7.6
CVE-2021-22532 - Possible NLDAP Denial of Service attack Vulnerability
Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000.
6.5
CVE-2021-22533 - Possible Insertion of Sensitive Information into Log File Vulnerability
Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.
5.4
CVE-2021-38131 - Cross-Site Scripting (XSS) Vulnerability
Possible Cross-Site Scripting (XSS) Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.5.0000.
5.3
CVE-2021-38132 - Possible External service interaction Vulnerability
Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.
7.4
CVE-2021-38133 - Possible Improper authentication Vulnerability in OpenText eDirectory
Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.
4.9
CVE-2022-26322 - Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager
Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST Driver. This impact version before 1.1.2.0200.
5.4
CVE-2024-8750 - Cross-site Scripting vulnerability in Idoit pro
Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack of proper sanitization of the following parameters (id,lang,mNavID,name,pID,treeNode,type,view).
8.8
CVE-2024-8749 - SQL Injection vulnerability in Idoit pro
SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially crafted query to the ID parameter in /var/www/html/src/classes/modules/api/model/cmdb/isys_api_model_cmdb_objects_by_relation.class.php and retrieve all the information stored in the …
8.8
CVE-2024-2010 - Reflected XSS in TE Informatics' V5 Software
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE Informatics V5 allows Reflected XSS.This issue affects V5: before 6.2.
10
CVE-2024-8522 - LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied parameter and lack of suf…