All CVEs — page 196 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows attackers to inject malicious HTML into document titles, leading to potential script execution in the Electron renderer with access to child_process for command execution.
SiYuan versions before 3.8.4 fail to properly escape HTML in bookmark labels, allowing attackers to inject scripts that can execute commands via the Electron renderer.
The flaw allows an unauthenticated attacker to exploit a JSESSIONID vulnerability in Opencast versions prior to 19.7 and 20.2, leading to session hijacking and potential full administrative account takeover.
The flaw allows an attacker to authenticate with a victim's email and bind their external identity to the victim's account, exposing sensitive information and permitting account changes or orders as the victim.
The flaw allows an attacker to inject and execute arbitrary scripts via administrator-controlled descriptions, potentially compromising the viewing administrator's session.