All CVEs — page 48 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution, due to insufficient file type validation in the Ultra Addons for Contact Form 7 plugin.
The flaw allows unauthenticated attackers to bypass authentication by exploiting the mo_wp_login_intent parameter in the miniOrange OTP plugin, enabling them to log in as any existing administrator account.
The flaw allows authenticated attackers with Subscriber-level access or higher to escalate their privileges to Administrator by exploiting a vulnerability in the Groups – Memberships and Access Control plugin for WordPress.
This flaw allows an authenticated low-privilege user to inject arbitrary web-server configuration lines by exploiting URL validation in froxlor's subdomain redirect feature.
The flaw allows an authenticated customer to exploit a symlink race condition to gain host root and cross-tenant access, due to improper path validation in the data export feature.
The flaw allows an authenticated customer to plant a symlink in the FTP home directory, leading to arbitrary file deletion via the cron task. This can result in cross-tenant data destruction and host denial of service.