Show filters
132 Total Results
Displaying 31-40 of 132
Sort by:
Attacker Value
Unknown

CVE-2024-5682

Disclosure Date: September 18, 2024 (last updated September 19, 2024)
Improper Restriction of Excessive Authentication Attempts vulnerability in Yordam Information Technology Yordam Library Automation System allows Interface Manipulation.This issue affects Yordam Library Automation System: before 20.1.
0
Attacker Value
Unknown

CVE-2024-5625

Disclosure Date: July 18, 2024 (last updated July 19, 2024)
Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup.This issue affects Apinizer Management Console: before 2024.05.1.
0
Attacker Value
Unknown

CVE-2024-5620

Disclosure Date: July 18, 2024 (last updated January 05, 2025)
Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Console allows Authentication Bypass.This issue affects Apinizer Management Console: before 2024.05.1.
0
Attacker Value
Unknown

CVE-2024-5619

Disclosure Date: July 18, 2024 (last updated January 05, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apinizer Management Console: before 2024.05.1.
0
Attacker Value
Unknown

CVE-2024-5618

Disclosure Date: July 18, 2024 (last updated January 05, 2025)
Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Apinizer Management Console: before 2024.05.1.
0
Attacker Value
Unknown

CVE-2024-0949

Disclosure Date: June 27, 2024 (last updated January 05, 2025)
Improper Access Control, Missing Authorization, Incorrect Authorization, Incorrect Permission Assignment for Critical Resource, Missing Authentication, Weak Authentication, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Talya Informatics Elektraweb allows Exploiting Incorrectly Configured Access Control Security Levels, Manipulating Web Input to File System Calls, Embedding Scripts within Scripts, Malicious Logic Insertion, Modification of Windows Service Configuration, Malicious Root Certificate, Intent Spoof, WebView Exposure, Data Injected During Configuration, Incomplete Data Deletion in a Multi-Tenant Environment, Install New Service, Modify Existing Service, Install Rootkit, Replace File Extension Handlers, Replace Trusted Executable, Modify Shared File, Add Malicious File to Shared Webroot, Run Software at Logon, Disable Security Software.This issue affects Elektraweb: before v17.0.68.
0
Attacker Value
Unknown

CVE-2024-0947

Disclosure Date: June 27, 2024 (last updated January 05, 2025)
Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Session Credential Falsification through Manipulation, Accessing/Intercepting/Modifying HTTP Cookies, Manipulating Opaque Client-based Data Tokens.This issue affects Elektraweb: before v17.0.68.
0
Attacker Value
Unknown

CVE-2024-1100

Disclosure Date: May 30, 2024 (last updated May 31, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vadi Corporate Information Systems DIGIKENT GIS allows SQL Injection.This issue affects DIGIKENT GIS: through 2.23.5.
0
Attacker Value
Unknown

CVE-2024-4300

Disclosure Date: April 29, 2024 (last updated January 05, 2025)
E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Accessing this path allows attacker to obtain the database credential with the highest privilege and database host IP address. With this information, attackers can connect to the database and perform actions such as adding, modifying, or deleting database contents.
0
Attacker Value
Unknown

CVE-2024-33682

Disclosure Date: April 26, 2024 (last updated April 26, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Cookie Information A/S WP GDPR Compliance.This issue affects WP GDPR Compliance: from n/a through 2.0.23.
0