8.3
CVE-2025-24858 -
Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by Develocity was chosen according to best practices for password storage and provides some protection aβ¦
8.1
CVE-2022-49043 - libxml: use-after-free in xmlXIncludeAddNode
xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.
7.1
CVE-2024-46881 -
Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in Enterprise Config schema version 8. Migration functionality from schema version 8 to versions 9 and 10 (in affected vulnerable versions) does not includβ¦
8.5
CVE-2025-0543 - G DATA Security Client Local privilege escalation
Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing an arbitrary executable in a globally writable directory resulting in eβ¦
7.3
CVE-2025-0542 - G DATA Management Server Local privilege escalation
Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing a crafted ZIP archive in a globally writaβ¦
5.3
CVE-2024-35150 - IBM Maximo Application Suite log manipulation
IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.
6.3
CVE-2024-35148 - IBM Maximo Application Suite SQL injection
IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
5.3
CVE-2024-35144 - IBM Maximo Application Suite information disclosure
IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against the system.
6.1
CVE-2024-35145 - IBM Maximo Application Suite cross-site scripting
IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusteβ¦
5.3
CVE-2024-35134 - IBM Analytics Content Hub information disclosure
IBM Analytics Content Hub 2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.