All CVEs — page 6 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw allows execution of malicious scripts through un-sanitized Fountain code blocks, posing a risk to user data and server security.
Joplin allows attackers to write files outside the intended directory due to unvalidated resource metadata, posing a risk of data leakage or corruption.
The flaw allows an attacker to replace update metadata and installers, leading to potential code execution with user privileges.
The flaw allows unfiltered URLs in notes to disclose NTLMv2 credentials via KaTeX's trust option, enabling attackers to exploit this through SMB authentication.
The flaw allows an unauthenticated attacker to cause memory exhaustion in Redis, leading to a denial-of-service condition.
The flaw allows a low-privileged local attacker to execute code and gain higher privileges by exploiting an unquoted search path vulnerability in Dell Inventory Collector Client versions prior to 15.0.0.
The flaw allows a downstream client to bypass RBAC policies by manipulating opaque headers, potentially allowing unauthorized access to routes intended for denial.
The flaw allows unauthenticated clients to exploit HPACK indexing to submit large Host values, causing out-of-memory issues in Envoy proxies.
The flaw allows reconstruction of scoped IPv6 addresses leading to process termination in specific configurations; it matters because it can disrupt service availability.
The flaw allows an unauthenticated HTTP/2 client to smuggle a complete HTTP/1.1 request and response through Envoy, potentially intercepting sensitive data. This matters because it can lead to unauthorized access and data exposure.
The flaw allows an unauthenticated client to crash Envoy by sending a path-less CONNECT request, exploiting misconfiguration of query-parameter mutation in the ext_authz filter.
The flaw allows attacker-controlled path segments to be incorporated into cached dynamic statistic names, enabling script execution with admin interface privileges.
The flaw allows a malformed HTTP/2 response trailer to crash Envoy, potentially leading to service disruption.
The flaw allows HTTP/3 datagrams to call decodeData through a freed decoder, causing process crashes. It matters because it can lead to service disruptions and security vulnerabilities.
The flaw allows a client with presence.write permission but denied presence.read to receive presence metadata from other clients, potentially exposing sensitive information like location and online status.
The flaw allows an attacker to bypass multi-factor authentication (MFA) and gain full access by successfully guessing a TOTP code or directly disabling MFA.
The flaw allows an attacker with stolen or phished credentials to bypass two-factor authentication (2FA) in a single request by exploiting the `POST /api/auth/token` endpoint before version 2.4.0, enabling unauthorized access.
The flaw allows an authenticated user with specific permissions to execute arbitrary commands as root via a crafted request through the luci-app-advanced-reboot web interface.
The flaw allows authenticated delegated users to inject malicious cron entries, leading to potential remote code execution as root.
The flaw allows unauthenticated users to manipulate the redirect_uri parameter, leading to potential phishing attacks or unauthorized redirects outside Tautulli.