Aggregator
CVE-2018-18804 | Bakeshop Inventory System 1.0 Login Screen publicfunction.vb sql injection (EDB-45720)
1 year 1 month ago
A vulnerability was found in Bakeshop Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file include/publicfunction.vb of the component Login Screen. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2018-18804. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-10856 | Booking Calendar WpDevArt Plugin up to 3.2.19 on WordPress sql injection
1 year 1 month ago
A vulnerability, which was classified as critical, was found in Booking Calendar WpDevArt Plugin up to 3.2.19 on WordPress. This affects an unknown part. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-10856. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-45631 | Responsive Image Gallery Album Plugin up to 2.0.3 on WordPress AJAX Action authorization
1 year 1 month ago
A vulnerability was found in Responsive Image Gallery Album Plugin up to 2.0.3 on WordPress. It has been classified as critical. Affected is an unknown function of the component AJAX Action Handler. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2023-45631. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-25041 | IBM Cognos Analytics up to 12.0.2 cross site scripting (XFDB-282780)
1 year 1 month ago
A vulnerability classified as problematic has been found in IBM Cognos Analytics up to 12.0.2. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-25041. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-5712 | stitionai devika cross-site request forgery
1 year 1 month ago
A vulnerability classified as problematic was found in stitionai devika. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-5712. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-5790 | Happy Addons for Elementor Plugin up to 3.11.1 on WordPress Gradient Heading Widget cross site scripting
1 year 1 month ago
A vulnerability has been found in Happy Addons for Elementor Plugin up to 3.11.1 on WordPress and classified as problematic. This vulnerability affects unknown code of the component Gradient Heading Widget. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-5790. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-38522 | scidsg hushline prior 0.1.0 tips.hushline.app permissive list of allowed inputs (GHSA-r85c-95x7-4h7q)
1 year 1 month ago
A vulnerability, which was classified as critical, was found in scidsg hushline. Affected is an unknown function of the file tips.hushline.app. The manipulation leads to permissive list of allowed inputs.
This vulnerability is traded as CVE-2024-38522. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-5666 | Extensions for Elementor Plugin up to 2.0.30 on WordPress URL Parameter cross site scripting
1 year 1 month ago
A vulnerability was found in Extensions for Elementor Plugin up to 2.0.30 on WordPress and classified as problematic. This issue affects some unknown processing of the component URL Parameter Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-5666. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-6363 | Stock Ticker Plugin up to 3.24.4 on WordPress Shortcode stock_ticker cross site scripting
1 year 1 month ago
A vulnerability was found in Stock Ticker Plugin up to 3.24.4 on WordPress. It has been classified as problematic. Affected is the function stock_ticker of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-6363. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-39307 | Kareadita Kavita up to 0.8.0 cross site scripting (GHSA-r4qc-3w52-2v84)
1 year 1 month ago
A vulnerability classified as problematic was found in Kareadita Kavita up to 0.8.0. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-39307. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-25211 | Gonic Gin-Gonic CORS Middleware up to 1.5.x cross-domain policy
1 year 1 month ago
A vulnerability has been found in Gonic Gin-Gonic CORS Middleware up to 1.5.x and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is known as CVE-2019-25211. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2018-1456 | IBM Rhapsody DM up to 6.0.5 XML Data xml external entity reference (Nessus ID 233181 / XFDB-140091)
1 year 1 month ago
A vulnerability was found in IBM Rhapsody DM up to 6.0.5. It has been rated as critical. This issue affects some unknown processing of the component XML Data Handler. The manipulation leads to xml external entity reference.
The identification of this vulnerability is CVE-2018-1456. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2020-7595 | libxml2 2.9.10 parser.c xmlStringLenDecodeEntities infinite loop (ssa-292794 / Nessus ID 233181)
1 year 1 month ago
A vulnerability, which was classified as problematic, has been found in libxml2 2.9.10. Affected by this issue is the function xmlStringLenDecodeEntities of the file parser.c. The manipulation leads to infinite loop.
This vulnerability is handled as CVE-2020-7595. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2020-7595 | Oracle Real User Experience Insight 13.3.1.0 APM Mesh infinite loop (Nessus ID 233181)
1 year 1 month ago
A vulnerability classified as critical has been found in Oracle Real User Experience Insight 13.3.1.0. Affected is an unknown function of the component APM Mesh. The manipulation leads to infinite loop.
This vulnerability is traded as CVE-2020-7595. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2017-2632 | CloudForms up to 5.7.1.2 Role Validation valid_role improper authorization (RHSA-2017:0320 / Nessus ID 233184)
1 year 1 month ago
A vulnerability was found in CloudForms up to 5.7.1.2 and classified as critical. This issue affects the function valid_role of the component Role Validation. The manipulation leads to improper authorization.
The identification of this vulnerability is CVE-2017-2632. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2019-20388 | libxml2 2.9.10 xmlschemas.c xmlSchemaPreRun denial of service (Nessus ID 233181)
1 year 1 month ago
A vulnerability classified as problematic was found in libxml2 2.9.10. This vulnerability affects the function xmlSchemaPreRun of the file xmlschemas.c. The manipulation leads to denial of service.
This vulnerability was named CVE-2019-20388. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2018-10905 | CloudForms Management Engine dRuby access control (RHSA-2018:2561 / Nessus ID 233185)
1 year 1 month ago
A vulnerability, which was classified as critical, has been found in CloudForms Management Engine. This issue affects some unknown processing of the component dRuby. The manipulation leads to improper access controls.
The identification of this vulnerability is CVE-2018-10905. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2025-1427 | Autodesk AutoCAD prior 2025.1.2 CATPRODUCT File uninitialized variable (Nessus ID 233189)
1 year 1 month ago
A vulnerability has been found in Autodesk AutoCAD, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D, Civil 3D, Advance Steel and AutoCAD MAP 3D and classified as critical. Affected by this vulnerability is an unknown functionality of the component CATPRODUCT File Handler. The manipulation leads to use of uninitialized variable.
This vulnerability is known as CVE-2025-1427. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
m0leCon CTF 2025
1 year 1 month ago
Name: m0leCon CTF 2025 (an m0leCon CTF event.)
Date: March 20, 2025, 4 p.m. — 21 March 2025, 16:00 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Italy, Torino
Offical URL: https://finals.m0lecon.it/
Rating weight: 75.00
Event organizers: pwnthem0le
Date: March 20, 2025, 4 p.m. — 21 March 2025, 16:00 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Italy, Torino
Offical URL: https://finals.m0lecon.it/
Rating weight: 75.00
Event organizers: pwnthem0le