6.3

CVSS3.1

CVE-2023-50316 - IBM Sterling B2B Integrator information disclosure

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.

πŸ“… Published: Jan. 28, 2025, 12:22 a.m. πŸ”„ Last Modified: Jan. 28, 2025, 3:17 p.m.

9.8

CVSS3.1

CVE-2022-3365 - Emote Interactive Remote Mouse Server command injection due to weak encoding

Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS commands over theproduct's custom control protocol. A Metasploit mo…

πŸ“… Published: Jan. 28, 2025, 12:13 a.m. πŸ”„ Last Modified: Jan. 28, 2025, 4:15 p.m.

5.3

CVSS3.1

CVE-2024-27263 - IBM Sterling B2B Integrator information disclosure

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to obtain sensitive information from the dashboard UI using man in the middle techniques.

πŸ“… Published: Jan. 28, 2025, 12:10 a.m. πŸ”„ Last Modified: Jan. 28, 2025, 3:18 p.m.

8.8

CVSS3.1

CVE-2024-55968 -

An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1. The com.dtexsystems.helper service, responsible for handling privileged operations within the macOS DTEX Event Forwarder agent, fails to implement critical client validation during XPC interprocess communication (IPC). Specifically, the …

πŸ“… Published: Jan. 28, 2025, midnight πŸ”„ Last Modified: March 24, 2025, 5:15 p.m.

5.4

CVSS3.1

CVE-2025-22917 -

A reflected cross-site scripting (XSS) vulnerability in Audemium ERP <=0.9.0 allows remote attackers to execute an arbitrary JavaScript payload in the web browser of a user by including a malicious payload into the 'type' parameter of list.php.

πŸ“… Published: Jan. 28, 2025, midnight πŸ”„ Last Modified: Jan. 29, 2025, 4:15 p.m.

4.8

CVSS3.1

CVE-2024-57514 -

The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the web interface. When a specially crafted URL is visited, the router's web page renders the directory listing and executes arbitrary JavaScript embedded in the URL. …

πŸ“… Published: Jan. 28, 2025, midnight πŸ”„ Last Modified: Jan. 29, 2025, 4:15 p.m.

7.5

CVSS3.1

CVE-2024-57519 -

An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.

πŸ“… Published: Jan. 28, 2025, midnight πŸ”„ Last Modified: April 30, 2025, 4:42 p.m.

7.5

CVSS3.1

CVE-2024-48310 -

AutoLib Software Systems OPAC v20.10 was discovered to have multiple API keys exposed within the source code. Attackers may use these keys to access the backend API or other sensitive information.

πŸ“… Published: Jan. 28, 2025, midnight πŸ”„ Last Modified: March 25, 2025, 2:15 p.m.

8.8

CVSS3.1

CVE-2024-57376 -

Buffer Overflow vulnerability in D-Link DSR-150, DSR-150N, DSR-250, DSR-250N, DSR-500N, DSR-1000N from 3.13 to 3.17B901C allows unauthenticated users to execute remote code execution.

πŸ“… Published: Jan. 28, 2025, midnight πŸ”„ Last Modified: July 1, 2025, 3:15 p.m.

5.2

CVSS3.1

CVE-2024-45775 - Grub2: commands/extcmd: missing check for failed allocation

A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for the grub's argument list. However, it fails to check in case the memory allocation fails. Once the allocation fails, a NULL point will be processed by the parse_option() function…

πŸ“… Published: Jan. 28, 2025, midnight πŸ”„ Last Modified: Jan. 29, 2026, 5:01 p.m.
Total resulsts: 343979
Page 6411 of 34,398
Β« previous page Β» next page
Filters