NA - CVE-2024-7118 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Affected by this vulnerability is an unknown functionality of the file...
CVE-2024-0760 - A Flood Of DNS Messages Over TCP May Make The Server Unstable
A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. This issue affects...
CVE-2024-1737 - BIND's Database Will Be Slow If A Very Large Number Of RRs Exist At The Same Name
A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. This issue affects...
CVE-2024-1975 - SIG(0) Can Be Used To Exhaust CPU Resources
If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, a client can exhaust resolver CPU resources by sending a stream of SIG(0) signed requests. This...
CVE-2024-4076 - Assertion Failure When Serving Both Stale Cache Data And Authoritative Zone Content
Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue affects BIND 9 versions 9.16.13 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19...
NA - CVE-2024-24621 - Softaculous Webuzo contains an authentication...
Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, anonymous attackers can exploit this vulnerability to gain full server access as...
NA - CVE-2024-24622 - Softaculous Webuzo contains a command injection...
Softaculous Webuzo contains a command injection in the password reset functionality. A remote, authenticated attacker can exploit this vulnerability to gain code execution on the system.
NA - CVE-2024-24623 - Softaculous Webuzo contains a command injection...
Softaculous Webuzo contains a command injection vulnerability in the FTP management functionality. A remote, authenticated attacker can exploit this vulnerability to gain code execution on the system.
NA - CVE-2024-3938 - The "reset password" login page accepted an...
The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patch, and as such it cannot be demonstrated via Demo site link. Those interested...