All CVEs — page 223 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows authenticated attackers with author-level access to delete arbitrary files via path traversal, potentially leading to remote code execution.
The flaw allows network attackers to access hardcoded credentials in RTSP authentication, enabling unauthorized viewing of camera footage.
The flaw allows deserialization of untrusted data, leading to potential code execution or data manipulation by authenticated users.
The flaw allows for SQL injection by misusing request parameters in Subrion CMS, enabling attackers to execute arbitrary SQL commands.
The flaw allows untrusted content to be executed as Twig templates, leading to Remote Code Execution (RCE) due to the lack of sandboxing.
The flaw allows direct access to the amp-manager REST API without going through the CAM gateway, enabling unauthorized access and potential full system compromise.
The flaw allows an attacker to inject SQL commands via the guided report builder, leading to potential data manipulation or theft.
The flaw allows an attacker to inject SQL commands by manipulating ORDER BY column names, leading to potential SQL injection attacks.
The flaw allows unauthenticated visitors to execute arbitrary JavaScript due to improper handling of user input in Matomo analytics integration, leading to potential session theft and full page takeover.
The flaw allows an admin to execute arbitrary OS commands by crafting a backup archive, leading to Remote Code Execution (RCE).
The flaw allows an attacker to execute arbitrary code by loading malicious cache/covariance files, posing a significant security risk.
The flaw allows an attacker to potentially manipulate or exploit a caller-supplied bookmark URL due to lack of validation checks, leading to potential security risks.
The flaw allows an attacker to execute arbitrary code by manipulating a file path parameter, leading to remote code execution.
The vulnerability allows an attacker to create a 'calc rule' without authentication, leading to potential unauthorized access and manipulation of the system.
The flaw allows an attacker to bypass authentication by sending any non-empty Authorization header, granting access to protected endpoints.
The flaw allows SQL injection by authenticated users due to direct interpolation of unvalidated HTTP query string values into raw SQL queries.
The flaw allows injection of malicious HTML content due to lack of sanitization and encoding, enabling cross-site scripting (XSS) attacks.
The flaw allows attackers to manipulate hostname resolution and potentially execute code by exploiting DNS rebinding or similar techniques.
The flaw lies in Memos' webhook URL validation where it fails to check for the unspecified IP address (0.0.0.0/8), potentially allowing unauthorized access. This matters because it can lead to security breaches if exploited.