Aggregator
CVE-2024-47779 | element-hq element-web up to 1.11.80 information disclosure (GHSA-3jm3-x98c-r34x)
9 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in element-hq element-web up to 1.11.80. This issue affects some unknown processing. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-47779. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-47824 | matrix-org matrix-react-sdk up to 3.101.x information disclosure (GHSA-qcvh-p9jq-wp8v)
9 months 3 weeks ago
A vulnerability classified as problematic was found in matrix-org matrix-react-sdk up to 3.101.x. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability was named CVE-2024-47824. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-48781 | Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 imageformat Privilege Escalation
9 months 3 weeks ago
A vulnerability classified as critical has been found in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6. This affects an unknown part of the file file/opt/EdrawProj-2/plugins/imageformat. The manipulation leads to Privilege Escalation.
This vulnerability is uniquely identified as CVE-2024-48781. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2024-31955 | Samsung eMMC KLM8G1WEMB/KLMAG2GE4A improper authentication
9 months 3 weeks ago
A vulnerability was found in Samsung eMMC KLMAG2GE4A/KLM8G1WEMB. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper authentication.
This vulnerability is handled as CVE-2024-31955. It is possible to launch the attack on the physical device. There is no exploit available.
vuldb.com
CVE-2024-47876 | sakai 23.0/23.1/23.2 improper authorization (GHSA-cx95-q6gx-w4qp)
9 months 3 weeks ago
A vulnerability was found in sakai 23.0/23.1/23.2. It has been classified as critical. Affected is an unknown function. The manipulation leads to improper authorization.
This vulnerability is traded as CVE-2024-47876. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-48783 | Ruijie NBR3000D-E postgresql.conf information disclosure
9 months 3 weeks ago
A vulnerability was found in Ruijie NBR3000D-E. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /tool/shell/postgresql.conf. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2024-48783. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-9954 | Google Chrome up to 129.0.6668.100 AI use after free (ID 367755)
9 months 3 weeks ago
A vulnerability was found in Google Chrome and classified as critical. This issue affects some unknown processing of the component AI. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2024-9954. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-48411 | itsourcecode Online Tours and Travels Management System 1.0 forget_password.php val-email sql injection
9 months 3 weeks ago
A vulnerability has been found in itsourcecode Online Tours and Travels Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file forget_password.php. The manipulation of the argument val-email leads to sql injection.
This vulnerability was named CVE-2024-48411. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2024-47874 | encode starlette up to 0.39.x allocation of resources (GHSA-f96h-pmfr-66vw)
9 months 3 weeks ago
A vulnerability, which was classified as critical, was found in encode starlette up to 0.39.x. This affects an unknown part. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2024-47874. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-35584 | OpenSis Community Edition 8.0/9.1 Insert Statement Ajax.php X-Forwarded-For sql injection
9 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in OpenSis Community Edition 8.0/9.1. Affected by this issue is some unknown functionality of the file Ajax.php of the component Insert Statement Handler. The manipulation of the argument X-Forwarded-For leads to sql injection.
This vulnerability is handled as CVE-2024-35584. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-9955 | Google Chrome up to 129.0.6668.100 WebAuthentication use after free (ID 370133)
9 months 3 weeks ago
A vulnerability classified as critical was found in Google Chrome. Affected by this vulnerability is an unknown functionality of the component WebAuthentication. The manipulation leads to use after free.
This vulnerability is known as CVE-2024-9955. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9957 | Google Chrome up to 129.0.6668.100 on iOS UI use after free (ID 358151)
9 months 3 weeks ago
A vulnerability classified as critical has been found in Google Chrome on iOS. Affected is an unknown function of the component UI. The manipulation leads to use after free.
This vulnerability is traded as CVE-2024-9957. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-9956 | Google Chrome up to 129.0.6668.100 on Android WebAuthentication Local Privilege Escalation (ID 370482)
9 months 3 weeks ago
A vulnerability was found in Google Chrome on Android. It has been rated as critical. This issue affects some unknown processing of the component WebAuthentication. The manipulation leads to Local Privilege Escalation.
The identification of this vulnerability is CVE-2024-9956. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-45085 | IBM WebSphere Application Server 8.5 Request unusual condition
9 months 3 weeks ago
A vulnerability was found in IBM WebSphere Application Server 8.5. It has been declared as critical. This vulnerability affects unknown code of the component Request Handler. The manipulation leads to improper check for unusual conditions.
This vulnerability was named CVE-2024-45085. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21196 | Oracle MySQL Server up to 8.0.39/8.4.2/9.0.1 X Plugin improper authorization
9 months 3 weeks ago
A vulnerability was found in Oracle MySQL Server up to 8.0.39/8.4.2/9.0.1. It has been classified as critical. This affects an unknown part of the component X Plugin. The manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2024-21196. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21198 | Oracle MySQL Server up to 8.0.39/8.4.2/9.0.1 DDL improper authorization
9 months 3 weeks ago
A vulnerability was found in Oracle MySQL Server up to 8.0.39/8.4.2/9.0.1 and classified as critical. Affected by this issue is some unknown functionality of the component DDL. The manipulation leads to improper authorization.
This vulnerability is handled as CVE-2024-21198. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21197 | Oracle MySQL Server up to 8.0.39/8.4.2/9.0.1 Information Schema improper authorization
9 months 3 weeks ago
A vulnerability has been found in Oracle MySQL Server up to 8.0.39/8.4.2/9.0.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Information Schema. The manipulation leads to improper authorization.
This vulnerability is known as CVE-2024-21197. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21195 | Oracle BI Publisher 7.0.0.0.0/7.6.0.0.0/12.2.1.4.0 Layout Templates improper authorization
9 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Oracle BI Publisher 7.0.0.0.0/7.6.0.0.0/12.2.1.4.0. Affected is an unknown function of the component Layout Templates. The manipulation leads to improper authorization.
This vulnerability is traded as CVE-2024-21195. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-21194 | Oracle MySQL Server up to 8.0.39/8.4.2/9.0.1 InnoDB improper authorization
9 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Oracle MySQL Server up to 8.0.39/8.4.2/9.0.1. This issue affects some unknown processing of the component InnoDB. The manipulation leads to improper authorization.
The identification of this vulnerability is CVE-2024-21194. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com