All CVEs — page 240 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows an attacker to inject SQL commands by manipulating the Line and Column parameters, leading to potential data manipulation or system compromise.
The flaw allows an attacker to inject SQL commands by manipulating user-controlled Filter request parameters, leading to potential data manipulation or system compromise.
The flaw allows remote unauthenticated clients to exhaust server memory by sending incomplete message chunks and disconnecting repeatedly, potentially crashing the server.
The flaw allows anonymous clients to access diagnostics nodes without proper authorization, exposing sensitive security information. This matters because it can lead to unauthorized access to critical system details.
The flaw allows an anonymous or low-privileged client to execute a denied method by batching it with an allowed one, bypassing authorization checks.
The flaw allows an unauthenticated remote client to exhaust monitored-item quotas by triggering a `StackOverflowError` during PubSub ExtensionObject decoding, leading to denial of service for monitored item creation.
The flaw allows an attacker to perform a padding oracle attack on RSA PKCS#1 v1.5 padding in `Basic128Rsa15`-encrypted username tokens, enabling password recovery and unauthorized access.
The flaw allows an anonymous client to bypass role-permission checks by exploiting a configuration issue in Eclipse Milo versions 1.0.0 through 1.1.4, leading to unauthorized access.
The flaw involves information disclosure in Firefox for Android and Firefox Focus for Android, potentially exposing sensitive user data.
The flaw allows external control of file names or paths in pardus-image-writer before version 0.9.0, potentially leading to removal of important client functionality.
The flaw is a stack-based buffer overflow in fbxsdk::ExtractDrive when processing maliciously crafted FBX files, allowing arbitrary code execution. This matters because it can lead to unauthorized access and system compromise.
This flaw involves a stack-based buffer overflow in the parsing of FBX files using Autodesk's FBX SDK, allowing arbitrary code execution.
The flaw allows an attacker to bypass authentication by crafting a password with non-ISO-8859-1 characters, which are silently replaced by '?'.
The flaw involves an improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie, allowing for exponential data expansion and potential denial of service.
The flaw is a cleartext storage of sensitive information and SQL Injection vulnerability in HUMANIST Digital Human Resources, which can lead to unauthorized access to sensitive data and potential data breaches.
The flaw is a session hijacking vulnerability due to sensitive query strings being exposed via GET requests. This matters because attackers can exploit it to take over user sessions.
The flaw involves hard-coded cryptographic keys in HUMANIST Digital Human Resources, allowing sensitive constants to be read from an executable. This can lead to unauthorized access to sensitive information.
This flaw allows session IDs to be reused, enabling attackers to replay sessions and potentially gain unauthorized access.
The flaw is a path traversal vulnerability that allows attackers to access sensitive files by manipulating file paths. This matters because it can lead to unauthorized data exposure.
This vulnerability allows an attacker to upload a web shell, enabling remote code execution, due to the unrestricted file upload feature in HUMANIST Digital Human Resources versions before 26.1.