Aggregator
RansomHub
4 months ago
cohenido
CVE-2016-5019 | Oracle Rapid Planning 12.1/12.2 Middle Tier deserialization (ID 150254 / BID-93236)
4 months ago
A vulnerability classified as very critical was found in Oracle Rapid Planning 12.1/12.2. This vulnerability affects unknown code of the component Middle Tier. The manipulation leads to deserialization.
This vulnerability was named CVE-2016-5019. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9295 | SourceCodester Advocate Office Management System 1.0 /control/login.php username sql injection
4 months ago
A vulnerability was found in SourceCodester Advocate Office Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /control/login.php. The manipulation of the argument username leads to sql injection.
The identification of this vulnerability is CVE-2024-9295. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-9296 | SourceCodester Advocate Office Management System 1.0 /control/forgot_pass.php username sql injection
4 months ago
A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /control/forgot_pass.php. The manipulation of the argument username leads to sql injection.
This vulnerability is traded as CVE-2024-9296. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-32824 | MediaTek MT8788 rpmb double free (ALPS07912966)
4 months ago
A vulnerability was found in MediaTek MT6580, MT6739, MT6761, MT6762, MT6765, MT6768, MT6769, MT6779, MT6781, MT6785, MT6789, MT6833, MT6853, MT6853T, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6889, MT6891, MT6893, MT6895, MT6983, MT6985, MT8666, MT8765 and MT8788. It has been rated as problematic. This issue affects some unknown processing of the component rpmb. The manipulation leads to double free.
The identification of this vulnerability is CVE-2023-32824. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-9291 | kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff XML File upfile cross site scripting
4 months ago
A vulnerability classified as problematic has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff. Affected is an unknown function of the file /ueditor/upload?configPath=ueditor/config.json&action=uploadfile of the component XML File Handler. The manipulation of the argument upfile leads to cross site scripting.
This vulnerability is traded as CVE-2024-9291. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The GitHub repository of the project did not receive an update for more than two years.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
vuldb.com
CVE-2024-9294 | dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c saveNewPwd.php username sql injection
4 months ago
A vulnerability, which was classified as critical, has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected by this issue is some unknown functionality of the file saveNewPwd.php. The manipulation of the argument username leads to sql injection.
This vulnerability is handled as CVE-2024-9294. The attack may be launched remotely. Furthermore, there is an exploit available.
Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
vuldb.com
2024全球数字经济大会——数字安全生态建设专题论坛,经纬信安斩获多项荣誉
4 months ago
企业资讯
TSA and DHS Want Your Selfie: The Move Toward Biometric IDs for Travel
4 months ago
The US Department of Homeland Security (DHS), the Transportation Security Administration (TSA), Home
CUPS: Unraveling a Critical Vulnerability Chain in Unix Printing Systems
4 months ago
A series of critical vulnerabilities has been uncovered in the Common Unix Printing System (CUPS), specifically in the
The post CUPS: Unraveling a Critical Vulnerability Chain in Unix Printing Systems appeared first on ARMO.
The post CUPS: Unraveling a Critical Vulnerability Chain in Unix Printing Systems appeared first on Security Boulevard.
Amit Schendel
CVE-2007-4067 | Clever Components Internet ActiveX Suite 6.2 ActiveX Control clinetsuitex6.clwebdav second path traversal (EDB-4226 / XFDB-35590)
4 months ago
A vulnerability has been found in Clever Components Internet ActiveX Suite 6.2 and classified as critical. This vulnerability affects unknown code of the file clinetsuitex6.clwebdav of the component ActiveX Control. The manipulation of the argument second leads to path traversal.
This vulnerability was named CVE-2007-4067. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2003-0853 | fileutils/coreutils Width denial of service (EDB-23274 / Nessus ID 14088)
4 months ago
A vulnerability, which was classified as critical, was found in fileutils and coreutils. This affects an unknown part. The manipulation of the argument Width leads to denial of service.
This vulnerability is uniquely identified as CVE-2003-0853. The attack can only be initiated within the local network. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38809 | Vmware Spring Framework up to 5.3.37/6.0.22/6.1.11 Conditional HTTP Request ETags denial of service
4 months ago
A vulnerability classified as critical has been found in Vmware Spring Framework up to 5.3.37/6.0.22/6.1.11. Affected is an unknown function of the component Conditional HTTP Request Handler. The manipulation of the argument ETags leads to denial of service.
This vulnerability is traded as CVE-2024-38809. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-37187 | Advantech ADAM-5550 weak encoding for password (icsa-24-270-01)
4 months ago
A vulnerability was found in Advantech ADAM-5550. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to weak encoding for password.
This vulnerability is known as CVE-2024-37187. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-38308 | Advantech ADAM-5550 Logs Page cross site scripting (icsa-24-270-01)
4 months ago
A vulnerability was found in Advantech ADAM-5550. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Logs Page. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-38308. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40507 | openPetra 2023.02 serverMPersonnel.asmx cross site scripting
4 months ago
A vulnerability was found in openPetra 2023.02. It has been classified as problematic. This affects an unknown part of the file serverMPersonnel.asmx. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-40507. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-40506 | openPetra 2023.02 serverMHospitality.asmx cross site scripting
4 months ago
A vulnerability was found in openPetra 2023.02. It has been declared as problematic. This vulnerability affects unknown code of the file serverMHospitality.asmx. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-40506. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-40508 | openPetra 2023.02 serverMConference.asmx cross site scripting
4 months ago
A vulnerability was found in openPetra 2023.02. It has been rated as problematic. This issue affects some unknown processing of the file serverMConference.asmx. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-40508. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-46366 | Webkul Krayin CRM 1.3.0 Template injection
4 months ago
A vulnerability, which was classified as critical, has been found in Webkul Krayin CRM 1.3.0. This issue affects some unknown processing of the component Template Handler. The manipulation leads to injection.
The identification of this vulnerability is CVE-2024-46366. The attack may be initiated remotely. There is no exploit available.
vuldb.com