All CVEs — page 4 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw allows user-controlled display names to contain HTML, enabling script injection in post actions. This can lead to cross-site scripting (XSS) attacks.
The flaw allows a low-privileged authenticated user to create items under a share ID before acceptance, potentially injecting content into shared folders without proper authorization.
The flaw allows a low-privileged user to publish an image/svg+xml attachment with executable script content that can access same-origin data and perform actions with the victim's session if they are authenticated.
The flaw allows an attacker to gain access to a local user's Joplin account by exploiting SAML authentication, potentially leading to unauthorized access or modifications of notes and settings.
The flaw allows a low-privileged user to inject malicious JavaScript via crafted HTML notes, potentially leading to script execution in the Joplin Server origin.
This vulnerability allows an attacker to cause a denial of service by manipulating frame lengths in control responses, leading to buffer overflows and incorrect data processing.
The flaw involves a race condition in the nonce generation for secure storage operations, leading to nonce reuse with the same key, which can result in plaintext leakage and authentication key exposure.
The flaw allows for argument injection in package changelog retrieval through improperly handled user input, posing a medium security risk.
The vulnerability allows heap-based buffer overflow in the Moore Threads MTT S80 Driver Package up to version 340.150 due to improper handling of user input. This can lead to remote code execution if exploited.
The flaw in libstoragemgmt allows an attacker to cause a stack buffer overflow by providing malformed SCSI VPD page 0x80 data, leading to potential denial of service.
The flaw involves an integer overflow in FalkorDB's Redis module v4.20.1, allowing attackers to cause a Denial of Service via crafted input, which could disrupt service availability.
The flaw involves improper error handling in FalkorDB v4.20.1's GRAPH.EFFECT component, leading to a Denial of Service (DoS). This matters because attackers can exploit it to disrupt service without needing specific privileges.
The flaw in FalkorDB's graph.UDF module allows unauthorized read operations, but no write commands are registered, leading to potential data exposure and integrity issues.
The _Decode_GrB_Matrix function in FalkorDB's Redis module allows buffer overflow when processing crafted inputs, leading to potential Denial of Service (DoS).
The flaw in FalkorDB (Redis module) allows attackers to cause a Denial of Service via a stack overflow from a crafted input, impacting system availability.
The flaw in FalkorDB (Redis module) allows out-of-bounds read leading to Denial of Service via crafted input, posing a significant risk.
The flaw in FalkorDB (Redis module) allows attackers to cause a Denial of Service via a stack overflow from a crafted input, compromising system availability.