Show filters
463 Total Results
Displaying 81-90 of 463
Sort by:
Attacker Value
Unknown
CVE-2023-49332
Disclosure Date: May 20, 2024 (last updated May 21, 2024)
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.
0
Attacker Value
Unknown
CVE-2023-49331
Disclosure Date: May 20, 2024 (last updated May 21, 2024)
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.
0
Attacker Value
Unknown
CVE-2023-49330
Disclosure Date: May 20, 2024 (last updated May 21, 2024)
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate report data.
0
Attacker Value
Unknown
CVE-2024-4599
Disclosure Date: May 07, 2024 (last updated May 07, 2024)
Remote denial of service vulnerability in LAN Messenger affecting version 3.4.0. This vulnerability allows an attacker to crash the LAN Messenger service by sending a long string directly and continuously over the UDP protocol.
0
Attacker Value
Unknown
CVE-2024-32563
Disclosure Date: April 18, 2024 (last updated April 18, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VikBooking Hotel Booking Engine & PMS allows Reflected XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.6.7.
0
Attacker Value
Unknown
CVE-2024-32519
Disclosure Date: April 17, 2024 (last updated April 17, 2024)
Missing Authorization vulnerability in GutenGeek GG Woo Feed for WooCommerce.This issue affects GG Woo Feed for WooCommerce: from n/a through 1.2.6.
0
Attacker Value
Unknown
CVE-2024-3689
Disclosure Date: April 12, 2024 (last updated April 13, 2024)
A vulnerability classified as problematic has been found in Zhejiang Land Zongheng Network Technology O2OA up to 20240403. Affected is an unknown function of the file /x_portal_assemble_surface/jaxrs/portal/list?v=8.2.3-4-43f4fe3. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. VDB-260478 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-3707
Disclosure Date: April 12, 2024 (last updated July 05, 2024)
Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to enumerate all files in the web tree by accessing a php file.
0
Attacker Value
Unknown
CVE-2024-3706
Disclosure Date: April 12, 2024 (last updated July 05, 2024)
Information exposure vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to view a php backup file (controlaccess.php-LAST) where database credentials are stored.
0
Attacker Value
Unknown
CVE-2024-3705
Disclosure Date: April 12, 2024 (last updated April 13, 2024)
Unrestricted file upload vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to send a POST request to the endpoint '/opengnsys/images/M_Icons.php' modifying the file extension, due to lack of file extension verification, resulting in a webshell injection.
0