All CVEs — page 2 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection due to deserialization of untrusted input, allowing attackers to inject a PHP object and potentially execute arbitrary code if certain conditions are met.
The flaw allows unauthenticated attackers to escalate privileges to Administrator by manipulating shortcode attributes and updating post_content.
The vulnerability allows for missing authentication in the processing of /index.html via WebSocket Service, enabling remote attackers to exploit it.
The flaw allows SQL injection via manipulation of the operator argument in Yonyou U8cloud 5.x's OpenAPI module, enabling remote code execution.
The flaw is a SQL injection vulnerability in Yonyou KSOA 9.0 due to improper argument handling in search_list.jsp, allowing remote attackers to execute arbitrary SQL commands. This matters because it can lead to data theft or corruption.
The flaw allows unauthenticated attackers to craft a malicious link that can exfiltrate sensitive information from an authenticated user's session in SAP Fiori Launchpad.
The flaw allows for os command injection through manipulation of the argument command in OctoPrint's Command API, enabling remote code execution.
The vulnerability allows path traversal through manipulation of the filename argument in OctoPrint's File Download API, enabling unauthorized access to files.
The vulnerability allows for cross-site scripting due to improper input handling in the Name argument of the /jobgroup/insert function, enabling remote attackers to inject malicious scripts.