NA - CVE-2024-44821 - ZZCMS 2023 contains a vulnerability in the...
ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does not properly refresh the captcha value after a failed validation attempt. As...
NA - CVE-2024-45050 - Ringer server is the server code for the Ringer...
Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messages loading route where Ringer Server does not check to ensure that the user...
NA - CVE-2024-45052 - Fides is an open-source privacy engineering...
Fides is an open-source privacy engineering platform. Prior to version 2.44.0, a timing-based username enumeration vulnerability exists in Fides Webserver authentication. This vulnerability allows...
NA - CVE-2024-45053 - Fides is an open-source privacy engineering...
Fides is an open-source privacy engineering platform. Starting in version 2.19.0 and prior to version 2.44.0, the Email Templating feature uses Jinja2 without proper input sanitization or rendering...
Medium - CVE-2024-45074 - IBM webMethods Integration 10.15 could allow an...
IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences...
High - CVE-2024-45075 - IBM webMethods Integration 10.15 could allow an...
IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to missing authentication.
Critical - CVE-2024-45076 - IBM webMethods Integration 10.15 could allow an...
IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be executed on the underlying operating system.
NA - CVE-2024-8380 - A vulnerability was found in SourceCodester...
A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been rated as critical. This issue affects some unknown processing of the file...
High - CVE-2024-42057 - A command injection vulnerability in the IPSec...
A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG FLEX 50(W)...