781
|
- |
|
-
|
-
|
Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate privileges on affec…
|
-
|
CVE-2025-0543
|
2025-01-26 02:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
782
|
- |
|
-
|
-
|
Local privilege escalation due to incorrect assignment of privileges of temporary files in the update mechanism of G DATA Management Server. This vulnerability allows a local, unprivileged attacker t…
|
-
|
CVE-2025-0542
|
2025-01-26 02:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
783
|
5.3 |
MEDIUM
Network
-
|
-
|
IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is written to logs, which could allow an attacker to inject false log entries.
|
CWE-117
Improper Output Neutralization for Logs
|
CVE-2024-35150
|
2025-01-26 00:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
784
|
6.3 |
MEDIUM
Network
|
-
|
-
|
IBM Maximo Application Suite 8.10.10, 8.11.7, and 9.0 - Monitor Component is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker…
|
CWE-89
SQL Injection
|
CVE-2024-35148
|
2025-01-26 00:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
785
|
6.1 |
MEDIUM
Network
|
-
|
-
|
IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI th…
|
CWE-79
Cross-site Scripting
|
CVE-2024-35145
|
2025-01-26 00:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
786
|
5.3 |
MEDIUM
Network
-
|
-
|
IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid in further attacks against the system.
|
CWE-540
Inclusion of Sensitive Information in Source Code
|
CVE-2024-35144
|
2025-01-26 00:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
787
|
8.8 |
HIGH
Network
|
-
|
-
|
IBM Analytics Content Hub 2.0 is vulnerable to a buffer overflow due to improper return length checking. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the syst…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2024-39750
|
2025-01-25 23:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
788
|
5.3 |
MEDIUM
Network
-
|
-
|
IBM Analytics Content Hub 2.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in furth…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-35134
|
2025-01-25 23:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
789
|
5.3 |
MEDIUM
Network
-
|
-
|
IBM Control Center 6.2.1 and 6.3.1
could allow a remote attacker to enumerate usernames due to an observable discrepancy between login attempts.
|
CWE-204
Response Discrepancy Information Exposure
|
CVE-2024-35114
|
2025-01-25 23:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
790
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IBM Control Center 6.2.1 and 6.3.1
could allow an authenticated user to obtain sensitive information exposed through a directory listing.
|
CWE-548
Exposure of Information Through Directory Listing
|
CVE-2024-35113
|
2025-01-25 23:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|