NA - CVE-2024-10385 - Ticket management system in DirectAdmin...
Ticket management system in DirectAdmin Evolution Skin is vulnerable to XSS (Cross-site Scripting), which allows a low-privileged user to inject and store malicious JavaScript code. If an admin...
Medium - CVE-2024-12840 - A server-side request forgery exists in...
A server-side request forgery exists in Satellite. When a PUT HTTP request is made to /http_proxies/test_connection, when supplied with the http_proxies variable set to localhost, the attacker can...
NA - CVE-2024-55186 - An IDOR (Insecure Direct Object Reference)...
An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to access inbox messages of other users by manipulating the notification ID in...
NA - CVE-2024-55470 - Oqtane Framework 6.0.0 is vulnerable to...
Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application or...
NA - CVE-2024-55471 - Oqtane Framework is vulnerable to Insecure...
Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to access sensitive information of other users by...
NA - CVE-2024-56337 - Time-of-check Time-of-use (TOCTOU) Race...
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1...