Aggregator
Dell security advisory (AV24-661)
5 months ago
Canadian Centre for Cyber Security
A Threat Actor is Allegedly Selling Access to the Government of Tamil Nadu
5 months ago
A Threat Actor is Allegedly Selling Access to the Government of Tamil Nadu
Dark Web Informer
CVE-2024-38203 | Microsoft Windows up to Server 2025 Package Library Manager protection mechanism
5 months ago
A vulnerability was found in Microsoft Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Package Library Manager. The manipulation leads to protection mechanism failure.
This vulnerability is known as CVE-2024-38203. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-8049 | Progress Telerik Document Processing Libraries prior 2024.4.1106 iteration
5 months ago
A vulnerability has been found in Progress Telerik Document Processing Libraries and classified as critical. This vulnerability affects unknown code. The manipulation leads to excessive iteration.
This vulnerability was named CVE-2024-8049. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7295 | Progress Telerik Report Server prior 10.3.24.1112 hard-coded credentials (Nessus ID 211469)
5 months ago
A vulnerability has been found in Progress Telerik Report Server 10.0.24.130/10.0.24.514/10.1.24.514/10.1.24.709/10.2.24.806 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to hard-coded credentials.
This vulnerability is known as CVE-2024-7295. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50824 | Kashipara E-Learning Management System Project 1.0 /admin/class.php class_name sql injection
5 months ago
A vulnerability classified as critical has been found in Kashipara E-Learning Management System Project 1.0. Affected is an unknown function of the file /admin/class.php. The manipulation of the argument class_name leads to sql injection.
This vulnerability is traded as CVE-2024-50824. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-50823 | Kashipara E-Learning Management System Project 1.0 /admin/login.php username/password sql injection
5 months ago
A vulnerability, which was classified as critical, has been found in Kashipara E-Learning Management System Project 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. The manipulation of the argument username/password leads to sql injection.
This vulnerability is handled as CVE-2024-50823. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-50834 | Kashipara E-Learning Management System Project 1.0 /admin/teachers.php firstname/lastname sql injection
5 months ago
A vulnerability classified as critical was found in Kashipara E-Learning Management System Project 1.0. This vulnerability affects unknown code of the file /admin/teachers.php. The manipulation of the argument firstname/lastname leads to sql injection.
This vulnerability was named CVE-2024-50834. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-50835 | Kashipara E-Learning Management System Project 1.0 /admin/edit_student.php cys/un/ln/fn/id sql injection
5 months ago
A vulnerability, which was classified as critical, has been found in Kashipara E-Learning Management System Project 1.0. This issue affects some unknown processing of the file /admin/edit_student.php. The manipulation of the argument cys/un/ln/fn/id leads to sql injection.
The identification of this vulnerability is CVE-2024-50835. The attack may be initiated remotely. There is no exploit available.
vuldb.com
ЦЕРН: Впервые зафиксировано рождение высших кварков в свинцовых столкновениях
5 months ago
Ученые впервые зафиксировали редчайшие частицы.
CVE-2022-26494 | PrimeKey SignServer up to 5.8.0 Admin Web Interface cross site scripting
5 months ago
A vulnerability has been found in PrimeKey SignServer up to 5.8.0 and classified as problematic. This vulnerability affects unknown code of the component Admin Web Interface. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2022-26494. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-11073 | SourceCodester Hospital Management System 1.0 delete-account.php id improper authorization
5 months ago
A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects an unknown part of the file /vm/patient/delete-account.php. The manipulation of the argument id leads to improper authorization.
This vulnerability is uniquely identified as CVE-2024-11073. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-50328 | Ivanti Endpoint Manager up to 2022 SU5/2024 sql injection
5 months ago
A vulnerability, which was classified as critical, was found in Ivanti Endpoint Manager up to 2022 SU5/2024. This affects an unknown part. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-50328. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50324 | Ivanti Endpoint Manager up to 2022 SU5/2024 path traversal
5 months ago
A vulnerability was found in Ivanti Endpoint Manager up to 2022 SU5/2024. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to path traversal.
This vulnerability is known as CVE-2024-50324. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50326 | Ivanti Endpoint Manager up to 2022 SU5/2024 sql injection
5 months ago
A vulnerability was found in Ivanti Endpoint Manager up to 2022 SU5/2024. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-50326. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50327 | Ivanti Endpoint Manager up to 2022 SU5/2024 sql injection
5 months ago
A vulnerability classified as critical has been found in Ivanti Endpoint Manager up to 2022 SU5/2024. This affects an unknown part. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-50327. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-51093 | Snipe-IT 7.0.13 #files cross site scripting
5 months ago
A vulnerability classified as problematic has been found in Snipe-IT 7.0.13. Affected is an unknown function of the file /users/{{user-id}}/#files. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-51093. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-52298 | xwikisas macro-pdfviewer up to 2.5.5 Delegate my view right inclusion of sensitive information in source code comments (GHSA-hph4-7j37-7c97)
5 months ago
A vulnerability, which was classified as problematic, was found in xwikisas macro-pdfviewer up to 2.5.5. Affected is an unknown function of the component Delegate my view right. The manipulation leads to inclusion of sensitive information in source code comments.
This vulnerability is traded as CVE-2024-52298. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52299 | xwikisas macro-pdfviewer up to 2.5.5 generation of predictable numbers or identifiers (GHSA-522m-m242-jr9p)
5 months ago
A vulnerability was found in xwikisas macro-pdfviewer up to 2.5.5 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to generation of predictable numbers or identifiers.
This vulnerability is handled as CVE-2024-52299. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com