Aggregator
CVE-2024-8355 | Visteon Infotainment DeviceManager iAP Serial Number sql injection (ZDI-24-1208)
10 months ago
A vulnerability classified as critical has been found in Visteon Infotainment. Affected is an unknown function of the component DeviceManager iAP Serial Number Handler. The manipulation leads to sql injection.
This vulnerability is traded as CVE-2024-8355. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2024-22399 | Apache Seata up to 1.8.0/2.0.0 deserialization
10 months ago
A vulnerability was found in Apache Seata up to 1.8.0/2.0.0. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to deserialization.
The identification of this vulnerability is CVE-2024-22399. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8646 | Eclipse Glassfish up to 7.0.9 redirect
10 months ago
A vulnerability was found in Eclipse Glassfish up to 7.0.9. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to open redirect.
This vulnerability was named CVE-2024-8646. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-8642 | Eclipse EDC Connector up to 0.8.x incorrect implementation of authentication algorithm
10 months ago
A vulnerability was found in Eclipse EDC Connector up to 0.8.x. It has been classified as problematic. This affects an unknown part. The manipulation leads to incorrect implementation of authentication algorithm.
This vulnerability is uniquely identified as CVE-2024-8642. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27113 | Simple Online Planning SO Planning prior 1.52.02 Public View Setting information disclosure
10 months ago
A vulnerability was found in Simple Online Planning SO Planning and classified as problematic. Affected by this issue is some unknown functionality of the component Public View Setting Handler. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-27113. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27112 | Simple Online Planning SO Planning prior 1.52.02 Public View Setting sql injection
10 months ago
A vulnerability has been found in Simple Online Planning SO Planning and classified as critical. Affected by this vulnerability is an unknown functionality of the component Public View Setting Handler. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-27112. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-6091 | significant-gravitas AutoGPT up to 0.5.0 Denylist Setting os command injection
10 months ago
A vulnerability, which was classified as very critical, was found in significant-gravitas AutoGPT up to 0.5.0. Affected is an unknown function of the component Denylist Setting Handler. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2024-6091. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45786 | Reedos Software Solutions Mutual Fund Distribution Product 2.0.1 API Endpoint authorization (CIVN-2024-0291)
10 months ago
A vulnerability, which was classified as problematic, has been found in Reedos Software Solutions Mutual Fund Distribution Product 2.0.1. This issue affects some unknown processing of the component API Endpoint. The manipulation leads to authorization bypass.
The identification of this vulnerability is CVE-2024-45786. The attack may be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-45789 | Reedos Software Solutions Mutual Fund Distribution Product 2.0.1 API Endpoint mode integrity check (CIVN-2024-0291)
10 months ago
A vulnerability classified as problematic was found in Reedos Software Solutions Mutual Fund Distribution Product 2.0.1. This vulnerability affects unknown code of the component API Endpoint. The manipulation of the argument mode leads to improper validation of integrity check value.
This vulnerability was named CVE-2024-45789. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-45790 | Reedos Software Solutions Mutual Fund Distribution Product 2.0.1 API Login excessive authentication (CIVN-2024-0291)
10 months ago
A vulnerability classified as problematic has been found in Reedos Software Solutions Mutual Fund Distribution Product 2.0.1. This affects an unknown part of the component API Login. The manipulation leads to improper restriction of excessive authentication attempts.
This vulnerability is uniquely identified as CVE-2024-45790. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-45787 | Reedos Software Solutions Mutual Fund Distribution Product 2.0.1 API Endpoint exposure of private personal information to an unauthorized actor (CIVN-2024-0291)
10 months ago
A vulnerability was found in Reedos Software Solutions Mutual Fund Distribution Product 2.0.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component API Endpoint. The manipulation leads to exposure of private personal information to an unauthorized actor.
This vulnerability is handled as CVE-2024-45787. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-45788 | Reedos Software Solutions Mutual Fund Distribution Product 2.0.1 API Endpoint improper control of interaction frequency (CIVN-2024-0291)
10 months ago
A vulnerability was found in Reedos Software Solutions Mutual Fund Distribution Product 2.0.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component API Endpoint. The manipulation leads to improper control of interaction frequency.
This vulnerability is known as CVE-2024-45788. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-27115 | Simple Online Planning SO Planning prior 1.52.02 unrestricted upload
10 months ago
A vulnerability was found in Simple Online Planning SO Planning. It has been classified as very critical. Affected is an unknown function. The manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2024-27115. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-27114 | Simple Online Planning SO Planning prior 1.52.02 Setting toctou
10 months ago
A vulnerability was found in Simple Online Planning SO Planning and classified as critical. This issue affects some unknown processing of the component Setting Handler. The manipulation leads to time-of-check time-of-use.
The identification of this vulnerability is CVE-2024-27114. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2014-6642 | Mark's Daily Apple Forum 2.9.4.3 X.509 Certificate cryptographic issues (VU#582497)
10 months ago
A vulnerability was found in Mark's Daily Apple Forum 2.9.4.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component X.509 Certificate Handler. The manipulation leads to cryptographic issues.
This vulnerability is known as CVE-2014-6642. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
硬件密钥集体破防,英飞凌芯片暗藏 14 年高危漏洞
10 months ago
error code: 521
[Control systems] ABB security advisory (AV24-513)
10 months ago
Canadian Centre for Cyber Security
网络攻击影响学区运行,美国西雅图上万学生被迫停课 2 天
10 months ago
error code: 521
CVE-2006-2731 | Enigma Haber admin/e_mesaj_yaz.asp \s\ sql injection (EDB-1840 / XFDB-26837)
10 months ago
A vulnerability has been found in Enigma Haber and classified as critical. This vulnerability affects unknown code of the file admin/e_mesaj_yaz.asp. The manipulation of the argument \s\ leads to sql injection.
This vulnerability was named CVE-2006-2731. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com