A vulnerability, which was classified as critical, has been found in ChurchCRM 5.5.0. Affected by this issue is some unknown functionality of the file FRCatalog.php of the component GET Parameter Handler. The manipulation of the argument CurrentFundraiser leads to sql injection.
This vulnerability is handled as CVE-2024-25897. The attack needs to be done within the local network. There is no exploit available.
A vulnerability classified as problematic was found in Archer Platform up to 6.14 P2 HF1. Affected by this vulnerability is an unknown functionality of the component Internal URL Handler. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-26309. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability has been found in esnet iPerf3 up to 3.16 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component OpenSSL Handler. The manipulation leads to cryptographic issues.
This vulnerability is known as CVE-2024-26306. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Make an Offer Module up to 1.7.1 on PrestaShop. It has been rated as critical. Affected by this issue is the function MakeOffers::checkUserExistingOffer/MakeOffers::addUserOffer. The manipulation leads to sql injection.
This vulnerability is handled as CVE-2024-25849. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability, which was classified as critical, was found in Friendica 2023.12. This affects an unknown part of the file fpostit.php. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2024-25864. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as critical, has been found in RSD 3d13a. This issue affects some unknown processing of the component mstatus Register. The manipulation leads to privilege escalation.
The identification of this vulnerability is CVE-2024-25883. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability was found in Foxit PDF Reader and PDF Editor up to 12.1.2. It has been classified as critical. This affects an unknown part of the component Prompt Message Handler. The manipulation of the argument review leads to multiple interpretations of ui input.
This vulnerability is uniquely identified as CVE-2024-25858. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in MyPrestaModules Product Catalog Import Module up to 6.5.0 on PrestaShop. Affected is the function Send::__construct/importProducts::_addDataToDb. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2024-25847. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability was found in Common-Services So Flexibilite Module up to 4.1.25 on PrestaShop. It has been classified as problematic. This affects an unknown part of the component Debug File Handler. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2024-25844. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in vuejs vue-cli up to 5.0.8. It has been rated as problematic. This issue affects the function HtmlPwaPlugin of the file packages/@vue/cli-plugin-pwa/lib/HtmlPwaPlugin.js of the component Markdown Code Handler. The manipulation leads to inefficient regular expression complexity.
The identification of this vulnerability is CVE-2025-5897. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in Linux Kernel up to 6.7.4. It has been classified as problematic. This affects an unknown part of the file drivers/mtd/ubi/attach.c of the component UBI Driver. The manipulation of the argument Name leads to memory leak.
This vulnerability is uniquely identified as CVE-2024-25740. Access to the local network is required for this attack. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as critical has been found in SKINsoft S-Museum 7.02.3. Affected is an unknown function of the component PDF File Handler. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2024-25801. The attack needs to be done within the local network. There is no exploit available.
A vulnerability was found in RuvarOA 6.01/12.01 and classified as critical. Affected by this issue is some unknown functionality of the file /PersonalAffair/worklog_template_show.aspx. The manipulation of the argument ID leads to sql injection.
This vulnerability is handled as CVE-2024-25527. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Linux Kernel up to 6.7.4 and classified as problematic. Affected by this issue is the function create_empty_lvol of the file drivers/mtd/ubi/vtbl.c. The manipulation of the argument leb_size leads to allocation of resources.
This vulnerability is handled as CVE-2024-25739. The attack needs to be initiated within the local network. There is no exploit available.
A vulnerability was found in Couchbase up to 7.2.5/7.6.1 and classified as problematic. This issue affects some unknown processing of the component HTTP Header Handler. The manipulation of the argument Host leads to injection.
The identification of this vulnerability is CVE-2024-25673. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.