All CVEs — page 59 of 62
The complete archive, 25 per page, newest first. 1530 records. Search instead.
The flaw allows notebook authors to inject a malicious base_url that exfiltrates operator API keys, compromising security.
The flaw allows unauthenticated attackers to read arbitrary files from the server filesystem by manipulating HTTP request paths, potentially exposing sensitive information.
The flaw allows remote attackers to create a denial of service by submitting a crafted expression with an unbounded loop in a TableMakeViewReq message, blocking the server event loop indefinitely.
The flaw in Perspective 5.0.0 allows unauthenticated attackers to crash the server by sending malformed protobuf messages, leading to a denial-of-service condition.
The flaw allows unauthenticated attackers to execute arbitrary commands by submitting crafted expression strings, posing a significant security risk.
The flaw allows unauthenticated command injection, enabling attackers to execute arbitrary OS commands and gain root-level access.
The flaw allows unauthenticated attackers to access device functions by exploiting an authentication bypass vulnerability in Puwell IP Camera firmware versions 2.x through 4.x.
The vulnerability allows code injection due to an unknown function in the Python Validation Handler, enabling remote attackers to exploit it for RCE. This matters because it can lead to unauthorized access and control of affected systems.
The flaw is a missing authorization vulnerability that allows privilege escalation in HAVELSAN Inc. Liman MYS versions from 2.2.3 to 2.3.1, enabling unauthorized users to gain elevated permissions. This matters because it can lead to severe system compromise and data breaches.
The flaw allows a remote peer to cause a use-after-free condition by disconnecting during an in-flight ATT PDU, leading to potential crashes.
The flaw is a stack-based out-of-bounds read vulnerability in stunnel's 's_vlog' function when handling oversized log messages. This can lead to crashes and potentially replace trailing newline characters with null bytes.
This vulnerability allows unauthorized access to functionality not properly constrained by ACLs, enabling potential data breaches or system compromises.
The flaw allows SQL injection by directly concatenating user-controlled parameters into SQL queries, enabling attackers to execute arbitrary database commands.
The flaw allows an authenticated staff user to inject arbitrary SQL, potentially reading sensitive data from various tables in the Koha database.
The flaw allows for SQL injection by directly concatenating user-controlled parameters into SQL queries without proper validation or sanitization, leading to potential data compromise.
The flaw allows for SQL injection by directly interpolating user-controlled parameters into SQL queries without validation, enabling potential database manipulation and data theft.
The flaw allows for SQL injection by directly interpolating user-controlled parameters into SQL queries, leading to potential data theft or system compromise.
The flaw allows remote unauthenticated clients to exhaust server memory by sending incomplete message chunks and disconnecting repeatedly, potentially crashing the server.
The flaw allows anonymous clients to access diagnostics nodes without proper authorization, exposing sensitive security information. This matters because it can lead to unauthorized access to critical system details.