All CVEs — page 23 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw allows for SQL injection by misusing request parameters in Subrion CMS, enabling attackers to execute arbitrary SQL commands.
The flaw allows untrusted content to be executed as Twig templates without sandboxing, enabling Remote Code Execution (RCE).
The flaw allows direct access to the amp-manager REST API without going through the CAM gateway, enabling unauthorized access and potential full system compromise.
The flaw allows SQL injection by directly concatenating unvalidated input into an SQL ORDER BY clause without proper allowlisting or validation, leading to potential data manipulation and theft.
The flaw allows SQL injection by not properly sanitizing ORDER BY column names, enabling attackers to execute arbitrary SQL commands.
The flaw allows unauthenticated visitors to execute arbitrary JavaScript due to improper handling of user input in Matomo analytics integration, leading to potential session theft and full page takeover.
The flaw allows an admin to execute arbitrary OS commands by crafting a backup archive, leading to Remote Code Execution (RCE).
The flaw allows attackers to execute arbitrary code by providing malicious cache/covariance files, as the torch.load function is called without weights_only=True, bypassing safety checks.
The flaw allows an attacker to potentially manipulate or exploit a caller-supplied bookmark URL due to lack of validation checks, leading to potential security risks.
The flaw allows an attacker to execute arbitrary code by manipulating a file path parameter, leading to remote code execution.
The flaw allows creating a 'calc rule' without authentication, enabling unauthorized access and potential manipulation of critical data.
The flaw allows an attacker to bypass authentication by sending any non-empty Authorization header, granting unauthorized access to protected endpoints.
The flaw allows SQL injection by authenticated users due to direct interpolation of unvalidated HTTP query string values into raw SQL queries.
The flaw allows injection of malicious HTML content due to lack of sanitization and encoding, enabling cross-site scripting (XSS) attacks.
The flaw allows attackers to manipulate hostname resolution and potentially execute code by exploiting DNS rebinding or similar techniques.
The flaw lies in Memos' webhook URL validation where it fails to check for the unspecified IP address (0.0.0.0/8), potentially allowing unauthorized access. This matters because it can lead to security breaches if exploited.
The flaw allows an attacker to exploit SSRF in Stirling-PDF by targeting unsecured conversion endpoints, leading to potential data exposure.
The flaw allows an attacker to traverse directories and potentially execute arbitrary code by manipulating path parameters in Node-RED's local-filesystem library storage module.
The flaw allows attackers to execute arbitrary code by manipulating file paths in uploaded Structured Text files, due to lack of proper validation.
The flaw allows an attacker to overwrite critical data on the stack by supplying a long entry name, potentially leading to remote code execution.