2441
|
- |
|
-
|
-
|
GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML E…
|
CWE-611
XXE
|
CVE-2024-56322
|
2025-01-4 01:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2442
|
- |
|
-
|
-
|
GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potentially execute arbitr…
|
CWE-20 CWE-36
Improper Input Validation Absolute Path Traversal
|
CVE-2024-56321
|
2025-01-4 01:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2443
|
- |
|
-
|
-
|
GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, an…
|
CWE-285
Improper Authorization
|
CVE-2024-56320
|
2025-01-4 01:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2444
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-5591
|
2025-01-4 00:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2445
|
- |
|
-
|
-
|
An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attackers to execute arbitrary code via uploading a crafted file.
|
-
|
CVE-2024-55078
|
2025-01-4 00:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2446
|
- |
|
-
|
-
|
SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function
|
-
|
CVE-2024-48814
|
2025-01-4 00:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2447
|
4.2 |
MEDIUM
Physics
|
-
|
-
|
IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could
could allow a physical user to obtain sensitive information due to not masking passwords during entry.
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2024-41780
|
2025-01-4 00:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2448
|
- |
|
-
|
-
|
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /user/add_cart.php…
|
-
|
CVE-2025-0176
|
2025-01-4 00:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2449
|
- |
|
-
|
-
|
Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly rest…
|
-
|
CVE-2024-9140
|
2025-01-3 18:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2450
|
- |
|
-
|
-
|
Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an …
|
-
|
CVE-2024-9138
|
2025-01-3 18:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|