NA - CVE-2022-40490 - Tiny File Manager v2.4.7 and below was...
Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected...
NA - CVE-2024-13614 - Kaspersky has fixed a security issue in...
Kaspersky has fixed a security issue in Kaspersky Anti-Virus SDK for Windows, Kaspersky Security for Virtualization Light Agent, Kaspersky Endpoint Security for Windows, Kaspersky Small Office...
NA - CVE-2024-39033 - In Newgensoft OmniDocs 11.0_SP1_03_006,...
In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII to be stolen.
NA - CVE-2024-39272 - A cross-site scripting (xss) vulnerability...
A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to an arbitrary html code....
NA - CVE-2024-43779 - An information disclosure vulnerability exists...
An information disclosure vulnerability exists in the Vault API functionality of ClearML Enterprise Server 3.22.5-1533. A specially crafted HTTP request can lead to reading vaults that have been...
NA - CVE-2024-57427 - PHPJabbers Cinema Booking System v2.0 is...
PHPJabbers Cinema Booking System v2.0 is vulnerable to reflected cross-site scripting (XSS). Multiple endpoints improperly handle user input, allowing malicious scripts to execute in a victim’s...
NA - CVE-2024-57428 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized input in file upload fields (event_img, seat_maps) and seat number...
NA - CVE-2024-57429 - A cross-site request forgery (CSRF)...
A cross-site request forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0 allows remote attackers to escalate privileges by tricking an authenticated...
NA - CVE-2024-57430 - An SQL injection vulnerability in the...
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers to manipulate database queries via the column parameter. Exploiting this...