Medium - CVE-2024-41780 - IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0...
IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could could allow a physical user to obtain sensitive information due to not masking passwords during entry.
NA - CVE-2024-48814 - SQL Injection vulnerability in Silverpeas 6.4.1...
SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function
NA - CVE-2024-55078 - An arbitrary file upload vulnerability in the...
An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attackers to execute arbitrary code via uploading a crafted file.
Medium - CVE-2024-5591 - IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0...
IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could...
NA - CVE-2024-56320 - GoCD is a continuous deliver server. GoCD...
GoCD is a continuous deliver server. GoCD versions prior to 24.5.0 are vulnerable to admin privilege escalation due to improper authorization of access to the admin "Configuration XML" UI feature,...
NA - CVE-2024-56321 - GoCD is a continuous deliver server. GoCD...
GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potentially execute...
NA - CVE-2024-56322 - GoCD is a continuous deliver server. GoCD...
GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML...
NA - CVE-2024-56324 - GoCD is a continuous deliver server. GoCD...
GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML...
NA - CVE-2024-56408 - PhpSpreadsheet is a PHP library for reading and...
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have no sanitization in the...