NA - CVE-2024-34831 - cross-site scripting (XSS) vulnerability in...
cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter in the library_manage_catalog_editProcess.php component.
NA - CVE-2024-45596 - Directus is a real-time API and App dashboard...
Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the...
NA - CVE-2024-43040 - Renwoxing Enterprise Intelligent Management...
Renwoxing Enterprise Intelligent Management System before v3.0 was discovered to contain a SQL injection vulnerability via the parid parameter at /fx/baseinfo/SearchInfo.
NA - CVE-2024-8503 - An unauthenticated attacker can leverage a...
An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.