All CVEs — page 31 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw allows a pre-authentication attacker to cause resource exhaustion by leveraging unbounded symbol value caching, leading to denial of service.
The flaw involves type size/count handling which can lead to excessive memory allocation, causing a denial of service. This matters because attackers without authentication can exploit it to disrupt services.
The flaw involves improper type size/count handling that can lead to excessive memory allocation, potentially causing a denial of service.
The flaw involves unbounded symbol value caching which can lead to resource exhaustion and denial of service. This matters because attackers can exploit it without authentication.
The flaw involves improper type size/count handling which can lead to excessive memory allocation, potentially causing a denial of service. This matters because attackers can exploit it without authentication to disrupt services.
The flaw allows a pre-authentication attacker to cause resource exhaustion through unbounded symbol value caching, leading to denial of service.
The vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting an Unquoted Search Path or Element flaw.
The flaw allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by manipulating search paths, posing a significant security risk.
The flaw involves type size/count handling which can lead to excessive memory allocation, potentially causing a denial of service. This matters because attackers without authentication can exploit it to disrupt services.
The flaw allows a pre-authentication attacker to cause resource exhaustion by leveraging unbounded symbol value caching, leading to potential denial of service.
This vulnerability allows command injection through manipulation of the my2P4key argument in the esps.wan.repeater.set/repeaterproc function, enabling remote code execution.
The flaw allows unauthenticated attackers to exploit a privilege escalation vulnerability by submitting a crafted POST request with a nonce from a public subscription confirmation email, potentially creating an administrator account.
The flaw allows unauthenticated attackers to inject arbitrary scripts via the customer email field in the booking checkout form due to insufficient input sanitization and output escaping.
The flaw allows an authenticated contributor to inject SQL through the Admin Search AJAX request, enabling time-based blind SQL injection. This matters because it can lead to database compromise without full admin privileges.
The flaw allows unauthenticated attackers to inject SQL queries and read sensitive data from the database, including WordPress user credentials.
The flaw is a SQL Injection vulnerability in the ERP: Complete HR, Accounting & CRM Suite plugin due to insufficient parameter escaping and direct query interpolation, allowing authenticated attackers with specific roles to extract sensitive information from the database.
The vulnerability in H3C NX15 V100R017 allows remote attackers to manipulate service.add via the /api/esps endpoint, leading to potential high impact exposure. This matters because it can be exploited remotely without user interaction.
The flaw allows os command injection via file argument manipulation in H3C NX15 V100R017's /api/esps endpoint, enabling remote code execution.
The CVE-2026-18898 flaw in UTT HiPER 1200GW allows remote attackers to exploit a stack-based buffer overflow via the timestart parameter, leading to potential code execution or system compromise.
The flaw allows arbitrary file write through directory traversal sequences in the filename, enabling potential data corruption or malicious code execution on affected Android devices.