All CVEs — page 26 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw allows a user with namespace-scoped 'edit' privileges to create Subscription resources that can escalate their privileges to full cluster-admin access, bypassing intended security controls.
The flaw allows a tenant administrator with namespace-scoped privileges to exploit a vulnerability in the Multicluster Engine for Kubernetes ClusterCurator controller, leading to privilege escalation and full control over the cluster.
The flaw allows authenticated attackers with Administrator-level access to execute arbitrary OS commands as the web-server user through insufficient sanitization of the `file` POST parameter in the Backup Migration plugin for WordPress.
The flaw allows authenticated attackers with Subscriber-level access to modify data by relinking MailMunch integration, leading to unauthorized access to subscriber data.
The flaw allows unauthenticated attackers to delete search-term records via a Cross-Site Request Forgery attack, compromising user data.
The flaw allows path traversal by not validating the resolved file path after using path.resolve, potentially leading to unauthorized access or execution of files.
The flaw allows an attacker to bypass authentication by manipulating the session_variables object in the request body instead of using the Authorization header's JWT claims.
The flaw allows unauthenticated attackers to perform unlimited password-guessing attacks due to lack of rate-limiting or account lockout mechanisms when captcha is disabled by default.
The flaw allows an attacker to inject arbitrary API endpoints, potentially leading to unauthorized access or data exfiltration.
The flaw allows unauthenticated access to sensitive resources via URL-encoded paths, potentially enabling unauthorized data exposure.
The flaw allows direct SQL injection due to unparameterized query construction and hardcoded credentials, enabling unauthorized access.
The flaw allows attackers to manipulate JWT tokens and gain unauthorized access to user accounts without revalidating them from the database.
The flaw allows for potential out-of-bounds memory access due to improper validation of offset parameters in the crop function, which could lead to arbitrary code execution if exploited.