All CVEs — page 37 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw allows unauthenticated attackers to bypass web authentication and access sensitive system functions via the REST API, posing a significant security risk.
The flaw allows unauthenticated attackers to bypass web authentication and access sensitive system functions via the REST API, posing a significant security risk.
The flaw in Node.js HTTP/2 handling can lead to a heap-use-after-free condition when `nghttp2_session_mem_send()` is called re-entrantly while `nghttp2_session_mem_recv()` is executing, which could allow attackers to crash the application or execute arbitrary code.
The vulnerability allows NoSQL injection by passing unvalidated checkpoint identifiers into MongoDB queries, potentially leaking sensitive data across tenants.
The vulnerability allows command injection via manipulation of args.id in remove_rule function, enabling remote code execution.