6.2

CVSS4.0

CVE-2024-5402 - Mint Workbench I Unquoted Service Path Enumeration

Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who successfully exploited this vulnerability could gain elevated privileges by inserting an executable file in the path of the affected service. This issue affects Mint Workbench I versions: from 5866 before…

📅 Published: July 15, 2024, 11:57 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:47 a.m.

6.9

CVSS4.0

CVE-2024-6745 - code-projects Simple Ticket Booking Login adminauthenticate.php sql injection

A vulnerability classified as critical has been found in code-projects Simple Ticket Booking 1.0. Affected is an unknown function of the file adminauthenticate.php of the component Login. The manipulation of the argument email/password leads to sql injection. It is possible to launch the attack rem…

📅 Published: July 15, 2024, 11 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:50 a.m.

4.3

CVSS3.1

CVE-2024-6398 -

An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows information stored in a customizable block page to be disclosed to third-party websites due to Same Origin Policy Bypass of browsers in certain scenarios. The risk is low, because other…

📅 Published: July 15, 2024, 8:52 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:49 a.m.

4.2

CVSS3.1

CVE-2024-39767 - Spoofed push notifications from malicious server

Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that se…

📅 Published: July 15, 2024, 8:43 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:28 a.m.

2.6

CVSS3.1

CVE-2024-32945 - LaTeX post content manipulation via renderer state leak across contexts

Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.

📅 Published: July 15, 2024, 8:42 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:16 a.m.

5.8

CVSS3.1

CVE-2024-6741 - Openfind Mail2000 - HttpOnly flag bypass

Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.

📅 Published: July 15, 2024, 8:26 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:50 a.m.

6.1

CVSS3.1

CVE-2024-6740 - Openfind Mail2000 - Stored XSS

Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject JavaScript code within the attachment and perform Stored Cross-site scripting attacks.

📅 Published: July 15, 2024, 8 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:50 a.m.

8.8

CVSS3.1

CVE-2023-49566 - Apache Linkis DataSource: JDBC Datasource Module with DB2 has JNDI Injection vulnerability

In Apache Linkis <=1.5.0, due to the lack of effective filtering of parameters, an attacker configuring malicious db2 parameters in the DataSource Manager Module will result in jndi injection. Therefore, the parameters in the DB2 URL should be blacklisted.  This attack requires the attacker t…

📅 Published: July 15, 2024, 7:56 a.m. 🔄 Last Modified: March 27, 2025, 4:15 p.m.

8.8

CVSS3.1

CVE-2023-46801 - Apache Linkis DataSource: DataSource Remote code execution vulnerability

In Apache Linkis <= 1.5.0, data source management module, when adding Mysql data source, exists remote code execution vulnerability for java version < 1.8.0_241. The deserialization vulnerability exploited through jrmp can inject malicious files into the server and execute them. This attack requ…

📅 Published: July 15, 2024, 7:55 a.m. 🔄 Last Modified: Nov. 21, 2024, 8:29 a.m.

6.5

CVSS3.1

CVE-2023-41916 - Apache Linkis DataSource: DatasourceManager module has a JDBC parameter judgment logic vulnerabili…

In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will trigger arbitrary file reading. Therefore, the parameters in the Mysql JDBC URL should be blacklisted. This attack requires t…

📅 Published: July 15, 2024, 7:53 a.m. 🔄 Last Modified: March 14, 2025, 4:15 p.m.
Total resulsts: 344009
Page 8631 of 34,401
« previous page » next page
Filters