All CVEs — page 22 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw is an XML External Entity (XXE) injection vulnerability in IBM QRadar versions 7.6.0.0 to 7.6.0.1 and 7.5.0 to 7.5.0 UP 15 Interim Fix 005, allowing attackers to inject malicious XML content and potentially access sensitive information.
The flaw allows a malicious TLS server to cause a memory leak in a client that checks OCSP responses, potentially leading to Denial of Service.
The flaw allows any authenticated user to overwrite files and subscribe to WebSocket events, enabling data exfiltration and poisoning.
The flaw in Keycloak's Dynamic Client Registration component allows attackers to write values to sensitive claim locations, potentially forging administrative roles and gaining full control over the realm.
The flaw in Keycloak's PathMatcher allows attackers to bypass security policies by manipulating URLs, granting unauthorized access.
This vulnerability allows a low-privileged user to escalate privileges by creating symlinks during CCleaner uninstallation, potentially gaining SYSTEM access. It matters because it can lead to unauthorized system control.
The flaw allows unauthenticated attackers to modify and disclose data through REST API endpoints due to lack of proper permission checks.
Mistral Vibe before 2.23.3 allows attackers to execute arbitrary commands via a malicious .git/config file, posing a significant security risk.
The flaw allows unauthenticated attackers to inject arbitrary scripts via the 404 not_found_url parameter, leading to cross-site scripting (XSS). This matters because it can be exploited to steal user data or manipulate web pages.
The flaw in Keycloak's SAML metadata import functionality allows unauthenticated attackers to forge SAML responses and gain unauthorized access by exploiting missing usage attributes for keys.
The flaw allows authenticated attackers with author-level access to delete arbitrary files via path traversal, potentially leading to remote code execution.
The flaw allows network attackers to access hardcoded credentials in RTSP authentication, enabling unauthorized viewing of camera footage.
The flaw allows deserialization of untrusted data, leading to potential code execution or data manipulation by authenticated users.