All CVEs — page 46 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows authenticated users to execute arbitrary Python and OS commands, posing a significant risk due to insufficient sandboxing of workflow condition expressions.
This vulnerability allows authenticated users to execute arbitrary Python code through the expression engine's DotList map/filter and fallback resolver, posing a significant risk due to the potential for remote code execution.
AzuraCast before 0.23.6 is vulnerable to code injection due to incomplete migration, allowing attackers to inject Liquidsoap syntax and execute arbitrary code, disclose API keys, or disrupt station operations.
This vulnerability allows authenticated users with Streamers and Profile permissions to inject shell commands, leading to potential command execution as the Liquidsoap process user.