Show filters
961 Total Results
Displaying 61-70 of 961
Sort by:
Attacker Value
Unknown

CVE-2024-8259

Disclosure Date: December 09, 2024 (last updated December 18, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection.This issue affects NatraCar B2B Dealer Management Program: through 09.12.2024. NOTE: The vendor was contacted and it was learned that the product is not supported.
Attacker Value
Unknown

CVE-2024-54002

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Performing a login request against the /api/v1/user/login endpoint with a username that exist in the system takes significantly longer than performing the same action with a username that is not known by the system. The observable difference in request duration can be leveraged by actors to enumerate valid names of managed users. LDAP and OpenID Connect users are not affected. The issue has been fixed in Dependency-Track 4.12.2.
0
Attacker Value
Unknown

CVE-2024-54158

Disclosure Date: December 04, 2024 (last updated January 31, 2025)
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
Attacker Value
Unknown

CVE-2024-54157

Disclosure Date: December 04, 2024 (last updated January 31, 2025)
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
Attacker Value
Unknown

CVE-2024-54156

Disclosure Date: December 04, 2024 (last updated January 31, 2025)
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
Attacker Value
Unknown

CVE-2024-54155

Disclosure Date: December 04, 2024 (last updated February 01, 2025)
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
Attacker Value
Unknown

CVE-2024-54154

Disclosure Date: December 04, 2024 (last updated February 01, 2025)
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
Attacker Value
Unknown

CVE-2024-54153

Disclosure Date: December 04, 2024 (last updated February 01, 2025)
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
Attacker Value
Unknown

CVE-2024-7026

Disclosure Date: November 21, 2024 (last updated January 13, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection.This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2024-51607

Disclosure Date: November 09, 2024 (last updated November 09, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Buddy Lindsey Golf Tracker allows SQL Injection.This issue affects Golf Tracker: from n/a through 0.7.
0