Low - CVE-2023-23472 - IBM InfoSphere DataStage Flow Designer...
IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.
Medium - CVE-2024-11351 - The Restrict – membership, site, content and...
The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.8...
Medium - CVE-2024-51460 - IBM InfoSphere Information Server 11.7 could...
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could...
NA - VU#164934 - PDQ Deploy allows reuse of deleted credentials that can compromise a device and facilitate lateral movement
OverviewPDQ Deploy is a service intended for usage by system administrators for the deployment of software or updates to targeted machines within their network. PDQ Deploy uses "run modes" to...
NA - CVE-2024-50585 - Users who click on a malicious link or visit a...
Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server...
NA - CVE-2024-28139 - The www-data user can elevate its privileges...
The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the...
NA - CVE-2024-28140 - The scanner device boots into a kiosk mode by...
The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user. There are also several other...
NA - CVE-2024-28141 - The web application is not protected against...
The web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users into performing actions on the application when they visit an...
NA - CVE-2024-47758 - GLPI is a free asset and IT management software...
GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the API to take control of any user that have the same...
NA - CVE-2024-53677 - File upload logic is flawed vulnerability in...
File upload logic is flawed vulnerability in Apache Struts. This issue affects Apache Struts: from 2.0.0 before 6.4.0. Users are recommended to upgrade to version 6.4.0, which fixes the issue....