|
313081
|
8.1 |
HIGH
Network
|
fiware
|
keyrock
|
Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to take over the account of any user by predicting the token for the password reset link.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2024-42163
|
2024-08-30 00:17 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313082
|
9.8 |
CRITICAL
Network
|
oretnom23
|
music_gallery_site
|
A vulnerability classified as critical has been found in SourceCodester Music Gallery Site 1.0. This affects an unknown part of the file /admin/?page=musics/manage_music. The manipulation of the argu…
|
CWE-89
SQL Injection
|
CVE-2024-8222
|
2024-08-30 00:13 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313083
|
9.8 |
CRITICAL
Network
|
oretnom23
|
music_gallery_site
|
A vulnerability classified as critical was found in SourceCodester Music Gallery Site 1.0. This vulnerability affects unknown code of the file /classes/Master.php?f=delete_category. The manipulation …
|
CWE-89
SQL Injection
|
CVE-2024-8223
|
2024-08-30 00:11 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313084
|
9.8 |
CRITICAL
Network
|
angeljudesuarez
|
tailoring_management_system
|
A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file staffedit.php. The …
|
CWE-89
SQL Injection
|
CVE-2024-8220
|
2024-08-29 23:49 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313085
|
9.0 |
CRITICAL
Network
|
microsoft
|
edge_chromium
|
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
|
CWE-843
Type Confusion
|
CVE-2024-38219
|
2024-08-29 23:45 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313086
|
5.4 |
MEDIUM
Network
|
ibm
|
aspera_shares
|
IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 260574.
|
CWE-384
Session Fixation
|
CVE-2023-38018
|
2024-08-29 23:36 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313087
|
7.2 |
HIGH
Network
|
abinitio
|
authorization_gateway metadata_hub
|
An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code via crafted modification of server configuration.
|
CWE-94
Code Injection
|
CVE-2024-37382
|
2024-08-29 23:29 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313088
|
5.3 |
MEDIUM
Network
|
dorsettcontrols
|
infoscan
|
Dorsett Controls InfoScan is vulnerable due to a leak of possible
sensitive information through the response headers and the rendered
JavaScript prior to user login.
|
NVD-CWE-noinfo
|
CVE-2024-42493
|
2024-08-29 23:24 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313089
|
7.5 |
HIGH
Network
|
dorsettcontrols
|
infoscan
|
Dorsett Controls Central Server update server has potential information
leaks with an unprotected file that contains passwords and API keys.
|
NVD-CWE-noinfo
|
CVE-2024-39287
|
2024-08-29 23:23 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313090
|
3.7 |
LOW
Network
|
dorsettcontrols
|
infoscan
|
The InfoScan client download page can be intercepted with a proxy, to
expose filenames located on the system, which could lead to additional
information exposure.
|
CWE-22
Path Traversal
|
CVE-2024-42408
|
2024-08-29 23:22 |
2024-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|