Show filters
731 Total Results
Displaying 41-50 of 731
Sort by:
Attacker Value
Unknown
CVE-2024-9315
Disclosure Date: September 28, 2024 (last updated October 02, 2024)
A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/maintenance/manage_department.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2024-9203
Disclosure Date: September 26, 2024 (last updated September 27, 2024)
A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. This issue affects some unknown processing. The manipulation leads to cleartext storage of sensitive information in memory. An attack has to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 6.10.1 is able to address this issue. It is recommended to upgrade the affected component.
0
Attacker Value
Unknown
CVE-2024-44798
Disclosure Date: September 13, 2024 (last updated September 17, 2024)
phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-details.php via fromdate and todate parameters.
0
Attacker Value
Unknown
CVE-2024-7015
Disclosure Date: September 09, 2024 (last updated September 18, 2024)
Improper Authentication, Missing Authentication for Critical Function, Improper Authorization vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse.This issue affects PassBox: before v1.2.
0
Attacker Value
Unknown
CVE-2024-42904
Disclosure Date: September 03, 2024 (last updated September 13, 2024)
A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter at /Controllers/ClientController.php.
0
Attacker Value
Unknown
CVE-2024-5546
Disclosure Date: August 28, 2024 (last updated September 20, 2024)
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.
0
Attacker Value
Unknown
CVE-2020-11850
Disclosure Date: August 21, 2024 (last updated August 24, 2024)
Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Cross-Site Scripting (XSS). This issue affects Self Service Password Reset before 4.5.0.2 and 4.4.0.6
0
Attacker Value
Unknown
CVE-2024-42219
Disclosure Date: August 06, 2024 (last updated August 13, 2024)
1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient.
0
Attacker Value
Unknown
CVE-2024-42218
Disclosure Date: August 06, 2024 (last updated August 13, 2024)
1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.
0
Attacker Value
Unknown
CVE-2024-7326
Disclosure Date: July 31, 2024 (last updated August 16, 2024)
A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknown part in the library RTL120.BPL of the component BPL Handler. The manipulation leads to uncontrolled search path. It is possible to launch the attack on the local host. The identifier VDB-273249 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0