All CVEs — page 241 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This vulnerability allows an admin to upload and execute arbitrary files, leading to remote code execution.
This vulnerability allows a local attacker to execute arbitrary code by placing a crafted DLL in an unsafe directory, potentially leading to unauthorized access and control of the GV-ASManager process.
The flaw involves an embedded RSA private key in the Lighttpd web server firmware, allowing attackers to decrypt HTTPS traffic and spoof the server, compromising confidentiality and integrity.
The flaw involves an embedded RSA private key in the Lighttpd web server firmware, allowing attackers to decrypt HTTPS traffic and spoof the server, compromising confidentiality and integrity.
This vulnerability allows an attacker to free a transport structure in the SCTP stack, leading to potential denial of service or other attacks by exploiting the dangling pointer issue.
The flaw involves a use-after-free vulnerability in rhashtable_walk_next due to stale pointers not being cleared properly during table restarts, allowing for potential memory corruption or crashes.
This vulnerability allows an attacker to potentially free a shadow VMCS prematurely, leading to a race condition that could result in the kernel memory being freed while the vCPU is still using it, potentially leading to a denial of service or other kernel-level issues.
This flaw allows an attacker to cause a kernel memory corruption by exploiting an invalid root page fault after MMU pages are made available for the shadow MMU, potentially leading to a system crash or privilege escalation.
The flaw allows a multisite subsite administrator to inject and execute arbitrary PHP code by improperly escaping user-supplied text in the Create Block WordPress plugin before version 2.10.0.
The flaw allows unauthenticated users to upload executable PHP files, leading to remote code execution due to improper file validation.
The flaw allows contributors to inject malicious scripts into podcast episode settings, leading to cross-site scripting attacks even when HTML filtering is disabled.
The flaw allows users with Contributor role or higher to inject arbitrary scripts by manipulating featured-image focal-point coordinates, potentially leading to cross-site scripting (XSS) attacks.
The flaw allows unauthenticated attackers to list, download, and upload files across the connected Dropbox account, and read connected account and administrator email addresses, due to missing authorization checks in the Easy Integration for Dropbox WordPress plugin before 2.2.0.