All CVEs — page 242 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows users with Contributor-level access or higher to perform Server-Side Request Forgery (SSRF) attacks, enabling them to retrieve sensitive cloud instance metadata, including IAM credentials.
The flaw allows SQL injection due to improper parameter sanitization in certain WordPress plugins, enabling administrators or users with specific capabilities to execute arbitrary database commands.
The flaw allows unauthenticated attackers to forge cookie-consent records and flood privacy-request queues, potentially leading to data misuse.