2481
|
- |
|
-
|
-
|
While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in logic implementation allows an authenticated user to reset it's bracket and then p…
|
-
|
CVE-2024-11716
|
2025-01-3 03:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2482
|
- |
|
-
|
-
|
The does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
|
-
|
CVE-2024-11846
|
2025-01-3 03:15 |
2025-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2483
|
- |
|
-
|
-
|
A vulnerability has been found in code-projects Chat System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/deleteroom.php. The manipulat…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2025-0172
|
2025-01-3 01:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2484
|
- |
|
-
|
-
|
A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows
unauthenticated user to modify compliance scripts due to insecure temporary directory.
|
-
|
CVE-2024-9950
|
2025-01-3 01:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2485
|
- |
|
-
|
-
|
Web installer integrity check used weak hash algorithm. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
|
CWE-328
Use of Weak Hash
|
CVE-2024-56414
|
2025-01-3 01:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2486
|
- |
|
-
|
-
|
Missing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
|
CWE-613
Insufficient Session Expiration
|
CVE-2024-56413
|
2025-01-3 01:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2487
|
- |
|
-
|
-
|
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-55543
|
2025-01-3 01:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2488
|
- |
|
-
|
-
|
Local privilege escalation due to excessive permissions assigned to Tray Monitor service. The following products are affected: Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169, Acr…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2024-55542
|
2025-01-3 01:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2489
|
- |
|
-
|
-
|
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169.
|
CWE-79
Cross-site Scripting
|
CVE-2024-55541
|
2025-01-3 01:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2490
|
- |
|
-
|
-
|
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2024-55540
|
2025-01-3 01:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|