Aggregator
CVE-2024-7813 | SourceCodester Prison Management System 1.0 Profile Image /uploadImage/Profile/ insufficiently protected credentials
1 year 8 months ago
A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. This issue affects some unknown processing of the file /uploadImage/Profile/ of the component Profile Image Handler. The manipulation leads to insufficiently protected credentials.
The identification of this vulnerability is CVE-2024-7813. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-7812 | SourceCodester Best House Rental Management System 1.0 POST Parameter ajax.php lastname cross site scripting
1 year 8 months ago
A vulnerability classified as problematic was found in SourceCodester Best House Rental Management System 1.0. This vulnerability affects unknown code of the file /rental_0/rental/ajax.php?action=save_tenant of the component POST Parameter Handler. The manipulation of the argument lastname leads to cross site scripting.
This vulnerability was named CVE-2024-7812. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
Microsoft retires Windows updates causing 0x80070643 errors
1 year 8 months ago
Microsoft has retired several Windows security updates released during the January 2024 Patch Tuesday that have been causing 0x80070643 errors when installing Windows Recovery Environment (WinRE) updates. [...]
Sergiu Gatlan
CVE-2024-7811 | SourceCodester Daily Expenses Monitoring App 1.0 delete-expense.php expense sql injection
1 year 8 months ago
A vulnerability classified as critical has been found in SourceCodester Daily Expenses Monitoring App 1.0. This affects an unknown part of the file /endpoint/delete-expense.php. The manipulation of the argument expense leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-7811. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-7810 | SourceCodester Online Graduate Tracer System 1.0 view_itprofile.php id sql injection
1 year 8 months ago
A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /tracking/admin/view_itprofile.php. The manipulation of the argument id leads to sql injection.
This vulnerability is handled as CVE-2024-7810. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-7809 | SourceCodester Online Graduate Tracer System 1.0 /tracking/nbproject/ exposure of information through directory listing
1 year 8 months ago
A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /tracking/nbproject/. The manipulation leads to exposure of information through directory listing.
This vulnerability is known as CVE-2024-7809. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-7808 | code-projects Job Portal 1.0 logindbc.php email sql injection
1 year 8 months ago
A vulnerability was found in code-projects Job Portal 1.0. It has been classified as critical. Affected is an unknown function of the file logindbc.php. The manipulation of the argument email leads to sql injection.
This vulnerability is traded as CVE-2024-7808. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
Digital Align Inc. Achieves SOC 2 Type 2 Certification for Secure Automation Intelligence
1 year 8 months ago
CVE-2024-6925 | TrueBooker Plugin up to 1.0.2 on WordPress Setting cross-site request forgery
1 year 8 months ago
A vulnerability was found in TrueBooker Plugin up to 1.0.2 on WordPress and classified as problematic. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to cross-site request forgery.
The identification of this vulnerability is CVE-2024-6925. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-7063 | ElementsKit Pro Plugin up to 3.6.6 on WordPress information disclosure
1 year 8 months ago
A vulnerability has been found in ElementsKit Pro Plugin up to 3.6.6 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-7063. The attack can only be done within the local network. There is no exploit available.
vuldb.com
CVE-2024-42472 | Flatpak up to 1.14.9/1.15.9 access control
1 year 8 months ago
A vulnerability, which was classified as critical, was found in Flatpak up to 1.14.9/1.15.9. This affects an unknown part. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2024-42472. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-7064 | ElementsKit Pro Plugin up to 3.6.5 on WordPress cross site scripting
1 year 8 months ago
A vulnerability, which was classified as problematic, has been found in ElementsKit Pro Plugin up to 3.6.5 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-7064. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-6924 | TrueBooker Plugin up to 1.0.2 on WordPress sql injection
1 year 8 months ago
A vulnerability classified as critical was found in TrueBooker Plugin up to 1.0.2 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-6924. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-5915 | Palo Alto GlobalProtect App prior 6.1.5/6.2.4/6.3.1 on Windows permission assignment
1 year 8 months ago
A vulnerability classified as critical has been found in Palo Alto GlobalProtect App on Windows. Affected is an unknown function. The manipulation leads to incorrect permission assignment.
This vulnerability is traded as CVE-2024-5915. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-5914 | Palo Alto Cortex XSOAR CommonScripts prior 1.12.33 command injection
1 year 8 months ago
A vulnerability was found in Palo Alto Cortex XSOAR CommonScripts. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to command injection.
The identification of this vulnerability is CVE-2024-5914. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-5916 | Palo Alto PAN-OS/Cloud NGFW/Prisma Access cleartext storage in a file or on disk
1 year 8 months ago
A vulnerability was found in Palo Alto PAN-OS, Cloud NGFW and Prisma Access. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cleartext storage in a file or on disk.
This vulnerability was named CVE-2024-5916. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-50314 | IBM WebSphere Application Liberty up to 24.0.0.8 certificate validation (XFDB-274713)
1 year 8 months ago
A vulnerability was found in IBM WebSphere Application Liberty up to 24.0.0.8. It has been classified as problematic. This affects an unknown part. The manipulation leads to improper certificate validation.
This vulnerability is uniquely identified as CVE-2023-50314. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-37529 | IBM DB2/DB2 Connect Server 11.1/11.5 Query memory allocation (XFDB-294295)
1 year 8 months ago
A vulnerability was found in IBM DB2 and DB2 Connect Server 11.1/11.5 and classified as critical. Affected by this issue is some unknown functionality of the component Query Handler. The manipulation leads to uncontrolled memory allocation.
This vulnerability is handled as CVE-2024-37529. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-50315 | IBM WebSphere Application Server 8.5/9.0 certificate validation (XFDB-274714)
1 year 8 months ago
A vulnerability has been found in IBM WebSphere Application Server 8.5/9.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper certificate validation.
This vulnerability is known as CVE-2023-50315. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com