All CVEs — page 204 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw in @fastify/proxy-addr allows unauthenticated clients to manipulate the X-Forwarded-For header, bypassing IP-based access control, rate limiting, geolocation, and audit logging.
The flaw allows an authenticated user to execute arbitrary code by manipulating the mkdocs.yml configuration, posing a significant security risk.
The flaw allows an authenticated user to bypass authorization and invoke any DWR method, leading to potential unauthorized access to restricted functionalities.
The flaw allows an attacker with low privileges to execute arbitrary code via the Scripting Sandbox Bypass in ScadaLTS 2.8.1-release-candidate build 0, due to lack of authorization checks.
This flaw allows a local, low-privileged attacker to escape file isolation and escalate privileges by modifying security descriptors of virtualized files, potentially leading to SYSTEM-level access.