Show filters
1,993 Total Results
Displaying 61-70 of 1,993
Sort by:
Attacker Value
Unknown

CVE-2024-41768

Disclosure Date: January 04, 2025 (last updated January 05, 2025)
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause an unhandled SSL exception which could leave the connection in an unexpected or insecure state.
Attacker Value
Unknown

CVE-2024-41767

Disclosure Date: January 04, 2025 (last updated January 05, 2025)
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
Attacker Value
Unknown

CVE-2024-41766

Disclosure Date: January 04, 2025 (last updated January 05, 2025)
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of service using a complex regular expression.
Attacker Value
Unknown

CVE-2024-41765

Disclosure Date: January 04, 2025 (last updated January 05, 2025)
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Attacker Value
Unknown

CVE-2024-41763

Disclosure Date: January 04, 2025 (last updated January 05, 2025)
IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
Attacker Value
Unknown

CVE-2023-48758

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in Crocoblock JetEngine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through 3.2.4.
0
Attacker Value
Unknown

CVE-2024-39727

Disclosure Date: December 25, 2024 (last updated January 13, 2025)
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 uses a web link with untrusted references to an external site. A remote attacker could exploit this vulnerability to expose sensitive information or perform unauthorized actions on the victims’ web browser.
Attacker Value
Unknown

CVE-2024-39725

Disclosure Date: December 25, 2024 (last updated January 13, 2025)
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
Attacker Value
Unknown

CVE-2024-12272

Disclosure Date: December 25, 2024 (last updated January 05, 2025)
The WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.7 via several widgets. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Attacker Value
Unknown

CVE-2024-55946

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Playloom Engine is an open-source, high-performance game development engine. Engine Beta v0.0.1 has a security vulnerability related to data storage, specifically when using the collaboration features. When collaborating with another user, they may have access to personal information you have entered into the software. This poses a risk to user privacy. The maintainers of Playloom Engine have temporarily disabled the collaboration feature until a fix can be implemented. When Engine Beta v0.0.2 is released, it is expected to contain a patch addressing this issue. Users should refrain from using the collaboration feature in the meantime.
0