Aggregator
INC
1 day 22 hours ago
You must login to view this content
cohenido
CVE-2023-47716 | IBM Filenet Content Manager 5.5.8.0/5.5.10.0/5.5.11.0 CP4BA access control (XFDB-271656)
1 day 22 hours ago
A vulnerability marked as critical has been reported in IBM Filenet Content Manager 5.5.8.0/5.5.10.0/5.5.11.0. Affected by this issue is some unknown functionality of the component CP4BA. The manipulation leads to improper access controls.
This vulnerability is handled as CVE-2023-47716. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-43043 | IBM Maximo Application Suite 8.10/8.11 Maximo Mobile for EAM log file (XFDB-266875)
1 day 22 hours ago
A vulnerability was found in IBM Maximo Application Suite 8.10/8.11. It has been classified as problematic. This vulnerability affects unknown code of the component Maximo Mobile for EAM. The manipulation leads to sensitive information in log files.
This vulnerability was named CVE-2023-43043. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-1504 | SecuPress Free Plugin up to 2.2.5.1 on WordPress Banned IP Address cross-site request forgery
1 day 22 hours ago
A vulnerability categorized as problematic has been discovered in SecuPress Free Plugin up to 2.2.5.1 on WordPress. Affected by this vulnerability is an unknown functionality of the component Banned IP Address. The manipulation leads to cross-site request forgery.
This vulnerability is known as CVE-2024-1504. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-21459 | Qualcomm Snapdragon Auto up to XR2 5G Platform Response Frame buffer over-read
1 day 22 hours ago
A vulnerability classified as critical was found in Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking. Affected by this vulnerability is an unknown functionality of the component Response Frame Handler. The manipulation leads to buffer over-read.
This vulnerability is known as CVE-2024-21459. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53989 | rails-html-sanitizer up to 1.6.0 Rails::HTML::Sanitizer cross site scripting (GHSA-rxv5-gxqc-xx8g)
1 day 22 hours ago
A vulnerability has been found in rails-html-sanitizer up to 1.6.0 and classified as problematic. This vulnerability affects the function Rails::HTML::Sanitizer. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-53989. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53985 | rails-html-sanitizer up to 1.6.0 Rails::HTML::Sanitizer cross site scripting (GHSA-w8gc-x259-rc7x)
1 day 22 hours ago
A vulnerability categorized as problematic has been discovered in rails-html-sanitizer up to 1.6.0. This issue affects the function Rails::HTML::Sanitizer. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-53985. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53988 | rails-html-sanitizer up to 1.6.0 Rails::HTML::Sanitizer cross site scripting (GHSA-cfjx-w229-hgx5)
1 day 22 hours ago
A vulnerability labeled as problematic has been found in rails-html-sanitizer up to 1.6.0. Affected by this vulnerability is the function Rails::HTML::Sanitizer. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-53988. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53986 | rails-html-sanitizer up to 1.6.0 Rails::HTML::Sanitizer cross site scripting (GHSA-638j-pmjw-jq48)
1 day 22 hours ago
A vulnerability, which was classified as problematic, has been found in rails-html-sanitizer up to 1.6.0. Affected is the function Rails::HTML::Sanitizer. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-53986. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-53987 | rails-html-sanitizer up to 1.6.0 Rails::HTML::Sanitizer cross site scripting (GHSA-2x5m-9ch4-qgrr)
1 day 22 hours ago
A vulnerability, which was classified as problematic, was found in rails-html-sanitizer up to 1.6.0. Affected by this vulnerability is the function Rails::HTML::Sanitizer. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-53987. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-54141 | thorsten phpMyFAQ up to 3.x information exposure (GHSA-vrjr-p3xp-xx2x)
1 day 22 hours ago
A vulnerability, which was classified as problematic, has been found in thorsten phpMyFAQ up to 3.x. Affected by this issue is some unknown functionality. The manipulation leads to information exposure through error message.
This vulnerability is handled as CVE-2024-54141. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-52586 | eLabFTW up to 5.1.8 authentication bypass
1 day 22 hours ago
A vulnerability marked as critical has been reported in eLabFTW up to 5.1.8. Affected by this issue is some unknown functionality. The manipulation leads to authentication bypass using alternate channel.
This vulnerability is handled as CVE-2024-52586. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-33322 | Etoile Web Design Front End Users Plugin up to 3.2.24 on WordPress cross site scripting
1 day 22 hours ago
A vulnerability classified as problematic has been found in Etoile Web Design Front End Users Plugin up to 3.2.24 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2023-33322. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-46954 | Artifex Ghostscript up to 10.03.x base/gp_utf8.c decode_utf8 path traversal (Nessus ID 210946)
1 day 22 hours ago
A vulnerability classified as critical was found in Artifex Ghostscript up to 10.03.x. This issue affects the function decode_utf8 of the file base/gp_utf8.c. The manipulation leads to path traversal.
The identification of this vulnerability is CVE-2024-46954. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-2783 | Google Chrome up to 134.0.6998.117 on Windows Mojo Remote Code Execution (EDB-52403 / Nessus ID 233331)
1 day 22 hours ago
A vulnerability, which was classified as critical, has been found in Google Chrome on Windows. Affected by this issue is some unknown functionality of the component Mojo. The manipulation leads to Remote Code Execution.
This vulnerability is handled as CVE-2025-2783. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-53770 | Microsoft SharePoint Enterprise Server 2016/2019/Subscription Edition HTTP Header /_layouts/SignOut.aspx Referer ToolShell deserialization (EUVD-2025-21981 / EDB-52405)
1 day 22 hours ago
A vulnerability classified as very critical was found in Microsoft SharePoint Enterprise Server 2016/2019/Subscription Edition. This affects an unknown part of the file /_layouts/SignOut.aspx of the component HTTP Header Handler. The manipulation of the argument Referer leads to deserialization.
This vulnerability is uniquely identified as CVE-2025-53770. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-49730 | Microsoft Windows up to Server 2025 QoS Scheduler Driver toctou (EUVD-2025-20544 / EDB-52399)
1 day 22 hours ago
A vulnerability has been found in Microsoft Windows and classified as critical. This vulnerability affects unknown code of the component QoS Scheduler Driver. The manipulation leads to time-of-check time-of-use.
This vulnerability was named CVE-2025-49730. The attack needs to be approached locally. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2025-50286 | Grav CMS 1.7.48 direct-install unrestricted upload (EDB-52402)
1 day 22 hours ago
A vulnerability described as critical has been identified in Grav CMS 1.7.48. This affects an unknown part of the file /admin/tools/direct-install. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2025-50286. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2025-21577 | Oracle MySQL Server up to 8.0.41/8.4.4/9.2.0 InnoDB denial of service (Nessus ID 240390 / WID-SEC-2025-1850)
1 day 22 hours ago
A vulnerability described as problematic has been identified in Oracle MySQL Server up to 8.0.41/8.4.4/9.2.0. This issue affects some unknown processing of the component InnoDB. The manipulation leads to denial of service.
The identification of this vulnerability is CVE-2025-21577. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com