All CVEs — page 34 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
This vulnerability allows an attacker to execute arbitrary commands with the privileges of the application process by manipulating external_account credentials JSON.
The flaw allows server-side request forgery and credential exfiltration due to unvalidated URLs from credentials JSON.
The flaw allows a local attacker to execute arbitrary code through the vms_fixfilename() function in Vim versions up to 9.2.0389, posing a significant security risk.
The flaw allows a local attacker to execute arbitrary code through the vms_fixfilename() function in Vim versions up to 9.2.0389, posing a significant security risk.
The flaw is a stack buffer overflow in OpenSIPS due to unbounded copying of SIP header names into a fixed-size buffer, allowing remote code execution via crafted SIP messages.
The vulnerability allows command injection through manipulation of the 'esps.apcm.version' argument in the '/api/esps' endpoint, enabling remote code execution.
The flaw allows command injection through manipulation of the workMode argument in H3C NX15 V100R017's esps.ipv6.wan function, enabling remote code execution.
The vulnerability allows command injection through manipulation of the esps.filter.url argument in the Add function of H3C NX15 V100R017's /api/esps API, enabling remote code execution.
The flaw allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file via crafted POST requests, leading to persistent remote code execution.
The flaw allows unauthenticated attackers to access admin endpoints by exploiting an authentication bypass in the AJAX dispatcher, enabling unauthorized actions such as manipulating poll states and vote counts.
The flaw allows authenticated users to execute scripts in the Open WebUI origin, potentially stealing session tokens and gaining admin privileges.
The flaw allows users to bypass global routability checks by embedding IPv4 addresses in transition encodings within a NAT64 gateway, potentially exposing internal network responses.
The flaw allows unauthorized access to an Open WebUI session by exchanging a raw OAuth token, posing a significant security risk.
The flaw allows authenticated users to execute JavaScript that can access blocked internal addresses, potentially leading to data leakage in web-search or RAG output.