10

CVSS3.1

CVE-2024-29202 - JumpServer vulnerable to Jinja2 template injection in Ansible leads to RCE in Celery

JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and h…

πŸ“… Published: March 29, 2024, 2:57 p.m. πŸ”„ Last Modified: March 25, 2025, 8:15 p.m.

10

CVSS3.1

CVE-2024-29201 - JumpServer's insecure Ansible playbook validation leads to RCE in Celery

JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and has database …

πŸ“… Published: March 29, 2024, 2:57 p.m. πŸ”„ Last Modified: March 25, 2025, 8:15 p.m.

4.6

CVSS3.1

CVE-2024-29020 - JumpServer allows nn authorized attacker to get sensitive information in playbook files when playbo…

JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker can obtain sensitive information contained within playbook files if they manage to learn the playbook_id of another user. This breach of confidentiality can lead to information d…

πŸ“… Published: March 29, 2024, 2:46 p.m. πŸ”„ Last Modified: Jan. 9, 2025, 5:20 p.m.

4.6

CVSS3.1

CVE-2024-29024 - JumpServer Direct Object Reference (IDOR) Vulnerability in File Manager Bulk Transfer Functionality

JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability in the file manager's bulk transfer by manipulating job IDs to upload malicious files, potentially compromis…

πŸ“… Published: March 29, 2024, 2:45 p.m. πŸ”„ Last Modified: Jan. 9, 2025, 5:32 p.m.

8.4

CVSS3.1

CVE-2024-23537 - Apache Fineract: Under certain circumstances, this vulnerability allowed users, without specific pe…

Improper Privilege Management vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.9.0, which fixes the issue.

πŸ“… Published: March 29, 2024, 2:38 p.m. πŸ”„ Last Modified: Feb. 13, 2025, 6:17 p.m.

9.9

CVSS3.1

CVE-2024-23538 - Apache Fineract: Under certain system configurations, the sqlSearch parameter was vulnerable to SQL…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.

πŸ“… Published: March 29, 2024, 2:37 p.m. πŸ”„ Last Modified: Feb. 13, 2025, 6:17 p.m.

8.3

CVSS3.1

CVE-2024-23539 - Apache Fineract: Under certain system configurations, the sqlSearch parameter for specific endpoint…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.

πŸ“… Published: March 29, 2024, 2:36 p.m. πŸ”„ Last Modified: Feb. 13, 2025, 6:17 p.m.

3.5

CVSS3.1

CVE-2024-3081 - EasyCorp EasyAdmin Autocomplete autocomplete.js cross site scripting

A vulnerability was found in EasyCorp EasyAdmin up to 4.8.9. It has been declared as problematic. Affected by this vulnerability is the function Autocomplete of the file assets/js/autocomplete.js of the component Autocomplete. The manipulation of the argument item leads to cross site scripting. The…

πŸ“… Published: March 29, 2024, 2:31 p.m. πŸ”„ Last Modified: April 29, 2025, 7:44 p.m.

5.9

CVSS3.1

CVE-2024-28867 - Swift Prometheus un-sanitized metric name or labels can be used to take over exported metrics

Swift Prometheus is a Swift client for the Prometheus monitoring system, supporting counters, gauges and histograms. In code which applies _un-sanitized string values into metric names or labels_, an attacker could make use of this and send a `?lang` query parameter containing newlines, `}` or sim…

πŸ“… Published: March 29, 2024, 2:26 p.m. πŸ”„ Last Modified: March 25, 2025, 2:39 p.m.

6.5

CVSS3.1

CVE-2024-30508 - WordPress WP Hotel Booking plugin <= 2.0.9.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through 2.0.9.2.

πŸ“… Published: March 29, 2024, 2:17 p.m. πŸ”„ Last Modified: April 28, 2026, 4:09 p.m.
Total resulsts: 349182
Page 10509 of 34,919
Β« previous page Β» next page
Filters