All CVEs — page 226 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows unauthenticated attackers to read arbitrary files by manipulating path parameters in the `/hostedPlugin` endpoint, due to improper path resolution.
A privilege escalation vulnerability allows authenticated users to gain full administrative access, bypassing role-based access controls.
The flaw allows unauthorized access to sensitive information via the /network/graph API due to missing authentication, posing a significant security risk.
The flaw allows a user with namespace-scoped 'edit' privileges to create a Subscription resource that includes cluster-scoped resources, leading to full cluster-admin privilege escalation.
The flaw allows a tenant administrator with namespace-scoped privileges to escalate their permissions by creating a namespaced ClusterCurator, leading to full cluster control.
The flaw allows authenticated attackers with Administrator-level access to execute arbitrary OS commands as the web-server user through insufficient sanitization of the `file` POST parameter in the Backup Migration plugin for WordPress.
The flaw allows authenticated attackers with Subscriber-level access to modify data by relinking MailMunch integration, leading to unauthorized access to subscriber data.
The flaw allows unauthenticated attackers to delete search-term records via a Cross-Site Request Forgery attack, compromising user data.
The flaw allows path traversal by not validating the resolved file path after using path.resolve, potentially leading to unauthorized access or execution of files.
The flaw allows an attacker to bypass authentication by manipulating the session_variables object in the request body, overriding the Authorization header's JWT claims without verification.
The flaw allows an attacker to perform unlimited password-guessing attempts against any account, including administrators, due to the absence of rate-limiting or account lockout mechanisms when the captcha is disabled, which is the default configuration.
The flaw allows an attacker to inject arbitrary API endpoints, potentially leading to unauthorized access or data exfiltration.
The flaw allows unauthenticated access to sensitive resources via URL-encoded paths, potentially enabling unauthorized data exposure.
The flaw allows direct SQL injection due to lack of parameterization and escaping, and includes hardcoded admin credentials, enabling full authentication bypass.
The flaw allows attackers to manipulate JWT tokens and gain unauthorized access to user accounts without revalidating them from the database.