All CVEs — page 222 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This flaw allows a malicious authenticated client to execute arbitrary code with root privileges on the switch via a specially crafted request to the gRPC Network Management Interface (gNMI). This is a high-risk vulnerability due to the potential for complete system compromise.
The flaw is an XML External Entity (XXE) injection vulnerability in IBM QRadar versions 7.6.0.0 to 7.6.0.1 and 7.5.0 to 7.5.0 UP 15 Interim Fix 005, allowing attackers to inject malicious XML content and potentially access sensitive information.
The flaw allows a malicious TLS server to cause a memory leak in a client that checks OCSP responses, potentially leading to Denial of Service.
The flaw allows any authenticated user to overwrite files and subscribe to WebSocket events, enabling data exfiltration and poisoning.
The flaw in Keycloak's Dynamic Client Registration component allows attackers to write values to sensitive claim locations, potentially forging administrative roles and gaining full control over the realm.
The flaw in Keycloak's PathMatcher allows attackers to bypass security policies by manipulating URLs, granting unauthorized access.
This vulnerability allows a low-privileged user to escalate privileges by creating symlinks during CCleaner uninstallation, potentially gaining SYSTEM access. It matters because it can lead to unauthorized system control.
The flaw allows unauthenticated attackers to modify and disclose data through REST API endpoints due to lack of proper permission checks.
Mistral Vibe before 2.23.3 allows attackers to execute arbitrary commands by embedding a malicious core.fsmonitor hook in a repository's .git/config file, posing a significant risk to system security.
The flaw allows unauthenticated attackers to inject arbitrary scripts via the 404 not_found_url parameter, leading to cross-site scripting (XSS). This matters because it can be exploited to steal user data or manipulate web pages.
The flaw in Keycloak's SAML metadata import functionality allows unauthenticated attackers to forge SAML responses and gain unauthorized access by exploiting missing usage attributes for keys.