Categoria: CVE

CVE-2024-48962 | Apache OFBiz up to 18.12.16 URL Parameter code injection

A vulnerability has been found in Apache OFBiz up to 18.12.16 and classified as critical. This vulnerability affects unknown code of the component URL Parameter Handler. The manipulation leads to code injection. This vulnerability was named CVE-2024-48962. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-41151 | Apache HertzBeat up to 1.6.0 Notice Template deserialization

A vulnerability, which was classified as critical, was found in Apache HertzBeat up to 1.6.0. This affects an unknown part of the component Notice Template Handler. The manipulation leads to deserialization. This vulnerability is uniquely identified as CVE-2024-41151. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-47208 | Apache OFBiz up to 18.12.16 Groovy Expression server-side request forgery

A vulnerability classified as critical was found in Apache OFBiz up to 18.12.16. Affected by this vulnerability is an unknown functionality of the component Groovy Expression Handler. The manipulation leads to server-side request forgery. This vulnerability is known as CVE-2024-47208. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2024-45791 | Apache Hertzbeat up to 1.6.0 Query String information disclosure

A vulnerability classified as problematic has been found in Apache Hertzbeat up to 1.6.0. Affected is an unknown function of the component Query String Handler. The manipulation leads to information disclosure. This vulnerability is traded as CVE-2024-45791. The attack needs to be approached within the local network. There is no exploit available. It is recommended to upgrade the affected...

Per saperne di più

CVE-2017-13314 | Google Android 7/8/8.1 NetworkManagementService.java setAllowOnlyVpnForUids permission

A vulnerability, which was classified as critical, was found in Google Android 7/8/8.1. Affected is the function setAllowOnlyVpnForUids of the file NetworkManagementService.java. The manipulation leads to permission issues. This vulnerability is traded as CVE-2017-13314. The attack needs to be approached locally. There is no exploit available. It is recommended to apply a patch to fix this...

Per saperne di più

CVE-2024-10883 | SimpleForm Plugin up to 2.2.0 on WordPress add_query_arg/remove_query_arg cross site scripting

A vulnerability, which was classified as problematic, has been found in SimpleForm Plugin up to 2.2.0 on WordPress. This issue affects the function add_query_arg/remove_query_arg. The manipulation leads to cross site scripting. The identification of this vulnerability is CVE-2024-10883. The attack may be initiated remotely. There is no exploit...

Per saperne di più
Caricamento