All CVEs — page 42 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The vulnerability in Seetong T8108, T8108P, T8116, and T8232 4.6.1.4-build202604241011 allows for remote improper authentication due to an unknown function in the Debug Service, making it critical.
The flaw allows an attacker to inject a Host header, leading to a redirect_uri that can be controlled, potentially enabling unauthorized account access.
The flaw allows any authenticated user to connect to restricted MCP servers by possessing the server ID, bypassing authorization checks and accessing sensitive backend systems.
The flaw allows unauthenticated access to the Obot API and UI, granting full administrative control to any party who can reach the exposed port.
The flaw allows an attacker to register an OAuth client without authentication, leading to unauthorized access to the victim's resources via a crafted authorization URL.