Show filters
150 Total Results
Displaying 31-40 of 150
Sort by:
Attacker Value
Unknown
CVE-2024-29918
Disclosure Date: March 27, 2024 (last updated January 05, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Reflected XSS.This issue affects Survey Maker: from n/a through 4.0.6.
0
Attacker Value
Unknown
CVE-2024-2828
Disclosure Date: March 22, 2024 (last updated April 11, 2024)
A vulnerability, which was classified as critical, was found in lakernote EasyAdmin up to 20240315. Affected is the function thumbnail of the file src/main/java/com/laker/admin/module/sys/controller/IndexController.java. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 23165d8cb569048c531150f194fea39f8800b8d5. It is recommended to apply a patch to fix this issue. VDB-257718 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-2827
Disclosure Date: March 22, 2024 (last updated April 11, 2024)
A vulnerability, which was classified as critical, has been found in lakernote EasyAdmin up to 20240315. This issue affects some unknown processing of the file /ureport/designer/saveReportFile. The manipulation leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257717 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-2826
Disclosure Date: March 22, 2024 (last updated April 11, 2024)
A vulnerability classified as problematic was found in lakernote EasyAdmin up to 20240315. This vulnerability affects unknown code of the file /ureport/designer/saveReportFile. The manipulation leads to xml external entity reference. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257716.
0
Attacker Value
Unknown
CVE-2024-2825
Disclosure Date: March 22, 2024 (last updated April 11, 2024)
A vulnerability classified as critical has been found in lakernote EasyAdmin up to 20240315. This affects an unknown part of the file /ureport/designer/saveReportFile. The manipulation of the argument file leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257715.
0
Attacker Value
Unknown
CVE-2024-27996
Disclosure Date: March 19, 2024 (last updated April 01, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS.This issue affects Survey Maker: from n/a through 4.0.5.
0
Attacker Value
Unknown
CVE-2024-22049
Disclosure Date: January 04, 2024 (last updated February 14, 2025)
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.
0
Attacker Value
Unknown
CVE-2023-36857
Disclosure Date: October 19, 2023 (last updated October 26, 2023)
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05
contains a replay vulnerability which could allow an attacker to
replay older captured packets of traffic to the device to gain access.
0
Attacker Value
Unknown
CVE-2023-34441
Disclosure Date: October 19, 2023 (last updated October 26, 2023)
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05
contains a cleartext transmission vulnerability which could allow an attacker to
steal the authentication secret from communication traffic to the device and reuse it for arbitrary requests.
0
Attacker Value
Unknown
CVE-2023-34437
Disclosure Date: October 19, 2023 (last updated November 13, 2024)
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05
contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device.
0