Show filters
317,036 Total Results
Displaying 21-30 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-38508

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via a specially crafted request.
0
Attacker Value
Unknown

CVE-2024-39304

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due to an improper sanitization of user input. Authentication is required, but no elevated privileges are necessary. This allows attackers to inject SQL statements directly into the database query due to inadequate sanitization of the EID parameter in in a GET request to `/GetText.php`. Version 5.9.2 patches the issue.
0
Attacker Value
Unknown

CVE-2024-38872

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module.
0
Attacker Value
Unknown

CVE-2024-38871

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.
0
Attacker Value
Unknown

CVE-2024-41813

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting in version 1.4.0 and prior to version 1.6.1, a Server-Side Request Forgery (SSRF) vulnerability in the `/proxy` route of txtdot allows remote attackers to use the server as a proxy to send HTTP GET requests to arbitrary targets and retrieve information in the internal network. Version 1.6.1 patches the issue.
0
Attacker Value
Unknown

CVE-2024-41812

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Prior to version 1.7.0, a Server-Side Request Forgery (SSRF) vulnerability in the `/get` route of txtdot allows remote attackers to use the server as a proxy to send HTTP GET requests to arbitrary targets and retrieve information in the internal network. Version 1.7.0 prevents displaying the response of forged requests, but the requests can still be sent. For complete mitigation, a firewall between txtdot and other internal network resources should be set.
0
Attacker Value
Unknown

CVE-2024-41375

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php
0
Attacker Value
Unknown

CVE-2024-41374

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php
0
Attacker Value
Unknown

CVE-2024-41373

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.
0
Attacker Value
Unknown

CVE-2024-41354

Disclosure Date: July 26, 2024 (last updated July 27, 2024)
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php
0