91
|
8.2 |
HIGH
Network
-
|
-
|
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate validat…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2024-40702
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
92
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code to private packages or reposit…
New
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-28778
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
93
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser.
New
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-25037
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
94
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.…
New
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2022-22363
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
95
|
3.7 |
LOW
Network
|
-
|
-
|
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.…
New
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2021-20455
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
96
|
- |
|
-
|
-
|
A vulnerability was found in code-projects Online Book Shop 1.0. It has been classified as critical. This affects an unknown part of the file /booklist.php. The manipulation of the argument subcatid …
New
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0296
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
97
|
- |
|
-
|
-
|
A vulnerability was found in code-projects Online Book Shop 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /booklist.php?subcatid=1. The manipulat…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0295
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
98
|
- |
|
-
|
-
|
A malicious or compromised MacPorts mirror can execute arbitrary commands as root on the machine of a client running port selfupdate against the mirror.
New
|
-
|
CVE-2024-11681
|
2025-01-8 01:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
99
|
- |
|
-
|
-
|
The Category Posts Widget WordPress plugin before 4.9.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting…
New
|
-
|
CVE-2024-9638
|
2025-01-8 01:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
100
|
- |
|
-
|
-
|
The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Stored Cross-Site Script…
New
|
-
|
CVE-2024-8857
|
2025-01-8 01:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|