All CVEs — page 239 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows notebook authors to inject a malicious base_url that exfiltrates operator API keys, compromising security.
The flaw allows unauthenticated attackers to read arbitrary files from the server filesystem by manipulating HTTP request paths, potentially exposing sensitive information.
The flaw allows remote attackers to create a denial of service by submitting a crafted expression with an unbounded loop in a TableMakeViewReq message, blocking the server event loop indefinitely.
The flaw in Perspective 5.0.0 allows unauthenticated attackers to crash the server by sending malformed protobuf messages, leading to a denial-of-service condition.
The flaw allows unauthenticated attackers to execute arbitrary commands by submitting crafted expressions to the PolarsVirtualServer backend, leveraging Python's eval() function.
The flaw allows unauthenticated command injection, enabling attackers to execute arbitrary OS commands and achieve root-level code execution, compromising the device.
The flaw allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456, leading to unauthorized access to live video streams and control of device features.
The vulnerability allows code injection due to an unknown function in the Python Validation Handler, enabling remote attackers to exploit it for RCE. This matters because it can lead to unauthorized access and control of affected systems.
A missing authorization vulnerability in HAVELSAN Inc. Liman MYS allows privilege escalation, enabling unauthorized users to perform actions with elevated privileges.
The flaw allows a remote peer to cause a use-after-free condition by disconnecting during an in-flight ATT PDU, leading to potential crashes.
The flaw is a stack-based out-of-bounds read vulnerability in stunnel's 's_vlog' function when handling oversized log messages. This can lead to crashes and potentially replace trailing newline characters with null bytes.
The flaw is a missing authorization vulnerability that allows unauthorized access to functionality not properly constrained by ACLs, potentially enabling attackers to perform actions they should not be able to.
The flaw allows for SQL injection by directly concatenating user-controlled parameters into SQL queries, leading to potential data compromise, manipulation, and system disruption.
The flaw allows an authenticated staff user with reports module permission to inject arbitrary SQL, potentially reading sensitive data from various tables.
The flaw allows an attacker to inject SQL code by manipulating user-controlled parameters, leading to potential data compromise, integrity issues, and availability problems.