NA - CVE-2024-57433 - macrozheng mall-tiny 1.0.1 is vulnerable to...
macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, their token is still available and fetches information in the logged-in state.
NA - CVE-2024-57434 - macrozheng mall-tiny 1.0.1 is vulnerable to...
macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control. The project imports users by default, and the test user is made a super administrator.
NA - CVE-2024-57435 - In macrozheng mall-tiny 1.0.1, an attacker can...
In macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a null pointer dereference occurring in all subsequent operations that require...
Medium - CVE-2023-38739 - IBM Sterling B2B Integrator 6.0.0.0 through...
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized...
NA - CVE-2024-11741 - Grafana is an open-source platform for...
Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission....
Medium - CVE-2024-40696 - IBM Sterling B2B Integrator 6.0.0.0 through...
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed...
Medium - CVE-2024-45089 - IBM Sterling B2B Integrator 6.0.0.0 through...
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allow an authenticated user to obtain sensitive filename information due to an...
Medium - CVE-2024-47103 - IBM Sterling B2B Integrator 6.0.0.0 through...
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed...