Categoria: CVE

CVE-2025-0576 | Mobotix M15 4.3.4.83 p_qual cross site scripting

A vulnerability was found in Mobotix M15 4.3.4.83 and classified as problematic. This issue affects some unknown processing of the file /control/player?center&eventlist&pda&dummy_for_reload=1736177631&p_evt. The manipulation of the argument p_qual leads to cross site scripting. The identification of this vulnerability is CVE-2025-0576. The attack may be initiated remotely. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any way. It is recommended to apply restrictive firewalling. The vendor was contacted early about this disclosure but did not respond in any...

Per saperne di più

CVE-2025-0575 | Union Bank of India Vyom 8.0.34 on Android Rooting Detection protection mechanism

A vulnerability has been found in Union Bank of India Vyom 8.0.34 on Android and classified as problematic. This vulnerability affects unknown code of the component Rooting Detection. The manipulation leads to protection mechanism failure. This vulnerability was named CVE-2025-0575. The attack needs to be approached locally. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any way. The vendor was contacted early about this disclosure but did not respond in any...

Per saperne di più

CVE-2024-8722 | Soflyy WP All Import Pro Plugin up to 4.9.7 on WordPress cross site scripting

A vulnerability, which was classified as problematic, was found in Soflyy WP All Import Pro Plugin up to 4.9.7 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2024-8722. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-45654 | IBM Security ReaQta 3.12 reliance on untrusted inputs in a security decision

A vulnerability, which was classified as problematic, has been found in IBM Security ReaQta 3.12. Affected by this issue is some unknown functionality. The manipulation leads to reliance on untrusted inputs in a security decision. This vulnerability is handled as CVE-2024-45654. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-45653 | IBM Sterling Connect:Direct Web Services 6.0/6.1/6.2/6.3 insertion of sensitive information into sent data

A vulnerability classified as problematic was found in IBM Sterling Connect:Direct Web Services 6.0/6.1/6.2/6.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to insertion of sensitive information into sent data. This vulnerability is known as CVE-2024-45653. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-49354 | IBM Concert Software 1.0.0/1.0.1/1.0.2 API Call exposure of sensitive information due to incompatible policies

A vulnerability was found in IBM Concert Software 1.0.0/1.0.1/1.0.2. It has been rated as problematic. This issue affects some unknown processing of the component API Call Handler. The manipulation leads to exposure of sensitive information due to incompatible policies. The identification of this vulnerability is CVE-2024-49354. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-51448 | IBM Robotic Process Automation up to 21.0.7.17/23.0.18 nssm.exe insecure inherited permissions

A vulnerability was found in IBM Robotic Process Automation up to 21.0.7.17/23.0.18. It has been declared as critical. This vulnerability affects unknown code of the file nssm.exe. The manipulation leads to insecure inherited permissions. This vulnerability was named CVE-2024-51448. It is possible to launch the attack on the local host. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-47106 | IBM Jazz for Service Management up to 1.1.3.22 file access

A vulnerability was found in IBM Jazz for Service Management up to 1.1.3.22. It has been classified as problematic. This affects an unknown part. The manipulation leads to files or directories accessible. This vulnerability is uniquely identified as CVE-2024-47106. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-49824 | IBM Robotic Process Automation up to 21.0.7.18/23.0.18 client-side enforcement of server-side security

A vulnerability was found in IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak up to 21.0.7.18/23.0.18 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to client-side enforcement of server-side security. This vulnerability is handled as CVE-2024-49824. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-47113 | IBM Voice Gateway up to 1.0.8 XML xml injection

A vulnerability has been found in IBM Voice Gateway up to 1.0.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the component XML Handler. The manipulation leads to xml injection. This vulnerability is known as CVE-2024-47113. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-45662 | IBM Safer Payments up to 6.4.2.07/6.5.0.05/6.6.0.03 allocation of resources

A vulnerability, which was classified as critical, was found in IBM Safer Payments up to 6.4.2.07/6.5.0.05/6.6.0.03. Affected is an unknown function. The manipulation leads to allocation of resources. This vulnerability is traded as CVE-2024-45662. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più
Caricamento