1931
|
- |
|
-
|
-
|
GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potentially execute arbitr…
|
CWE-20 CWE-36
Improper Input Validation Absolute Path Traversal
|
CVE-2024-56321
|
2025-01-4 01:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1932
|
- |
|
-
|
-
|
GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature, an…
|
CWE-285
Improper Authorization
|
CVE-2024-56320
|
2025-01-4 01:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1933
|
4.3 |
MEDIUM
Network
|
-
|
-
|
IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-5591
|
2025-01-4 00:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1934
|
- |
|
-
|
-
|
An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attackers to execute arbitrary code via uploading a crafted file.
|
-
|
CVE-2024-55078
|
2025-01-4 00:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1935
|
- |
|
-
|
-
|
SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function
|
-
|
CVE-2024-48814
|
2025-01-4 00:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1936
|
4.2 |
MEDIUM
Physics
|
-
|
-
|
IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could
could allow a physical user to obtain sensitive information due to not masking passwords during entry.
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2024-41780
|
2025-01-4 00:15 |
2025-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1937
|
- |
|
-
|
-
|
A vulnerability was found in code-projects Point of Sales and Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /user/add_cart.php…
|
-
|
CVE-2025-0176
|
2025-01-4 00:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1938
|
- |
|
-
|
-
|
Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2024-9140. This vulnerability allows OS command injection due to improperly rest…
|
-
|
CVE-2024-9140
|
2025-01-3 18:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1939
|
- |
|
-
|
-
|
Moxa’s cellular routers, secure routers, and network security appliances are affected by a high-severity vulnerability, CVE-2024-9138. This vulnerability involves hard-coded credentials, enabling an …
|
-
|
CVE-2024-9138
|
2025-01-3 18:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1940
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.4 d…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-12132
|
2025-01-3 18:15 |
2025-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|