Show filters
132 Total Results
Displaying 31-40 of 132
Sort by:
Attacker Value
Unknown
CVE-2024-5682
Disclosure Date: September 18, 2024 (last updated September 19, 2024)
Improper Restriction of Excessive Authentication Attempts vulnerability in Yordam Information Technology Yordam Library Automation System allows Interface Manipulation.This issue affects Yordam Library Automation System: before 20.1.
0
Attacker Value
Unknown
CVE-2024-5625
Disclosure Date: July 18, 2024 (last updated July 19, 2024)
Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup.This issue affects Apinizer Management Console: before 2024.05.1.
0
Attacker Value
Unknown
CVE-2024-5620
Disclosure Date: July 18, 2024 (last updated January 05, 2025)
Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Console allows Authentication Bypass.This issue affects Apinizer Management Console: before 2024.05.1.
0
Attacker Value
Unknown
CVE-2024-5619
Disclosure Date: July 18, 2024 (last updated January 05, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apinizer Management Console: before 2024.05.1.
0
Attacker Value
Unknown
CVE-2024-5618
Disclosure Date: July 18, 2024 (last updated January 05, 2025)
Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Apinizer Management Console: before 2024.05.1.
0
Attacker Value
Unknown
CVE-2024-0949
Disclosure Date: June 27, 2024 (last updated January 05, 2025)
Improper Access Control, Missing Authorization, Incorrect Authorization, Incorrect Permission Assignment for Critical Resource, Missing Authentication, Weak Authentication, Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Talya Informatics Elektraweb allows Exploiting Incorrectly Configured Access Control Security Levels, Manipulating Web Input to File System Calls, Embedding Scripts within Scripts, Malicious Logic Insertion, Modification of Windows Service Configuration, Malicious Root Certificate, Intent Spoof, WebView Exposure, Data Injected During Configuration, Incomplete Data Deletion in a Multi-Tenant Environment, Install New Service, Modify Existing Service, Install Rootkit, Replace File Extension Handlers, Replace Trusted Executable, Modify Shared File, Add Malicious File to Shared Webroot, Run Software at Logon, Disable Security Software.This issue affects Elektraweb: before v17.0.68.
0
Attacker Value
Unknown
CVE-2024-0947
Disclosure Date: June 27, 2024 (last updated January 05, 2025)
Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Session Credential Falsification through Manipulation, Accessing/Intercepting/Modifying HTTP Cookies, Manipulating Opaque Client-based Data Tokens.This issue affects Elektraweb: before v17.0.68.
0
Attacker Value
Unknown
CVE-2024-1100
Disclosure Date: May 30, 2024 (last updated May 31, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vadi Corporate Information Systems DIGIKENT GIS allows SQL Injection.This issue affects DIGIKENT GIS: through 2.23.5.
0
Attacker Value
Unknown
CVE-2024-4300
Disclosure Date: April 29, 2024 (last updated January 05, 2025)
E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Accessing this path allows attacker to obtain the database credential with the highest privilege and database host IP address. With this information, attackers can connect to the database and perform actions such as adding, modifying, or deleting database contents.
0
Attacker Value
Unknown
CVE-2024-33682
Disclosure Date: April 26, 2024 (last updated April 26, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Cookie Information A/S WP GDPR Compliance.This issue affects WP GDPR Compliance: from n/a through 2.0.23.
0