5.9

CVSS3.1

CVE-2024-45097 - IBM Aspera Faspex bypass security

IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.

📅 Published: Sept. 5, 2024, 3:35 p.m. 🔄 Last Modified: Sept. 6, 2024, 12:51 p.m.

6.5

CVSS3.1

CVE-2024-45096 - IBM Aspera Faspex information disclosure

IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.

📅 Published: Sept. 5, 2024, 3:34 p.m. 🔄 Last Modified: Sept. 6, 2024, 12:34 p.m.

6.8

CVSS3.1

CVE-2024-45098 - IBM Aspera Faspex bypass security

IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource modification.

📅 Published: Sept. 5, 2024, 3:31 p.m. 🔄 Last Modified: Sept. 6, 2024, 1:01 p.m.

6.3

CVSS3.1

CVE-2024-8473 - SQL injection vulnerability in Job Portal

Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through user_email parameter in /jobportal/admin/login.php.

📅 Published: Sept. 5, 2024, 1:08 p.m. 🔄 Last Modified: Sept. 6, 2024, 11:44 a.m.

6.3

CVSS3.1

CVE-2024-8472 - SQL injection vulnerability in Job Portal

Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through multiple parameters in /jobportal/index.php.

📅 Published: Sept. 5, 2024, 1:08 p.m. 🔄 Last Modified: Sept. 6, 2024, 11:44 a.m.

6.3

CVSS3.1

CVE-2024-8471 - SQL injection vulnerability in Job Portal

Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of this vulnerability could allow an attacker to retrieve the session details of an authenticated user through JOBID and USERNAME parameters in /jobportal/process.php.

📅 Published: Sept. 5, 2024, 1:07 p.m. 🔄 Last Modified: Sept. 6, 2024, 11:44 a.m.

7.5

CVSS3.1

CVE-2024-7884 - Memory leak when calling a canister method via `ic_cdk::call`

When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the execution result. Internally, the state of the Future is tracked and stored in a struct called CallFutureState. A bug in the polling implementation of the CallFuture…

📅 Published: Sept. 5, 2024, 1:01 p.m. 🔄 Last Modified: Sept. 12, 2024, 8:47 p.m.

6.3

CVSS4.0

CVE-2024-8462 - Windmill HTTP Request users.rs excessive authentication

A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of the file backend/windmill-api/src/users.rs of the component HTTP Request Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possi…

📅 Published: Sept. 5, 2024, 1 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-8470 - SQL injection vulnerability in Job Portal

SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/vacancy/controller.php, and retrieve all the information stored in it.

📅 Published: Sept. 5, 2024, 12:56 p.m. 🔄 Last Modified: Sept. 6, 2024, 11:44 a.m.

9.8

CVSS3.1

CVE-2024-8469 - SQL injection vulnerability in Job Portal

SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/employee/index.php, and retrieve all the information stored in it.

📅 Published: Sept. 5, 2024, 12:55 p.m. 🔄 Last Modified: Sept. 6, 2024, 11:43 a.m.
Total resulsts: 349182
Page 8650 of 34,919
« previous page » next page
Filters