All CVEs — page 50 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
This vulnerability allows attackers with BUILDER role to write arbitrary files as root via a malicious ZIP archive, enabling remote code execution.
stoatchat before 0.15.5 allows attackers to bypass multi-factor authentication (MFA) by using their own valid MFA ticket with another user's session token, enabling unauthorized access to sensitive operations.
This vulnerability allows an authenticated backend operator to escalate their privileges to full super-admin by manipulating the access map, leading to control over critical system components.