All CVEs — page 65 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw in FriendsOfFlarum OAuth allows unauthenticated attackers to link their Discord account to a victim's Flarum account by exploiting the lack of email verification checks, potentially compromising user accounts, including administrator accounts.
This vulnerability allows unauthenticated users to extract database information through SQL injection by manipulating the ratings parameter in the search functionality.
The flaw allows an authenticated administrator to upload an image with a server-executable extension, leading to arbitrary command execution and other severe impacts.
The flaw allows a malicious PHP file to be executed with web-server privileges, enabling remote code execution.