All CVEs — page 237 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator allow unauthenticated attackers to bypass web authentication and access sensitive system functions, posing a significant risk.
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator allow unauthenticated attackers to bypass web authentication and access sensitive functions, potentially leading to data theft or system compromise.
The flaw in Node.js HTTP/2 handling can lead to a heap-use-after-free condition when `nghttp2_session_mem_send()` is called re-entrantly while `nghttp2_session_mem_recv()` is executing, which could allow attackers to crash the application or execute arbitrary code.
The vulnerability allows NoSQL injection by passing unvalidated checkpoint identifiers into MongoDB queries, potentially leaking sensitive data across tenants.
The vulnerability allows for command injection through the manipulation of the args.id argument in the remove_rule function of GL.iNet AX1800 up to 4.8.3, enabling remote attackers to execute arbitrary commands.