Aggregator
Dark Vault
8 months 1 week ago
cohenido
INC
8 months 1 week ago
cohenido
CVE-1999-0109 | Sun Solaris 2.5/2.5.1 ffbconfig memory corruption (ID 00140 / EDB-19159)
8 months 1 week ago
A vulnerability was found in Sun Solaris 2.5/2.5.1. It has been classified as critical. This affects an unknown part of the component ffbconfig. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-1999-0109. Local access is required to approach this attack. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2015-1478 | CMSJunkie J-ClassifiedsManager view cross site scripting (Exploit 130093 / EDB-35911)
8 months 1 week ago
A vulnerability, which was classified as problematic, was found in CMSJunkie J-ClassifiedsManager. This affects an unknown part. The manipulation of the argument view leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2015-1478. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2019-6116 | Artifex Ghostscript up to 9.26 psi/zdevice2.c input validation (RHSA-2019:0229 / EDB-46242)
8 months 1 week ago
A vulnerability has been found in Artifex Ghostscript up to 9.26 and classified as critical. Affected by this vulnerability is an unknown functionality of the file psi/zdevice2.c. The manipulation leads to improper input validation.
This vulnerability is known as CVE-2019-6116. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2021-42840 | SuiteCRM up to 7.11.18 Log File Name Setting logger_file_name code injection (EDB-50531)
8 months 1 week ago
A vulnerability was found in SuiteCRM up to 7.11.18. It has been classified as critical. This affects an unknown part of the component Log File Name Setting. The manipulation of the argument logger_file_name leads to code injection.
This vulnerability is uniquely identified as CVE-2021-42840. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
DNI Claims to be Selling the Data from a Private Healthcare Provider in Spain
8 months 1 week ago
DNI Claims to be Selling the Data from a Private Healthcare Provider in Spain
Dark Web Informer - Cyber Threat Intelligence
CVE-2024-50945 | SimplCommerce 230310c8d7a0408569b292c5a805c459d47a1d8f Review Submit access control
8 months 1 week ago
A vulnerability was found in SimplCommerce 230310c8d7a0408569b292c5a805c459d47a1d8f and classified as problematic. This issue affects some unknown processing of the component Review Submit Handler. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2024-50945. The attack needs to be approached within the local network. There is no exploit available.
vuldb.com
CVE-2024-53476 | SimplCommerce 230310c8d7a0408569b292c5a805c459d47a1d8f Purchase Request race condition
8 months 1 week ago
A vulnerability was found in SimplCommerce 230310c8d7a0408569b292c5a805c459d47a1d8f. It has been classified as problematic. Affected is an unknown function of the component Purchase Request Handler. The manipulation leads to race condition.
This vulnerability is traded as CVE-2024-53476. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-50944 | SimplCommerce 230310c8d7a0408569b292c5a805c459d47a1d8f Shopping Cart AddToCart quantity integer overflow
8 months 1 week ago
A vulnerability was found in SimplCommerce 230310c8d7a0408569b292c5a805c459d47a1d8f. It has been declared as critical. Affected by this vulnerability is the function AddToCart of the component Shopping Cart Handler. The manipulation of the argument quantity leads to integer overflow.
This vulnerability is known as CVE-2024-50944. The attack can only be initiated within the local network. There is no exploit available.
vuldb.com
CVE-2024-50715 | smarts-srl Smart Agent 1.1.0 /youtubeInfo.php command injection
8 months 1 week ago
A vulnerability was found in smarts-srl Smart Agent 1.1.0. It has been rated as critical. This issue affects some unknown processing of the file /youtubeInfo.php. The manipulation leads to command injection.
The identification of this vulnerability is CVE-2024-50715. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-50714 | smarts-srl Smart Agent 1.1.0 /FB/getFbVideoSource.php server-side request forgery
8 months 1 week ago
A vulnerability classified as critical has been found in smarts-srl Smart Agent 1.1.0. Affected is an unknown function of the file /FB/getFbVideoSource.php. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2024-50714. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-50716 | smarts-srl Smart Agent 1.1.0 /sendPushManually.php id sql injection
8 months 1 week ago
A vulnerability, which was classified as critical, has been found in smarts-srl Smart Agent 1.1.0. Affected by this issue is some unknown functionality of the file /sendPushManually.php. The manipulation of the argument id leads to sql injection.
This vulnerability is handled as CVE-2024-50716. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-13025 | Codezips College Management System 1.0 /Front-end/faculty.php book_name/book_author sql injection
8 months 1 week ago
A vulnerability was found in Codezips College Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Front-end/faculty.php. The manipulation of the argument book_name/book_author leads to sql injection.
This vulnerability is traded as CVE-2024-13025. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-13024 | Codezips Blood Bank Management System 1.0 /campaign.php cname sql injection
8 months 1 week ago
A vulnerability was found in Codezips Blood Bank Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /campaign.php. The manipulation of the argument cname leads to sql injection.
The identification of this vulnerability is CVE-2024-13024. The attack may be initiated remotely. Furthermore, there is an exploit available.
Other parameters might be affected as well.
vuldb.com
CVE-2024-13023 | PHPGurukul Maid Hiring Management System 1.0 Search Maid Page /admin/search-maid.php searchdata cross site scripting
8 months 1 week ago
A vulnerability has been found in PHPGurukul Maid Hiring Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/search-maid.php of the component Search Maid Page. The manipulation of the argument searchdata leads to cross site scripting.
This vulnerability was named CVE-2024-13023. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #471108: Codezips College Management System 1.0 SQL Injection [Accepted]
8 months 1 week ago
Submit #471108 / VDB-289716
John Correche
Submit #471038: Codezips Blood Bank Management System In PHP With Source Code V1.0 SQL Injection [Accepted]
8 months 1 week ago
Submit #471038 / VDB-289715
1905589289
Submit #470461: phpgurukul Maid Hiring Management System 1.0 Cross Site Scripting [Accepted]
8 months 1 week ago
Submit #470461 / VDB-289714
Havook