All CVEs — page 225 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows an attacker to bypass authentication by directly manipulating the SQL query through unescaped POST parameters, leading to unauthorized access.
The flaw allows SQL injection by improperly sanitizing user input and directly concatenating it into a SQL query.
The flaw lies in the backmeup npm package, which directly concatenates user-provided values into shell commands, leading to potential command injection. This is significant because it allows an attacker to execute arbitrary commands, compromising the system.
The flaw allows any authenticated user to manipulate notes from other companies due to missing company-ownership checks, posing a significant security risk.
The flaw allows unauthorized access to sensitive API endpoints by enumerating card_id values, compromising user data security.
The flaw allows attackers to inject malicious code through user-controlled EmlMessage fields, leading to potential remote code execution.
The flaw lies in DjangoCRM hardcoding the Django SECRET_KEY in the settings.py file, allowing anyone to read the public repository to forge session cookies, CSRF tokens, and password reset tokens, leading to full account takeover.
The flaw allows an unauthenticated attacker to bypass authentication and potentially extract database data via SQL injection, posing a critical security risk.
The flaw lies in the manual reversal of HTML entity encoding after purification with HTMLPurifier, potentially allowing for injection of malicious scripts.
The flaw allows authenticated users to execute arbitrary Lua scripts, leading to remote code execution (RCE) and potential data exfiltration or system compromise.
The flaw allows unauthorized access to document downloads by merely providing a non-empty query parameter, leading to potential data exposure.
The flaw allows an attacker to inject malicious HTML into the client portal by exploiting the raw output directive in the 'terms' field, leading to Cross-Site Scripting (XSS).
The flaw allows execution of dangerous PHP functions in template content due to incomplete blacklist filtering, enabling remote code execution.
The flaw allows an attacker to execute arbitrary SQL commands by injecting malicious input into the decoded cookie value, leading to potential unauthorized access to user data.
The Zbtlink router firmware contains an embedded implant called ENDLESSDOORS that provides unauthenticated remote code execution as root, posing a critical security risk.
The flaw allows an attacker to perform unauthenticated arbitrary file writes outside the workspace, potentially leading to remote code execution.