All CVEs — page 231 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows authenticated attackers with Vendor/Seller-level access to read, modify, or delete any WordPress user, including administrators, via REST API requests. This is due to a missing authorization check in the Dokan plugin's CustomersController.
The flaw allows authenticated attackers with Subscriber-level access or higher to export sensitive data, including secret keys for payment gateways and reCAPTCHA.
The flaw allows a pre-authentication attacker to cause resource exhaustion by leveraging unbounded symbol value caching, leading to denial of service.
The flaw involves type size/count handling which can lead to excessive memory allocation, causing a denial of service. This matters because attackers without authentication can exploit it to disrupt services.
The flaw involves improper type size/count handling that can lead to excessive memory allocation, potentially causing a denial of service.
The flaw involves unbounded symbol value caching which can lead to resource exhaustion and denial of service. This matters because attackers can exploit it without authentication.
The flaw involves improper type size/count handling which can lead to excessive memory allocation, potentially causing a denial of service. This matters because attackers can exploit it without authentication to disrupt services.
The flaw allows a pre-authentication attacker to cause resource exhaustion through unbounded symbol value caching, leading to denial of service.
The vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting an Unquoted Search Path or Element flaw.
The flaw allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by manipulating search paths, posing a significant security risk.
The flaw involves type size/count handling which can lead to excessive memory allocation, potentially causing a denial of service. This matters because attackers without authentication can exploit it to disrupt services.
The flaw allows a pre-authentication attacker to cause resource exhaustion by leveraging unbounded symbol value caching, leading to potential denial of service.
This vulnerability allows command injection through manipulation of the my2P4key argument in the esps.wan.repeater.set/repeaterproc function, enabling remote code execution.
The flaw allows unauthenticated attackers to exploit a privilege escalation vulnerability by submitting a crafted POST request, leading to the creation of a WordPress Administrator account.
The flaw allows unauthenticated attackers to inject arbitrary scripts via the customer email field in the booking checkout form due to insufficient input sanitization and output escaping.
The flaw allows an authenticated contributor to inject SQL through the Admin Search AJAX request, enabling time-based blind SQL injection. This matters because it can lead to database compromise without full admin privileges.
The flaw allows unauthenticated attackers to inject SQL queries and read sensitive data from the database, including WordPress user credentials.
The flaw is a SQL Injection vulnerability in the ERP: Complete HR, Accounting & CRM Suite plugin due to insufficient parameter escaping and direct query interpolation, allowing authenticated attackers with specific roles to extract sensitive information from the database.