Show filters
330 Total Results
Displaying 41-50 of 330
Sort by:
Attacker Value
Unknown
CVE-2024-0157
Disclosure Date: April 12, 2024 (last updated February 05, 2025)
Dell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in SRM Windows Host Agent. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to the hijack of a targeted user's application session.
0
Attacker Value
Unknown
CVE-2024-28167
Disclosure Date: April 09, 2024 (last updated April 10, 2024)
SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, specific data can be changed via the Enter Package Data app although the user does not have sufficient authorization causing high impact on Integrity of the appliction.
0
Attacker Value
Unknown
CVE-2024-1856
Disclosure Date: March 20, 2024 (last updated January 17, 2025)
In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization vulnerability.
0
Attacker Value
Unknown
CVE-2024-1801
Disclosure Date: March 20, 2024 (last updated January 17, 2025)
In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.
0
Attacker Value
Unknown
CVE-2024-1821
Disclosure Date: February 23, 2024 (last updated December 21, 2024)
A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file police_add.php. The manipulation of the argument police_name/police_id/police_spec/password leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-254609 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-1820
Disclosure Date: February 23, 2024 (last updated December 21, 2024)
A vulnerability was found in code-projects Crime Reporting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file inchargelogin.php. The manipulation of the argument email/password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254608.
0
Attacker Value
Unknown
CVE-2023-26206
Disclosure Date: February 15, 2024 (last updated March 02, 2024)
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4.2, 9.2.0 - 9.2.8, 9.1.0 - 9.1.10 and 7.2.0 allows an attacker to execute unauthorized code or commands via the name fields observed in the policy audit logs.
0
Attacker Value
Unknown
CVE-2024-0832
Disclosure Date: January 31, 2024 (last updated February 10, 2024)
In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.
0
Attacker Value
Unknown
CVE-2024-0527
Disclosure Date: January 15, 2024 (last updated January 20, 2024)
A vulnerability, which was classified as critical, has been found in CXBSoft Url-shorting up to 1.3.1. This issue affects some unknown processing of the file /admin/pages/update_go.php of the component HTTP POST Request Handler. The manipulation of the argument version leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-250697 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-0526
Disclosure Date: January 15, 2024 (last updated January 20, 2024)
A vulnerability classified as critical was found in CXBSoft Url-shorting up to 1.3.1. This vulnerability affects unknown code of the file /pages/short_to_long.php of the component HTTP POST Request Handler. The manipulation of the argument shorturl leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250696. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0