Show filters
4,047 Total Results
Displaying 841-850 of 4,047
Sort by:
Attacker Value
Unknown

CVE-2024-2265

Disclosure Date: March 07, 2024 (last updated March 12, 2025)
A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. This affects an unknown part of the file login.sql. The manipulation leads to inclusion of sensitive information in source code. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256035. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-2264

Disclosure Date: March 07, 2024 (last updated March 12, 2025)
A vulnerability, which was classified as critical, has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-256034 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-2216

Disclosure Date: March 06, 2024 (last updated February 26, 2025)
A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions.
0
Attacker Value
Unknown

CVE-2024-2215

Disclosure Date: March 06, 2024 (last updated February 26, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting future build step executions.
0
Attacker Value
Unknown

CVE-2024-28162

Disclosure Date: March 06, 2024 (last updated February 26, 2025)
In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections fails to take effect until Jenkins is restarted when switching from disabled validation to enabled validation.
0
Attacker Value
Unknown

CVE-2024-28161

Disclosure Date: March 06, 2024 (last updated February 26, 2025)
In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled by default.
0
Attacker Value
Unknown

CVE-2024-28160

Disclosure Date: March 06, 2024 (last updated February 26, 2025)
Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
0
Attacker Value
Unknown

CVE-2024-28159

Disclosure Date: March 06, 2024 (last updated February 26, 2025)
A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build.
0
Attacker Value
Unknown

CVE-2024-28158

Disclosure Date: March 06, 2024 (last updated February 26, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers to trigger a build.
0
Attacker Value
Unknown

CVE-2024-28157

Disclosure Date: March 06, 2024 (last updated February 26, 2025)
Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
0