Aggregator
CVE-2024-56898 | Geovision GV-ASWeb up to 6.1.0.0 HTTP Request access control
10 months 1 week ago
A vulnerability, which was classified as critical, has been found in Geovision GV-ASWeb up to 6.1.0.0. This issue affects some unknown processing of the component HTTP Request Handler. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2024-56898. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
Play
10 months 1 week ago
cohenido
CVE-2025-24960 | CyferShepard Jellystat up to 1.1.2 path traversal (GHSA-6x46-6w9f-ffv6)
10 months 1 week ago
A vulnerability classified as critical was found in CyferShepard Jellystat up to 1.1.2. This vulnerability affects unknown code. The manipulation leads to path traversal.
This vulnerability was named CVE-2025-24960. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-57098 | Moss 0.1.3 order sql injection (Issue 13)
10 months 1 week ago
A vulnerability classified as critical has been found in Moss 0.1.3. This affects an unknown part. The manipulation of the argument order leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-57098. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2025-22978 | eladmin up to 2.7 Exception Log Download Module csv injection (Issue 863)
10 months 1 week ago
A vulnerability was found in eladmin up to 2.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Exception Log Download Module. The manipulation leads to csv injection.
This vulnerability is handled as CVE-2025-22978. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
Play
10 months 1 week ago
cohenido
Play
10 months 1 week ago
cohenido
CVE-2024-56903 | Geovision GV-ASWeb up to 6.1.1.0 HTTP Request cross-site request forgery
10 months 1 week ago
A vulnerability was found in Geovision GV-ASWeb up to 6.1.1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component HTTP Request Handler. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-56903. The attack can be launched remotely. There is no exploit available.
vuldb.com
Play
10 months 1 week ago
cohenido
CVE-2025-22918 | Polycom RealPresence Group 500 up to 20 Cookie information disclosure
10 months 1 week ago
A vulnerability was found in Polycom RealPresence Group 500 up to 20. It has been classified as problematic. Affected is an unknown function of the component Cookie Handler. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2025-22918. The attack needs to be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-56902 | Geovision GV-ASWeb up to 6.1.0.0 HTTP Request improper authorization
10 months 1 week ago
A vulnerability has been found in Geovision GV-ASWeb up to 6.1.0.0 and classified as problematic. This vulnerability affects unknown code of the component HTTP Request Handler. The manipulation leads to improper authorization.
This vulnerability was named CVE-2024-56902. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-57099 | ClassCMS 4.8 Model Management classview Privilege Escalation
10 months 1 week ago
A vulnerability was found in ClassCMS 4.8 and classified as problematic. This issue affects some unknown processing of the component Model Management. The manipulation of the argument classview leads to Privilege Escalation.
The identification of this vulnerability is CVE-2024-57099. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
Veriti Expands Exposure Assessment Platform with Industry First Proactive Cloud Native Remediation Solution
10 months 1 week ago
Leverage Infrastructure as Code, APIs, and automations to natively remediate exposures at scale for AWS Azure and GCP, while maintaining business continuity. TEL AVIV, Israel – February 4, 2025, Veriti, a leader in exposure management solutions, is proud to announce the launch of Veriti Cloud, an expansion of its Exposure Assessment and Remediation platform that […]
The post Veriti Expands Exposure Assessment Platform with Industry First Proactive Cloud Native Remediation Solution appeared first on VERITI.
The post Veriti Expands Exposure Assessment Platform with Industry First Proactive Cloud Native Remediation Solution appeared first on Security Boulevard.
Yair Herling
CVE-2025-24371 | CometBFT up to 0.38.16/1.0.0 improper check or handling of exceptional conditions
10 months 1 week ago
A vulnerability, which was classified as problematic, was found in CometBFT up to 0.38.16/1.0.0. This affects an unknown part. The manipulation leads to improper check or handling of exceptional conditions.
This vulnerability is uniquely identified as CVE-2025-24371. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-24029 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition Artifact insufficient permissions or privileges
10 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Enalean Tuleap Community Edition and Tuleap Enterprise Edition. Affected by this issue is some unknown functionality of the component Artifact Handler. The manipulation leads to improper handling of insufficient permissions or privileges.
This vulnerability is handled as CVE-2025-24029. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-22129 | Enalean Tuleap Community Edition/Tuleap Enterprise Edition insufficient permissions or privileges
10 months 1 week ago
A vulnerability classified as problematic was found in Enalean Tuleap Community Edition and Tuleap Enterprise Edition. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper handling of insufficient permissions or privileges.
This vulnerability is known as CVE-2025-22129. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-34896 | Nedis SmartLife Video Doorbell WIFICDP10GY 1.4.0 on iOS access control
10 months 1 week ago
A vulnerability classified as problematic has been found in Nedis SmartLife Video Doorbell WIFICDP10GY 1.4.0 on iOS. Affected is an unknown function. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2024-34896. Access to the local network is required for this attack. There is no exploit available.
vuldb.com
CVE-2025-24962 | yogeshojha rengine up to 2.2.0 nmap_cmd injection (GHSA-cg75-ph7x-5rr9)
10 months 1 week ago
A vulnerability was found in yogeshojha rengine up to 2.2.0. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument nmap_cmd leads to injection.
The identification of this vulnerability is CVE-2025-24962. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-24899 | yogeshojha rengine 1.2.0/1.3.0 /api/listVulnerability/ information disclosure (GHSA-r3fp-xr9f-wv38)
10 months 1 week ago
A vulnerability was found in yogeshojha rengine 1.2.0/1.3.0. It has been declared as problematic. This vulnerability affects unknown code of the file /api/listVulnerability/. The manipulation leads to information disclosure.
This vulnerability was named CVE-2025-24899. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com