All CVEs — page 234 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows automation rules to cause availability issues for other users due to synchronous computation on the event loop.
This flaw allows attackers to execute arbitrary code by placing a shared object on target storage, due to incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1. This is a critical vulnerability that can lead to full system compromise.
The flaw allows an attacker to execute arbitrary commands on the system where the vulnerable Google::Auth module is running, due to the lack of proper input validation and control over the command execution.
The flaw allows server-side request forgery and credential exfiltration due to unvalidated URLs from credentials JSON.
The flaw allows a local attacker to execute arbitrary code through the vms_fixfilename() function in Vim versions up to 9.2.0389, posing a significant security risk.
The flaw allows a local attacker to execute arbitrary code through the vms_fixfilename() function in Vim versions up to 9.2.0389, posing a significant security risk.
The flaw is a stack buffer overflow in OpenSIPS due to improper handling of SIP header names, allowing remote attackers to crash the process or achieve remote code execution.
The vulnerability allows command injection through manipulation of the 'esps.apcm.version' argument in the '/api/esps' endpoint, enabling remote code execution.
The flaw allows command injection through manipulation of the workMode argument in H3C NX15 V100R017's esps.ipv6.wan function, enabling remote code execution.
The vulnerability allows command injection through manipulation of the esps.filter.url argument in the Add function of H3C NX15 V100R017's /api/esps API, enabling remote code execution.
This vulnerability allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file, leading to persistent remote code execution as the web-server process user.
This vulnerability allows unauthenticated attackers to bypass authentication by manipulating the X-Requested-With header, gaining access to admin endpoints and performing actions such as manipulating poll states and vote counts.
The flaw allows authenticated users to execute scripts in the Open WebUI origin, potentially stealing session tokens and gaining admin privileges.
The flaw allows users to bypass global routability checks by embedding IPv4 addresses in transition encodings within a NAT64 gateway, potentially exposing internal network responses.
The flaw allows unauthorized access to an Open WebUI session by exchanging a raw OAuth token, posing a significant security risk.
The flaw allows authenticated users to execute JavaScript that can access blocked internal addresses, potentially leading to data leakage in web-search or RAG output.