7.5

CVSS3.1

CVE-2024-5013 - WhatsUp Gold InstallController Denial-of-Service Vulnerability

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service vulnerability was identified. An unauthenticated attacker can put the application into the SetAdminPassword installation step, which renders the application non-accessible.

📅 Published: June 25, 2024, 8:11 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:46 a.m.

8.6

CVSS3.1

CVE-2024-5012 - WhatsUp Gold Missing Authentication GetWindowsCredential Information Disclosure Vulnerability

In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Credentials. This vulnerability allows unauthenticated attackers to disclose Windows Credentials stored in the product Credential Library.

📅 Published: June 25, 2024, 8:10 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:46 a.m.

8.8

CVSS3.1

CVE-2024-38516 - Aimeos HTML client may potentially reveal sensitive information in error log

ai-client-html is an Aimeos e-commerce HTML client component. Debug information revealed sensitive information from environment variables in error log. This issue has been patched in versions 2024.04.7, 2023.10.15, 2022.10.13 and 2021.10.22.

📅 Published: June 25, 2024, 8:08 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-6206 -

A security vulnerability has been identified in HPE Athonet Mobile Core software. The core application contains a code injection vulnerability where a threat actor could execute arbitrary commands with the privilege of the underlying container leading to complete takeover of the target system.

📅 Published: June 25, 2024, 8:05 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-5011 - WhatsUp Gold TestController Chart denial of service vulnerability

In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A specially crafted unauthenticated HTTP request to the TestController Chart functionality can lead to denial of service.

📅 Published: June 25, 2024, 8:01 p.m. 🔄 Last Modified: Feb. 13, 2025, 5:53 p.m.

7.5

CVSS3.1

CVE-2024-5010 - WhatsUp Gold TestController multiple information disclosure vulnerabilities

In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality.  A specially crafted unauthenticated HTTP request can lead to a disclosure of sensitive information.

📅 Published: June 25, 2024, 8 p.m. 🔄 Last Modified: Feb. 13, 2025, 5:53 p.m.

8.4

CVSS3.1

CVE-2024-5009 - WhatsUp Gold SetAdminPassword Improper Access Control Privilege Escalation Vulnerability

In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.InstallController.SetAdminPassword allows local attackers to modify admin's password.

📅 Published: June 25, 2024, 7:58 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:46 a.m.

8.8

CVSS3.1

CVE-2024-5008 - WhatsUp Gold APM Unrestricted File Upload Remote Code Execution Vulnerability

In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using Apm.UI.Areas.APM.Controllers.Api.Applications.AppProfileImportController.

📅 Published: June 25, 2024, 7:57 p.m. 🔄 Last Modified: Nov. 21, 2024, 9:46 a.m.

7.7

CVSS3.0

CVE-2024-4498 - Path Traversal and RFI Vulnerability in parisneo/lollms-webui

A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affecting versions v9.7 to the latest. The vulnerability arises from insufficient input validation in the `/apply_settings` function, allowing an attacker to manipulate the `discussion_db…

📅 Published: June 25, 2024, 7:55 p.m. 🔄 Last Modified: July 9, 2025, 2:24 p.m.

9.8

CVSS3.1

CVE-2024-4885 - WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.

📅 Published: June 25, 2024, 7:48 p.m. 🔄 Last Modified: Oct. 31, 2025, 9:57 p.m.
Total resulsts: 349182
Page 9332 of 34,919
« previous page » next page
Filters