Low - CVE-2021-20455 - IBM Cognos Controller 11.0.0 through 11.0.1 and...
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the...
Medium - CVE-2022-22363 - IBM Cognos Controller 11.0.0 through 11.0.1 and...
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the...
Medium - CVE-2024-25037 - IBM Cognos Controller 11.0.0 through 11.0.1 and...
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser.
Medium - CVE-2024-28778 - IBM Cognos Controller 11.0.0 through 11.0.1 and...
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code to private packages or...
High - CVE-2024-40702 - IBM Cognos Controller 11.0.0 through 11.0.1 and...
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow an unauthorized user to obtain valid tokens to gain access to protected resources due to improper certificate...
NA - CVE-2024-46242 - An issue in the validate_email function in...
An issue in the validate_email function in CTFd/utils/validators/__init__.py of CTFd 3.7.3 allows attackers to cause a Regular expression Denial of Service (ReDoS) via supplying a crafted string as...
NA - CVE-2024-46602 - An issue was discovered in Elspec G5 digital...
An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an attacker to cause a Denial of Service (DoS) via a...
NA - CVE-2024-46603 - An XML External Entity (XXE) vulnerability in...
An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML payload.
NA - CVE-2024-48245 - Vehicle Management System 1.0 is vulnerable to...
Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a vehicle or confirming a...