All CVEs — page 61 of 62
The complete archive, 25 per page, newest first. 1530 records. Search instead.
The flaw involves an embedded RSA private key in the firmware of a Lighttpd web server used for TLS termination, which can be exploited to decrypt HTTPS traffic and spoof the server.
This vulnerability allows an attacker to free a transport structure and then reuse it, leading to potential denial of service or other critical issues in SCTP associations.
The flaw involves a use-after-free vulnerability in rhashtable_walk_next due to stale pointers not being cleared properly during table restarts, allowing for potential memory corruption or crashes.
This flaw allows an attacker to free a shadow VMCS prematurely, potentially leading to kernel memory corruption or privilege escalation.
This flaw allows an attacker to cause invalid memory mappings in KVM's shadow MMU, potentially leading to system crashes or privilege escalation.
The flaw allows a multisite subsite administrator to inject and execute arbitrary PHP code by improperly escaping user-supplied text in the Create Block WordPress plugin before version 2.10.0.
The flaw allows unauthenticated users to upload executable PHP files due to improper file validation in the Improve SEO WordPress plugin, leading to remote code execution.
The flaw allows contributors to inject malicious scripts into podcast episode settings, leading to cross-site scripting attacks even when HTML filtering is disabled.
The flaw allows users with Contributor role or higher to inject arbitrary scripts by manipulating featured-image focal-point coordinates, potentially leading to cross-site scripting (XSS) attacks.
The flaw allows unauthenticated attackers to perform file management actions on connected Dropbox accounts, leading to unauthorized access and data exposure.
The flaw allows users with Contributor-level access or higher to perform Server-Side Request Forgery (SSRF) attacks, enabling them to retrieve sensitive cloud instance metadata, including IAM credentials.
The flaw allows SQL injection due to improper parameter sanitization in certain WordPress plugins, enabling administrators or users with specific capabilities to execute arbitrary database commands.