2761
|
6.2 |
MEDIUM
Local
|
-
|
-
|
IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-52897
|
2024-12-20 03:15 |
2024-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2762
|
5.3 |
MEDIUM
Network
|
-
|
-
|
IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service when trace is enabled due to information being written into memory outside of …
|
CWE-125
Out-of-bounds Read
|
CVE-2024-51471
|
2024-12-20 03:15 |
2024-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2763
|
6.5 |
MEDIUM
Network
-
|
-
|
IBM Security Guardium 11.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-49336
|
2024-12-20 03:15 |
2024-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2764
|
- |
|
-
|
-
|
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain …
|
-
|
CVE-2024-38819
|
2024-12-20 03:15 |
2024-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2765
|
- |
|
-
|
-
|
A vulnerability, which was classified as critical, was found in Codezips E-Commerce Site 1.0. This affects an unknown part of the file /admin/editorder.php. The manipulation of the argument dstatus/q…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2024-12794
|
2024-12-20 03:15 |
2024-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2766
|
- |
|
-
|
-
|
A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3. Affected by this issue is some unknown functionality of the file apps/home/controller/IndexController.php…
|
CWE-22
Path Traversal
|
CVE-2024-12793
|
2024-12-20 03:15 |
2024-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2767
|
- |
|
-
|
-
|
A vulnerability classified as critical was found in Codezips E-Commerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file newadmin.php. The manipulation of the argument…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2024-12792
|
2024-12-20 03:15 |
2024-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2768
|
- |
|
-
|
-
|
A vulnerability was found in Codezips E-Commerce Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file signin.php. The manipulation of the argument email lea…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2024-12791
|
2024-12-20 03:15 |
2024-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2769
|
- |
|
-
|
-
|
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (…
|
-
|
CVE-2024-50379
|
2024-12-20 03:15 |
2024-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2770
|
- |
|
-
|
-
|
An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB v0.3.5 allows attackers to execute arbitrary code via supplying a crafted XML input.
|
-
|
CVE-2024-55081
|
2024-12-20 02:15 |
2024-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|