All CVEs — page 9 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw allows unauthenticated attackers to trigger a global login lockdown by sending POST requests with nonexistent usernames, leading to HTTP 429 rate limiting for legitimate users.
The flaw allows an authenticated low-privilege user to bypass per-app access controls by using a differently cased hostname, potentially gaining unauthorized access. This matters because it undermines security measures designed to restrict access based on case-insensitive hostnames.
The flaw allows unauthenticated requests to inject traversal segments and access unintended internal routes, potentially exposing sensitive endpoints.
The flaw allows an attacker to hijack a victim's draw.io session by exploiting OAuth callback handling in self-hosted deployments, leading to potential misattribution of cloud-storage actions.
The flaw allows an attacker to forge server-side requests by manipulating DNS resolutions, potentially exposing internal network resources through a proxy.
The flaw allows any authenticated user to modify protected records without proper authorization checks, leading to potential data corruption or service disruption.
The flaw allows unauthenticated clients to manipulate or remove critical headers like ClientIPHeader, TLSHeader, and RequestID before they reach the backend service, potentially undermining security measures.
The flaw in Dasel allows an attacker to cause a panic due to index-out-of-range errors by providing input ending in whitespace. This matters because it can lead to service disruption.
The flaw allows authenticated users to inject shell metacharacters into command parameters, leading to arbitrary command execution with upgrade process privileges.
The flaw allows an authenticated edge peer to cause memory exhaustion and disrupt cloud-edge communication by sending crafted headers with excessive declared lengths.
The flaw allows deep nesting of JSON or XML data to exhaust the Go goroutine stack, leading to a fatal error. This matters because it can cause service disruption without proper mitigation.
A vulnerability allows execution of attacker-controlled JavaScript when processing crafted .drawio files, potentially exposing sensitive data and cookies.
This flaw allows an attacker to cause an out-of-bounds write by setting a length field in the doorbell register beyond the buffer size, leading to potential static memory corruption.
This flaw allows a malicious USB device to cause a double-free vulnerability by manipulating descriptor responses during device enumeration, potentially leading to system instability or crashes.
The flaw allows an authenticated tenant worker to retrieve durable event-log records from another tenant by exploiting a lack of tenant filter in the WorkerStatus gRPC polling path.
The flaw allows an unauthenticated attacker to spoof trusted proxy identity and bypass authentication by manipulating the X-Forwarded-By header.
The flaw allows an authenticated tenant worker to intercept another tenant's task callback if they know the task UUID and keep a stream open on the same dispatcher process.
The vulnerability allows any authenticated non-admin user to execute OS commands as the ntopng process account via crafted GET requests, leading to potential unauthorized access and control of the system.
Users could not unlock locks placed by other users, potentially leading to data loss or unavailability.
The flaw allows an authenticated user to read another tenant's durable task event logs by exploiting a misconfigured API endpoint, potentially revealing sensitive workflow details.
The flaw allows unauthenticated attackers to bind a victim's session to an attacker-controlled OAuth identity by exploiting an empty state parameter acceptance in ValidateOAuthState before version 0.91.1.
The flaw allows an authenticated user to replace the UnsubscribeURL with an internal URL, leading to potential exposure of sensitive data and credentials.