Show filters
60 Total Results
Displaying 1-10 of 60
Sort by:
Attacker Value
Unknown
CVE-2024-48257
Disclosure Date: October 14, 2024 (last updated October 17, 2024)
Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.
0
Attacker Value
Unknown
CVE-2024-48251
Disclosure Date: October 14, 2024 (last updated October 17, 2024)
Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
0
Attacker Value
Unknown
CVE-2024-4999
Disclosure Date: May 16, 2024 (last updated May 17, 2024)
A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through 2-5.95-4.Rt3352.
0
Attacker Value
Unknown
CVE-2024-29034
Disclosure Date: March 24, 2024 (last updated January 05, 2025)
CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-49090 wasn't fully addressed. This vulnerability is caused by the fact that when uploading to object storage, including Amazon S3, it is possible to set a Content-Type value that is interpreted by browsers to be different from what's allowed by `content_type_allowlist`, by providing multiple values separated by commas. This bypassed value can be used to cause XSS. Upgrade to 3.0.7 or 2.2.6.
0
Attacker Value
Unknown
CVE-2024-1019
Disclosure Date: January 30, 2024 (last updated February 14, 2025)
ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs before it separates the URL path component from the optional query string component. This results in an impedance mismatch versus RFC compliant back-end applications. The vulnerability hides an attack payload in the path component of the URL from WAF rules inspecting it. A back-end may be vulnerable if it uses the path component of request URLs to construct queries. Integrators and users are advised to upgrade to 3.0.12. The ModSecurity v2 release line is not affected by this vulnerability.
0
Attacker Value
Unknown
CVE-2023-49090
Disclosure Date: November 29, 2023 (last updated December 06, 2023)
CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-Type allowlist bypass vulnerability, possibly leading to XSS. The validation in `allowlisted_content_type?` determines Content-Type permissions by performing a partial match. If the `content_type` argument of `allowlisted_content_type?` is passed a value crafted by the attacker, Content-Types not included in the `content_type_allowlist` will be allowed. This issue has been patched in versions 2.2.5 and 3.0.5.
0
Attacker Value
Unknown
CVE-2023-42471
Disclosure Date: September 11, 2023 (last updated October 08, 2023)
The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to display web content and doesn't adequately validate or sanitize the URI or any extra data passed in the intent by a third party application (with no permissions).
0
Attacker Value
Unknown
CVE-2023-38285
Disclosure Date: July 26, 2023 (last updated October 08, 2023)
Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.
0
Attacker Value
Unknown
CVE-2023-29738
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause code execution and escalation of Privileges via the database files.
0
Attacker Value
Unknown
CVE-2023-29737
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
An issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service via the database files.
0