All CVEs — page 165 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This vulnerability allows for a buffer overflow through the manipulation of the submit-url argument in the formWlWds function of the Totolink A3002MU Hh-B20211125.1046 device, enabling remote code execution.
The flaw allows authenticated attackers with Contributor-level access or higher to invoke arbitrary PHP functions, potentially disclosing sensitive information or enabling server-side abuse.
The flaw allows unauthenticated attackers to execute arbitrary shortcodes, leading to potential remote code execution.
The WP Recipe Maker plugin allows unauthenticated attackers to execute arbitrary shortcodes server-side, leading to potential disclosure of sensitive data.
This flaw allows unauthenticated attackers to upload executable files via a hidden File Upload field in Gravity Forms for WordPress, leading to potential remote code execution.
SiYuan through 3.8.4 allows attackers to inject malicious style values via crafted notebooks or administrative endpoints, leading to stored cross-site scripting (XSS) attacks.
This flaw allows attackers to inject HTML payloads into notebook names, which can execute JavaScript with Node.js access when the Daily Note picker dialog opens, leading to potential operating system command execution.