Aggregator
CVE-2024-52378 | Labs64 DigiPass Plugin up to 0.3.0 on WordPress path traversal
1 year 4 months ago
A vulnerability was found in Labs64 DigiPass Plugin up to 0.3.0 on WordPress. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2024-52378. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-3502 | lunary-ai lunary up to 1.2.5 User Password information disclosure (dec-4538-8905)
1 year 4 months ago
A vulnerability was found in lunary-ai lunary up to 1.2.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component User Password Handler. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-3502. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3760 | lunary-ai lunary up to 1.2.7 allocation of resources
1 year 4 months ago
A vulnerability was found in lunary-ai lunary up to 1.2.7. It has been classified as critical. Affected is an unknown function. The manipulation leads to allocation of resources.
This vulnerability is traded as CVE-2024-3760. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50828 | Kashipara E-Learning Management System Project 1.0 edit_department.php d sql injection
1 year 4 months ago
A vulnerability was found in Kashipara E-Learning Management System Project 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/edit_department.php. The manipulation of the argument d leads to sql injection.
The identification of this vulnerability is CVE-2024-50828. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-50827 | Kashipara E-Learning Management System Project 1.0 /admin/add_subject.php subject_code sql injection
1 year 4 months ago
A vulnerability has been found in Kashipara E-Learning Management System Project 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/add_subject.php. The manipulation of the argument subject_code leads to sql injection.
This vulnerability was named CVE-2024-50827. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-50826 | Kashipara E-Learning Management System Project 1.0 /admin/add_content.php title/content sql injection
1 year 4 months ago
A vulnerability, which was classified as critical, was found in Kashipara E-Learning Management System Project 1.0. This affects an unknown part of the file /admin/add_content.php. The manipulation of the argument title/content leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-50826. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-50823 | Kashipara E-Learning Management System Project 1.0 /admin/login.php username/password sql injection
1 year 4 months ago
A vulnerability, which was classified as critical, has been found in Kashipara E-Learning Management System Project 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. The manipulation of the argument username/password leads to sql injection.
This vulnerability is handled as CVE-2024-50823. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-50825 | Kashipara E-Learning Management System Project 1.0 /admin/school_year.php school_year sql injection
1 year 4 months ago
A vulnerability classified as critical was found in Kashipara E-Learning Management System Project 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/school_year.php. The manipulation of the argument school_year leads to sql injection.
This vulnerability is known as CVE-2024-50825. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-50824 | Kashipara E-Learning Management System Project 1.0 /admin/class.php class_name sql injection
1 year 4 months ago
A vulnerability classified as critical has been found in Kashipara E-Learning Management System Project 1.0. Affected is an unknown function of the file /admin/class.php. The manipulation of the argument class_name leads to sql injection.
This vulnerability is traded as CVE-2024-50824. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-4311 | zenml-io zenml up to 0.56.x /api/v1/current-user allocation of resources
1 year 4 months ago
A vulnerability was found in zenml-io zenml up to 0.56.x. It has been rated as problematic. This issue affects some unknown processing of the file /api/v1/current-user. The manipulation leads to allocation of resources.
The identification of this vulnerability is CVE-2024-4311. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-50831 | Kashipara E-Learning Management System Project 1.0 /admin/admin_user.php username/password sql injection
1 year 4 months ago
A vulnerability was found in Kashipara E-Learning Management System Project 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/admin_user.php. The manipulation of the argument username/password leads to sql injection.
This vulnerability was named CVE-2024-50831. The attack can be initiated remotely. There is no exploit available.
vuldb.com
NFC Tools PRO模拟器v8.8.0
1 year 4 months ago
软件介绍NFC Tools PRO功能强大且免费的NFC卡模拟器,可模拟各类门禁卡、电梯卡、部分公司(工厂)工卡或饭卡、部分学校饭卡、部分图书馆借书卡等
Is SOAR Obsolete?
1 year 4 months ago
Let’s look at the factors behind the push to declare the end of SOAR, consider their merits, and determine whether or not SOAR is obsolete.
The post Is SOAR Obsolete? appeared first on D3 Security.
The post Is SOAR Obsolete? appeared first on Security Boulevard.
Walker Banerd
CVE-2024-50829 | Kashipara E-Learning Management System Project 1.0 /admin/edit_subject.php unit sql injection
1 year 4 months ago
A vulnerability was found in Kashipara E-Learning Management System Project 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit_subject.php. The manipulation of the argument unit leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-50829. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-50830 | Kashipara E-learning Management System Project 1.0 calendar_of_events.php date_start/date_end/title sql injection
1 year 4 months ago
A vulnerability was found in Kashipara E-learning Management System Project 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/calendar_of_events.php. The manipulation of the argument date_start/date_end/title leads to sql injection.
This vulnerability is handled as CVE-2024-50830. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-50833 | Kashipara E-Learning Management System Project 1.0 /login.php username/password sql injection
1 year 4 months ago
A vulnerability has been found in Kashipara E-Learning Management System Project 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument username/password leads to sql injection.
This vulnerability is known as CVE-2024-50833. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-50832 | Kashipara E-Learning Management System Project 1.0 /admin/edit_class.php class_name sql injection
1 year 4 months ago
A vulnerability, which was classified as critical, was found in Kashipara E-Learning Management System Project 1.0. Affected is an unknown function of the file /admin/edit_class.php. The manipulation of the argument class_name leads to sql injection.
This vulnerability is traded as CVE-2024-50832. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-50835 | Kashipara E-Learning Management System Project 1.0 /admin/edit_student.php cys/un/ln/fn/id sql injection
1 year 4 months ago
A vulnerability, which was classified as critical, has been found in Kashipara E-Learning Management System Project 1.0. This issue affects some unknown processing of the file /admin/edit_student.php. The manipulation of the argument cys/un/ln/fn/id leads to sql injection.
The identification of this vulnerability is CVE-2024-50835. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-50834 | Kashipara E-Learning Management System Project 1.0 /admin/teachers.php firstname/lastname sql injection
1 year 4 months ago
A vulnerability classified as critical was found in Kashipara E-Learning Management System Project 1.0. This vulnerability affects unknown code of the file /admin/teachers.php. The manipulation of the argument firstname/lastname leads to sql injection.
This vulnerability was named CVE-2024-50834. The attack can be initiated remotely. There is no exploit available.
vuldb.com