Show filters
731 Total Results
Displaying 61-70 of 731
Sort by:
Attacker Value
Unknown
CVE-2024-3122
Disclosure Date: July 01, 2024 (last updated January 05, 2025)
CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.
0
Attacker Value
Unknown
CVE-2024-5976
Disclosure Date: June 13, 2024 (last updated August 17, 2024)
A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been classified as critical. Affected is the function log_employee of the file /classes/Master.php?f=log_employee. The manipulation of the argument employee_code leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-268422 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-5897
Disclosure Date: June 12, 2024 (last updated August 24, 2024)
A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=log_visitor. The manipulation of the argument name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-268141 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-5896
Disclosure Date: June 12, 2024 (last updated August 24, 2024)
A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is the function save_users of the file /classes/Users.php?f=save. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268140.
0
Attacker Value
Unknown
CVE-2024-5895
Disclosure Date: June 12, 2024 (last updated August 15, 2024)
A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. This issue affects the function delete_users of the file /classes/Users.php?f=delete. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-268139.
0
Attacker Value
Unknown
CVE-2024-5813
Disclosure Date: June 11, 2024 (last updated February 12, 2025)
A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.
0
Attacker Value
Unknown
CVE-2024-5812
Disclosure Date: June 11, 2024 (last updated February 12, 2025)
A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request.
0
Attacker Value
Unknown
CVE-2023-51436
Disclosure Date: June 03, 2024 (last updated June 03, 2024)
Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.8, which may allow a remote authenticated attacker with an administrative privilege to execute an arbitrary script on the web browser of the user who is using the product.
0
Attacker Value
Unknown
CVE-2023-42427
Disclosure Date: June 03, 2024 (last updated June 03, 2024)
Cross-site scripting vulnerability exists in UNIVERSAL PASSPORT RX versions 1.0.0 to 1.0.7, which may allow a remote authenticated attacker to execute an arbitrary script on the web browser of the user who is using the product.
0
Attacker Value
Unknown
CVE-2024-1721
Disclosure Date: May 21, 2024 (last updated May 22, 2024)
Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue affects HYPR Passwordless: before 9.1.
0