All CVEs — page 173 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows unauthenticated attackers to crash the Icinga 2 process by sending deeply nested JSON, posing a significant risk to the availability of the service.
The flaw allows an unauthenticated attacker to replace node and CA certificates, enabling them to impersonate trusted nodes and gain control over them.
The flaw in Mnemosyne allows any well-formed token to be accepted by the sync server, bypassing signature verification, which could lead to unauthorized access to the system.
The flaw allows an attacker to execute arbitrary Python code by crafting a specific `quantization_config.quant_dtype` value, leading to remote code execution.
LMDeploy's PyTorch DistServe/PD-disaggregation control plane deserializes messages using Python pickle, allowing remote code execution if an attacker can reach the `/distserve/p2p_connect` endpoint.
This flaw in Mongoid allows unauthenticated input to trigger unintended internal method invocations, potentially leading to data loss and application unresponsiveness.
The CareCam CM2507 IP cameras use a fixed legacy password hash for the root account, making it susceptible to offline cracking. This flaw allows an attacker to recover the password, posing a significant security risk.
The CM2507 IP cameras store wireless network credentials in cleartext, allowing an attacker with filesystem access to recover sensitive information. This flaw is critical as it can lead to unauthorized network access.