All CVEs — page 48 of 62
The complete archive, 25 per page, newest first. 1530 records. Search instead.
A stack-based buffer overflow vulnerability exists in Apache Lucy, allowing attackers to potentially execute arbitrary code through crafted input.
The flaw is a memory allocation vulnerability in Apache Lucy that allows for excessive size values, potentially leading to denial of service or other issues. This matters because it can be exploited if an attacker can manipulate input sizes.
The flaw is a deserialization vulnerability in Apache Lucy, allowing untrusted data to be deserialized, which can lead to remote code execution or other severe impacts. This matters because it can enable attackers to exploit the software even though it is no longer supported.
Uncontrolled recursion vulnerability in Apache Lucy allows attackers to cause a denial of service by triggering excessive memory consumption.
The flaw allows unauthenticated attackers to delete any media attachment by exploiting missing capability checks and exposed nonce values, potentially leading to complete media library destruction.
This flaw allows unauthenticated attackers to send large HTTP requests that can exhaust memory on the Rancher Manager server, leading to service disruption.
The flaw allows a malicious user to obtain long-lived registration tokens in plaintext, enabling unauthorized node registration and potential cluster compromise.
The flaw involves improper file path handling in a cookbook example, allowing for potential directory traversal attacks if copied into production code.
The flaw allows unauthorized access to customer data by bypassing company ownership checks in certain methods, enabling potential data exfiltration or modification.
The flaw allows unauthorized access to TwoFA management functions without proper authentication or permission checks, posing a significant security risk.
The flaw allows attackers to upload executable PHP files via a restricted but incomplete blacklist in file names, potentially leading to remote code execution.
The flaw allows unauthenticated attackers to modify post data and change post status due to missing capability checks in the `create_post()` function.
The flaw is a blind SQL Injection vulnerability in the TableOn plugin for WordPress, allowing unauthenticated attackers to extract sensitive database information by manipulating the `filter_data[comment_count]` parameter.
The flaw allows unauthenticated attackers to access sensitive page and post content via WordPress REST API endpoints, despite global privacy settings.