All CVEs — page 7 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw allows a use-after-free condition in Envoy's HTTP external-authorization client, leading to potential process crashes under production traffic.
The flaw allows a low-privileged attacker with local access to exploit an Incorrect Permission Assignment for Critical Resource vulnerability in Dell Command | Monitor (DCM) versions prior to 10.13.2, potentially leading to Elevation of Privileges.
The flaw allows dereferencing of a null pointer in Envoy's connection pool allocation logic, potentially leading to worker crashes under specific conditions.
The flaw allows authenticated users to bypass authorization checks in jshERP through 3.6, enabling them to manipulate user-role mappings and escalate privileges.
The flaw allows authenticated users to manipulate other users' business objects by bypassing authorization checks, potentially leading to unauthorized data modification or deletion.
The flaw allows authenticated users to modify tenant system configurations, potentially leading to unauthorized changes in company identity, stock rules, approval behavior, and printing settings.
This vulnerability allows authenticated users to read other tenants' records by exploiting a tenant isolation bypass in jshERP through version 3.6, potentially exposing sensitive data.
The flaw allows authenticated users to modify role button-permission definitions without proper authorization checks, enabling them to overwrite configurations for any role in the tenant.
The flaw allows authenticated users to retrieve unsalted MD5 password hashes, enabling attackers to perform offline cracking or direct authentication bypass.
The vulnerability allows authenticated users to reset any other user's password, granting unauthorized access. This can lead to significant data breaches and loss of control over administrative accounts.
The vulnerability allows authenticated users to escalate their privileges by sending a POST request with specific parameters, enabling them to assume arbitrary roles, including tenant administrator.
The flaw allows untrusted pointer dereference in ColorFul iGameCenter 1.0.3.4, enabling local exploitation. This matters because it can lead to arbitrary code execution.
This flaw allows a jump host key to be stored for a target address, enabling interception of user traffic and certificate authentication when exploited.
The flaw allows an attacker to use a leaked HTTP API token from prohibited network locations, potentially gaining unauthorized access. This matters because it can lead to data breaches or system compromise.
This vulnerability allows a low-privileged local attacker to exploit incorrect default permissions, leading to information disclosure.
The flaw is an Incorrect Default Permissions vulnerability in Dell Command | Intel vPro Out of Band versions prior to 4.7.2, allowing a low-privileged attacker with local access to potentially exploit it for Information Disclosure.
The flaw allows any authenticated user to subscribe to real-time terminal input and output streams of proxied sessions, including sensitive data like credentials and commands.
The flaw allows an attacker to authorize themselves as another user by manipulating headers in a proxied request, potentially leading to unauthorized access.
The flaw allows privileged users to retrieve attacker-selected resources through URL schemes or local file URIs during report rendering, leading to server-side request forgery and potential disclosure of sensitive files including credentials.