All CVEs — page 232 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The vulnerability in H3C NX15 V100R017 allows remote attackers to manipulate service.add via the /api/esps endpoint, leading to potential high impact exposure. This matters because it can be exploited remotely without user interaction.
The flaw allows os command injection via file argument manipulation in H3C NX15 V100R017's /api/esps endpoint, enabling remote code execution.
A stack-based buffer overflow vulnerability exists in UTT HiPER 1200GW versions up to v2.5.3-170306 due to improper handling of the timestart argument in the strcpy function. This allows remote attackers to execute arbitrary code.
The flaw allows arbitrary file write through directory traversal sequences in the filename, enabling potential data corruption or malicious code execution on affected Android devices.
The flaw is a stack-based buffer overflow in the strcpy function due to improper handling of the tempName argument, allowing remote attackers to exploit it. This matters because it can lead to arbitrary code execution.
The flaw is a stack-based buffer overflow in the strcpy function due to improper handling of the cipher argument, allowing remote attackers to exploit it. This matters because it can lead to arbitrary code execution or other severe impacts.
The vulnerability allows for SQL injection through manipulation of the keyid argument in the logindojojs file, enabling remote attackers to exploit it for unauthorized access or data theft.
The vulnerability allows for SQL injection through manipulation of the FilterString argument in the GetStoredClassByFilter function, enabling remote code execution.
The flaw in OpenSIPS allows an attacker to overflow a buffer by providing a long username, which can corrupt global data and alter the server's routing behavior.
The flaw allows admin-privileged attackers to probe internal network resources by submitting arbitrary URLs without proper validation, potentially reading sensitive information from cloud metadata services and internal APIs.
The flaw allows authenticated non-admin users to manage server-wide embedding backend configuration, leading to plaintext transmission of sensitive data or denial of service.
The flaw allows session fixation attacks due to un invalidated sessions on login in Ghost Admin versions from 2.2.0 to 6.54.1, posing a medium security risk.
The vulnerability allows a staff user to write files outside the intended directory via custom themes, potentially altering system behavior.