811
|
4.8 |
MEDIUM
Network
|
-
|
-
|
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get …
|
CWE-614
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
|
CVE-2024-28770
|
2025-01-27 11:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
812
|
2.4 |
LOW
Adjacent
|
-
|
-
|
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could disclose sensitive information about directory contents that could aid in further attacks against the…
|
CWE-548
Exposure of Information Through Directory Listing
|
CVE-2024-28766
|
2025-01-27 11:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
813
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IBM InfoSphere Master Data Management 11.6, 12.0, and 14.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering…
|
CWE-79
Cross-site Scripting
|
CVE-2023-46187
|
2025-01-27 11:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
814
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability classified as critical was found in needyamin image_gallery 1.0. This vulnerability affects unknown code of the file /admin/gallery.php of the component Cover Image Handler. The manip…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2025-0722
|
2025-01-27 09:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
815
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability classified as problematic has been found in needyamin image_gallery 1.0. This affects the function image_gallery of the file /view.php. The manipulation of the argument username leads…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0721
|
2025-01-27 09:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
816
|
3.3 |
LOW
Local
|
-
|
-
|
A vulnerability was found in Microword eScan Antivirus 7.0.32 on Linux. It has been rated as problematic. Affected by this issue is the function removeExtraSlashes of the file /opt/MicroWorld/sbin/rt…
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2025-0720
|
2025-01-27 08:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
817
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM Common Licensing 9.0 could allow an authenticated user to modify a configuration file that they should not have access to due to a broken authorization mechanism.
|
CWE-863
Incorrect Authorization
|
CVE-2023-50946
|
2025-01-27 01:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
818
|
6.2 |
MEDIUM
Local
|
-
|
-
|
IBM Common Licensing 9.0 stores user credentials in plain clear text which can be read by a local user.
|
CWE-256
Plaintext Storage of a Password
|
CVE-2023-50945
|
2025-01-27 01:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
819
|
4.2 |
MEDIUM
Physics
|
-
|
-
|
IBM Cognos Mobile Client 1.1 iOS may be vulnerable to information disclosure through man in the middle techniques due to the lack of certificate pinning.
|
CWE-295
Improper Certificate Validation
|
CVE-2023-38009
|
2025-01-27 01:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
820
|
6.2 |
MEDIUM
Local
|
-
|
-
|
IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.
|
CWE-525
Use of Web Browser Cache Containing Sensitive Information
|
CVE-2024-31906
|
2025-01-27 00:15 |
2025-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|