All CVEs — page 159 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This vulnerability allows unauthenticated attackers to execute arbitrary code on the REDCap server by manipulating HTTP requests and exploiting survey passthrough routing and data import logic.
getID3 before 1.9.26 is vulnerable to OS command injection due to insufficient filename escaping, allowing attackers to inject arbitrary commands with process privileges.
NivoCart through 2.4.0 allows attackers with view-only back-office access to upload PHP files, leading to remote code execution.
The flaw is a stack-based buffer overflow in the get_css_path_from_uri function of the Comfast CF-N1-S 2.6.0.1 Web Management Interface, which can lead to remote code execution if exploited.