6.2

CVSS3.1

CVE-2024-34075 - kurwov vulnerable to Denial of Service due to improper data sanitization

kurwov is a fast, dependency-free library for creating Markov Chains. An unsafe sanitization of dataset contents on the `MarkovData#getNext` method used in `Markov#generate` and `Markov#choose` allows a maliciously crafted string on the dataset to throw and stop the function from running properly. …

πŸ“… Published: May 3, 2024, 5:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS3.1

CVE-2024-34066 - Arbitrary File Write/Read in Pterodactyl wings

Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it accidentally somewhere, an attacker can use it to gain arbitrary file write and read access on the node the token is associated to. This issue has…

πŸ“… Published: May 3, 2024, 5:42 p.m. πŸ”„ Last Modified: Feb. 21, 2025, 3:15 p.m.

5.3

CVSS3.1

CVE-2023-28952 - IBM Cognos Controller log injection

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data. IBM X-Force ID: 251463.

πŸ“… Published: May 3, 2024, 5:39 p.m. πŸ”„ Last Modified: Jan. 7, 2025, 7:19 p.m.

6.1

CVSS3.1

CVE-2024-34067 - Multiple cross site scripting (XSS) vulnerabilities in the admin area of Pterodactyl panel

Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance could lead to cross site scripting (XSS) on the panel, which could be used to gain an administrator account on the panel. Specifically, the fo…

πŸ“… Published: May 3, 2024, 5:38 p.m. πŸ”„ Last Modified: June 6, 2025, 7:15 p.m.

6.3

CVSS3.1

CVE-2023-38724 - IBM Cognos Controller SQL injection

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 262183.

πŸ“… Published: May 3, 2024, 5:36 p.m. πŸ”„ Last Modified: Jan. 14, 2025, 8:16 p.m.

5.9

CVSS3.1

CVE-2023-40696 - IBM Cognos Controller information disclosure

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 264939.

πŸ“… Published: May 3, 2024, 5:34 p.m. πŸ”„ Last Modified: Jan. 7, 2025, 7:14 p.m.

6.4

CVSS3.1

CVE-2024-34068 - Server-side Request Forgery during remote file pull in Pterodactyl wings

Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the previously implemented access control (GHSA-6rg3-8h8x-5xfv) that prevents accessing internal endpoints of the node hosting Wings in the pull endpoint. Thi…

πŸ“… Published: May 3, 2024, 5:34 p.m. πŸ”„ Last Modified: Feb. 21, 2025, 3:19 p.m.

5.3

CVSS3.1

CVE-2021-20556 - IBM Cognos Controller information disclosure

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 199181.

πŸ“… Published: May 3, 2024, 5:31 p.m. πŸ”„ Last Modified: Jan. 7, 2025, 6:20 p.m.

3.7

CVSS3.1

CVE-2023-23474 - IBM Cognos Controller information disclosure

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 245403.

πŸ“… Published: May 3, 2024, 5:15 p.m. πŸ”„ Last Modified: Jan. 7, 2025, 7:14 p.m.

4.3

CVSS3.1

CVE-2021-20450 - IBM Cognos Controller information disclosure

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insec…

πŸ“… Published: May 3, 2024, 4:55 p.m. πŸ”„ Last Modified: June 18, 2025, 3:21 p.m.
Total resulsts: 349182
Page 9988 of 34,919
Β« previous page Β» next page
Filters