All CVEs — page 171 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This vulnerability allows an unauthenticated attacker to inject SQL queries and read arbitrary database content, including sensitive credential tables.
The flaw allows an unauthenticated party to obtain sensitive data and permanently delete documents by manipulating field names in query methods, posing a significant security risk.
The flaw allows an unauthenticated attacker to inject server-side JavaScript code into MongoDB queries via the Mongoid ORM, potentially leading to data exposure and performance degradation.