1011
|
- |
|
-
|
-
|
Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the template function of host_templates.php using the graph_template parameter. This vul…
|
CWE-89
SQL Injection
|
CVE-2024-54146
|
2025-01-28 02:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1012
|
- |
|
-
|
-
|
Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the get_discovery_results function of automation_devices.php using the network parameter…
|
CWE-89
SQL Injection
|
CVE-2024-54145
|
2025-01-28 02:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1013
|
3.7 |
LOW
Network
|
-
|
-
|
A vulnerability classified as problematic has been found in TP-Link TL-SG108E 1.0.0 Build 20201208 Rel. 40304. Affected is an unknown function of the file /usr_account_set.cgi of the component HTTP G…
|
CWE-598
Information Exposure Through Query Strings in GET Request
|
CVE-2025-0730
|
2025-01-28 02:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1014
|
5.9 |
MEDIUM
Network
|
-
|
-
|
IBM MQ Container 3.0.0, 3.0.1, 3.1.0 through 3.1.3 CD, 2.0.0 LTS through 2.0.22 LTS and 2.4.0 through 2.4.8, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2 uses weaker than expected cryptographic algorithm…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2024-27256
|
2025-01-28 02:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1015
|
- |
|
-
|
-
|
Cacti is an open source performance and fault management framework. Prior to 1.2.29, an administrator can change the `Poller Standard Error Log Path` parameter in either Installation Step 5 or in Con…
|
CWE-22
Path Traversal
|
CVE-2024-45598
|
2025-01-28 01:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1016
|
5.9 |
MEDIUM
Network
|
-
|
-
|
IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI
could allow a remote attacker to obtain sensitive information, caused by sending network requests over an insecure channel. …
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2024-38325
|
2025-01-28 01:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1017
|
5.9 |
MEDIUM
Network
|
-
|
-
|
IBM Storage Protect for Virtual Environments: Data Protection for VMware and Storage Protect Backup-Archive Client 8.1.0.0 through 8.1.23.0 uses weaker than expected cryptographic algorithms that cou…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2024-38320
|
2025-01-28 01:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1018
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intende…
|
CWE-79
Cross-site Scripting
|
CVE-2024-37527
|
2025-01-28 01:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1019
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an authenticated user to perform unauthorized actions to another user's data due to improper access controls.
|
CWE-284
Improper Access Control
|
CVE-2024-22316
|
2025-01-28 01:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1020
|
6.4 |
MEDIUM
Network
|
-
|
-
|
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the W…
|
CWE-79
Cross-site Scripting
|
CVE-2023-52292
|
2025-01-28 01:15 |
2025-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|