All CVEs — page 45 of 62
The complete archive, 25 per page, newest first. 1530 records. Search instead.
The flaw allows SQL injection by improperly sanitizing user input and directly concatenating it into a SQL query.
The flaw allows attackers to inject malicious shell commands by directly concatenating user-controlled input, leading to remote code execution.
The flaw allows any authenticated user to manipulate notes from other companies due to missing company-ownership checks, posing a significant security risk.
The flaw allows unauthorized access to sensitive API endpoints by enumerating card_id values, compromising user data security.
The flaw allows attackers to inject malicious code through user-controlled EmlMessage fields, leading to potential remote code execution.
The flaw involves a hardcoded Django SECRET_KEY in the codebase, allowing attackers to forge session cookies and tokens, leading to full account takeover.
The flaw allows unauthenticated attackers to bypass authentication and potentially extract database data through SQL injection.
The flaw allows for injection of HTML entities that are later improperly decoded, potentially leading to Cross-Site Scripting (XSS) attacks.
The flaw allows authenticated users to execute arbitrary Go or Lua scripts server-side, leading to Remote Code Execution (RCE). This matters because it can enable attackers to gain full control over the system.
The flaw allows unauthorized access to document downloads by merely providing a non-empty query parameter, leading to potential data exposure.
The flaw allows untrusted input to be executed as HTML in the client portal, enabling cross-site scripting (XSS) attacks.
The flaw allows execution of dangerous PHP functions in template content due to incomplete blacklist filtering, enabling remote code execution.
The flaw allows an attacker to execute arbitrary SQL commands by exploiting improper input sanitization in the authentication query construction.
The Zbtlink router firmware includes an embedded implant called ENDLESSDOORS that provides unauthenticated remote code execution as root over cleartext TCP to a hardcoded C2 server.
The flaw allows unauthenticated file uploads to any writable path on the server, potentially leading to remote code execution by overwriting critical files.
The flaw allows unauthenticated attackers to read arbitrary files by manipulating path parameters in the `/hostedPlugin` endpoint, due to improper path resolution.
A privilege escalation vulnerability allows authenticated users to gain full administrative access, bypassing role restrictions.
The flaw allows unauthorized access to sensitive information via the /network/graph API due to missing authentication, posing a significant security risk.