts via job names or authors.
The flaw allows SQL injection by manipulating the filter argument in drogonframework's makeCriteria function, posing a high risk due to remote exploitability.
The flaw allows an attacker to access a user’s session by controlling a privileged WebView, posing a high security risk.
The flaw allows unauthenticated attackers to upload arbitrary files, including PHP files, to execute code on the server, due to lack of file type and extension validation.
The vulnerability allows SQL injection through manipulation of the sort argument in the Mapper::orderBy function, posing a high risk due to remote exploitability.
The vulnerability allows local manipulation of the PhysicalAddress argument, leading to a write-what-where condition in the BioStar Temperature Monitor Utility 1.2.1806.2200. This can result in arbitrary code execution.