8.8

CVSS3.1

CVE-2024-37532 - IBM WebSphere Application Server identity spoofing

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X-Force ID: 294721.

πŸ“… Published: June 20, 2024, 1:22 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:24 a.m.

5.3

CVSS4.0

CVE-2024-6187 - Ruijie RG-UAC sub_commit.php os command injection

A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This vulnerability affects unknown code of the file /view/vpn/autovpn/sub_commit.php. The manipulation of the argument key leads to os command injection. The attack can be initiated remotely. The exploit has been disclo…

πŸ“… Published: June 20, 2024, 1 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 12:58 a.m.

7.8

CVSS3.1

CVE-2023-49113 - Sensitive Data Stored Insecurely in Kiuwan SAST Local Analyzer

The Kiuwan Local Analyzer (KLA) Java scanning application contains several hard-coded secrets in plain text format. In some cases, this can potentially compromise the confidentiality of the scan results.Β Several credentials were found in the JAR files of the Kiuwan Local Analyzer. The JAR file …

πŸ“… Published: June 20, 2024, 12:39 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2023-49112 - Insecure Direct Object Reference in Kiuwan SAST

Kiuwan provides an API endpoint /saas/rest/v1/info/application to get information about any application, providing only its name via the "application" parameter. This endpoint lacks proper access control mechanisms, allowing other authenticated users to read information about applications, eve…

πŸ“… Published: June 20, 2024, 12:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2023-49111 - Reflected Cross-Site-Scripting in Kiuwan SAST

For Kiuwan installations with SSO (single sign-on) enabled, an unauthenticated reflected cross-site scripting attack can be performed on the login page "login.html". This is possible due to the request parameter "message" values being directly included in a JavaScript block in the response. This…

πŸ“… Published: June 20, 2024, 12:34 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-6186 - Ruijie RG-UAC commit.php os command injection

A vulnerability, which was classified as critical, was found in Ruijie RG-UAC 1.0. This affects an unknown part of the file /view/userAuthentication/SSO/commit.php. The manipulation of the argument ad_log_name leads to os command injection. It is possible to initiate the attack remotely. The exploi…

πŸ“… Published: June 20, 2024, 12:31 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 1:01 a.m.

7.2

CVSS3.1

CVE-2023-49110 - XML External Entity Injection in Kiuwan SAST

When the Kiuwan Local Analyzer uploads the scan results to the Kiuwan SAST web application (either on-premises or cloud/SaaS solution), the transmitted data consists of a ZIP archive containing several files, some of them in the XML file format. During Kiuwan's server-side processing of these XM…

πŸ“… Published: June 20, 2024, 12:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-6185 - Ruijie RG-UAC commit.php get_ip_addr_details os command injection

A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC 1.0. Affected by this issue is the function get_ip_addr_details of the file /view/dhcp/dhcpConfig/commit.php. The manipulation of the argument ethname leads to os command injection. The attack may be launched remotel…

πŸ“… Published: June 20, 2024, noon πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

5.3

CVSS4.0

CVE-2024-6184 - Ruijie RG-UAC reboot_commit.php os command injection

A vulnerability classified as critical was found in Ruijie RG-UAC 1.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/reboot/reboot_commit.php. The manipulation of the argument servicename leads to os command injection. The attack can be launched remotely.…

πŸ“… Published: June 20, 2024, 11:31 a.m. πŸ”„ Last Modified: Aug. 21, 2025, 1:04 a.m.

6.9

CVSS4.0

CVE-2024-6183 - EZ-Suite EZ-Partner Forgot Password cross site scripting

A vulnerability classified as problematic has been found in EZ-Suite EZ-Partner 5. Affected is an unknown function of the component Forgot Password Handler. The manipulation leads to basic cross site scripting. It is possible to launch the attack remotely. VDB-269154 is the identifier assigned to t…

πŸ“… Published: June 20, 2024, 11:31 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.
Total resulsts: 349182
Page 9376 of 34,919
Β« previous page Β» next page
Filters