Show filters
9,350 Total Results
Displaying 241-250 of 9,350
Sort by:
Attacker Value
Unknown
CVE-2025-23369
Disclosure Date: January 21, 2025 (last updated February 27, 2025)
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unauthorized internal users. Instances not utilizing SAML single sign-on or where the attacker is not already an existing user were not impacted. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12.14, 3.13.10, 3.14.7, 3.15.2, and 3.16.0. This vulnerability was reported via the GitHub Bug Bounty program.
0
Attacker Value
Unknown
CVE-2025-22322
Disclosure Date: January 21, 2025 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Private Messages for UserPro allows Reflected XSS. This issue affects Private Messages for UserPro: from n/a through 4.10.0.
0
Attacker Value
Unknown
CVE-2025-22311
Disclosure Date: January 21, 2025 (last updated February 27, 2025)
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Private Messages for UserPro. This issue affects Private Messages for UserPro: from n/a through 4.10.0.
0
Attacker Value
Unknown
CVE-2024-49700
Disclosure Date: January 21, 2025 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound ARPrice allows Reflected XSS. This issue affects ARPrice: from n/a through 4.0.3.
0
Attacker Value
Unknown
CVE-2024-49699
Disclosure Date: January 21, 2025 (last updated February 27, 2025)
Deserialization of Untrusted Data vulnerability in NotFound ARPrice allows Object Injection. This issue affects ARPrice: from n/a through 4.0.3.
0
Attacker Value
Unknown
CVE-2024-49688
Disclosure Date: January 21, 2025 (last updated February 27, 2025)
Deserialization of Untrusted Data vulnerability in NotFound ARPrice allows Object Injection. This issue affects ARPrice: from n/a through 4.0.3.
0
Attacker Value
Unknown
CVE-2024-49666
Disclosure Date: January 21, 2025 (last updated February 27, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound ARPrice allows SQL Injection. This issue affects ARPrice: from n/a through 4.0.3.
0
Attacker Value
Unknown
CVE-2024-49655
Disclosure Date: January 21, 2025 (last updated February 27, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound ARPrice allows SQL Injection. This issue affects ARPrice: from n/a through 4.0.3.
0
Attacker Value
Unknown
CVE-2024-49338
Disclosure Date: January 18, 2025 (last updated February 27, 2025)
IBM App Connect Enterprise 12.0.1.0 through 12.0.7.0and 13.0.1.0 under certain configurations could allow a privileged user to obtain JMS credentials.
0
Attacker Value
Unknown
CVE-2025-0557
Disclosure Date: January 18, 2025 (last updated February 27, 2025)
A vulnerability classified as problematic has been found in Hyland Alfresco Community Edition and Alfresco Enterprise Edition up to 6.2.2. This affects an unknown part of the file /share/s/ of the component URL Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0 is able to address this issue. It is recommended to upgrade the affected component.
0