6.3
CVE-2024-11717 -
Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When used, they are sent to the server as a GET parameter and they are not single use, which means, that during token expiration time an on-path attacker might reuse such a token to cβ¦
5.3
CVE-2024-11716 -
While assignment of a user to a team (bracket) inΒ CTFd should be possible only once, at the registration, a flaw in logic implementation allows an authenticated user to reset it's bracket and then pick a new one, joining another team while a competition is already ongoing. This issue impacts releaβ¦
5.3
CVE-2024-12907 - XSS in Kentico 7
Kentico CMS in version 7 is vulnerable to a Reflected XSS attacks through manipulation of a specific GET request parameter sent toΒ /CMSMessages/AccessDenied.aspx endpoint. Notably, support for this version of Kentico ended in 2016. Version 8 was tested as well and does not contain this vulnerabiliβ¦
8.5
CVE-2024-9950 - Abuse of Unauthenticated Compliance Recheck in SecureConnector
A vulnerability in Forescout SecureConnector v11.3.07.0109Β on Windows allows unauthenticated user to modify compliance scripts due to insecure temporary directory.
5.3
CVE-2025-0172 - code-projects Chat System deleteroom.php sql injection
A vulnerability has been found in code-projects Chat System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/deleteroom.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has β¦
3.1
CVE-2024-55541 -
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169.
4.4
CVE-2024-55542 -
Local privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169, Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35895.
5.5
CVE-2024-56414 -
Web installer integrity check used weak hash algorithm. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
6.1
CVE-2024-56413 -
Missing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
6.6
CVE-2024-55540 -
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.