All CVEs — page 35 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The vulnerability allows the Fleet agent to write resources to downstream clusters using cluster-admin credentials, potentially overwriting configuration files in multi-tenancy environments.
The flaw allows unauthenticated attackers to execute a stored cross-site scripting attack in the Rancher UI, leading to potential data exfiltration, session hijacking, and other web-based attacks.
This flaw allows unauthenticated users to execute arbitrary code on the IdentityIQ server due to improper input validation, posing a critical risk.
The flaw in Netcore NR289-GE 1.4.5102 allows for missing authentication due to a vulnerability in the boa_temp Handler's process_request function, enabling remote attackers to exploit this without authentication.
The vulnerability allows remote command injection through the manipulation of the ntp_ip argument in the /set_ntp_server_ip.cgi file, enabling attackers to execute arbitrary commands on the device.
The flaw allows os command injection via the mac argument in the /location_time.cgi file, enabling remote code execution.
The flaw is a stack-based buffer overflow in the password-check function of Netcore NR289-GE 1.4.5102, which can be exploited by manipulating the Username argument. This vulnerability is critical as it allows remote code execution.