Show filters
961 Total Results
Displaying 61-70 of 961
Sort by:
Attacker Value
Unknown
CVE-2024-8259
Disclosure Date: December 09, 2024 (last updated December 18, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection.This issue affects NatraCar B2B Dealer Management Program: through 09.12.2024.
NOTE: The vendor was contacted and it was learned that the product is not supported.
0
Attacker Value
Unknown
CVE-2024-54002
Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Performing a login request against the /api/v1/user/login endpoint with a username that exist in the system takes significantly longer than performing the same action with a username that is not known by the system. The observable difference in request duration can be leveraged by actors to enumerate valid names of managed users. LDAP and OpenID Connect users are not affected. The issue has been fixed in Dependency-Track 4.12.2.
0
Attacker Value
Unknown
CVE-2024-54158
Disclosure Date: December 04, 2024 (last updated January 31, 2025)
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
0
Attacker Value
Unknown
CVE-2024-54157
Disclosure Date: December 04, 2024 (last updated January 31, 2025)
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
0
Attacker Value
Unknown
CVE-2024-54156
Disclosure Date: December 04, 2024 (last updated January 31, 2025)
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
0
Attacker Value
Unknown
CVE-2024-54155
Disclosure Date: December 04, 2024 (last updated February 01, 2025)
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
0
Attacker Value
Unknown
CVE-2024-54154
Disclosure Date: December 04, 2024 (last updated February 01, 2025)
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
0
Attacker Value
Unknown
CVE-2024-54153
Disclosure Date: December 04, 2024 (last updated February 01, 2025)
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
0
Attacker Value
Unknown
CVE-2024-7026
Disclosure Date: November 21, 2024 (last updated January 13, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection.This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-51607
Disclosure Date: November 09, 2024 (last updated November 09, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Buddy Lindsey Golf Tracker allows SQL Injection.This issue affects Golf Tracker: from n/a through 0.7.
0