All CVEs — page 162 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This vulnerability allows attackers with project write access to execute arbitrary code by exploiting a flaw in the JavaScript webhook template validator, which fails to block computed member access to constructor chains.
This flaw allows an attacker to load arbitrary Perl modules by manipulating unvalidated connect attributes, leading to potential remote code execution.
The flaw allows command injection via the localPin argument in the formWsc function, enabling remote attackers to execute arbitrary commands on the device.