NA - CVE-2024-39741 - IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7,...
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing...
High - CVE-2024-6737 - The access control in the Electronic Official...
The access control in the Electronic Official Document Management System from 2100 TECHNOLOGY is not properly implemented, allowing remote attackers with regular privileges to access the account...
Medium - CVE-2024-6738 - The tumbnail API of Tronclass from WisdomGarden...
The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers to obtain certain specific files by modifying the URL.
NA - CVE-2024-6739 - The session cookie in MailGates and MailAudit...
The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote attackers to potentially steal the session cookie via XSS.
NA - CVE-2024-6745 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in code-projects Simple Ticket Booking 1.0. Affected is an unknown function of the file adminauthenticate.php of the component Login. The...
NA - CVE-2024-5402 - Unquoted Search Path or Element vulnerability...
Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who successfully exploited this vulnerability could gain elevated privileges by inserting an executable file...
NA - CVE-2024-6746 - A vulnerability classified as problematic was...
A vulnerability classified as problematic was found in NaiboWang EasySpider 0.6.2 on Windows. Affected by this vulnerability is an unknown functionality of the file...
NA - CVE-2024-6721 - Rejected reason: ** REJECT **
DO NOT USE THIS...
Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-5324. Reason: This record is a reservation duplicate of CVE-2024-5324. Notes: All CVE users should reference...
NA - CVE-2024-36455 - An improper input validation allows an...
An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.
NA - CVE-2024-36456 - This vulnerability allows an unauthenticated...
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.