Category: CVE

CVE-2024-49354 | IBM Concert Software 1.0.0/1.0.1/1.0.2 API Call exposure of sensitive information due to incompatible policies

A vulnerability was found in IBM Concert Software 1.0.0/1.0.1/1.0.2. It has been rated as problematic. This issue affects some unknown processing of the component API Call Handler. The manipulation leads to exposure of sensitive information due to incompatible policies. The identification of this vulnerability is CVE-2024-49354. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-51448 | IBM Robotic Process Automation up to 21.0.7.17/23.0.18 nssm.exe insecure inherited permissions

A vulnerability was found in IBM Robotic Process Automation up to 21.0.7.17/23.0.18. It has been declared as critical. This vulnerability affects unknown code of the file nssm.exe. The manipulation leads to insecure inherited permissions. This vulnerability was named CVE-2024-51448. It is possible to launch the attack on the local host. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-47106 | IBM Jazz for Service Management up to 1.1.3.22 file access

A vulnerability was found in IBM Jazz for Service Management up to 1.1.3.22. It has been classified as problematic. This affects an unknown part. The manipulation leads to files or directories accessible. This vulnerability is uniquely identified as CVE-2024-47106. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-49824 | IBM Robotic Process Automation up to 21.0.7.18/23.0.18 client-side enforcement of server-side security

A vulnerability was found in IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak up to 21.0.7.18/23.0.18 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to client-side enforcement of server-side security. This vulnerability is handled as CVE-2024-49824. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-47113 | IBM Voice Gateway up to 1.0.8 XML xml injection

A vulnerability has been found in IBM Voice Gateway up to 1.0.8 and classified as critical. Affected by this vulnerability is an unknown functionality of the component XML Handler. The manipulation leads to xml injection. This vulnerability is known as CVE-2024-47113. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-45662 | IBM Safer Payments up to 6.4.2.07/6.5.0.05/6.6.0.03 allocation of resources

A vulnerability, which was classified as critical, was found in IBM Safer Payments up to 6.4.2.07/6.5.0.05/6.6.0.03. Affected is an unknown function. The manipulation leads to allocation of resources. This vulnerability is traded as CVE-2024-45662. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-49338 | IBM App Connect Enterprise up to 12.0.7.0/13.0.1.0 improper management of sensitive trace data

A vulnerability, which was classified as problematic, has been found in IBM App Connect Enterprise up to 12.0.7.0/13.0.1.0. This issue affects some unknown processing. The manipulation leads to improper management of sensitive trace data. The identification of this vulnerability is CVE-2024-49338. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2025-0566 | Tenda AC15 15.13.07.13 /goform/SetDevNetName formSetDevNetName mac stack-based overflow

A vulnerability classified as critical has been found in Tenda AC15 15.13.07.13. This affects the function formSetDevNetName of the file /goform/SetDevNetName. The manipulation of the argument mac leads to stack-based buffer overflow. This vulnerability is uniquely identified as CVE-2025-0566. It is possible to initiate the attack remotely. Furthermore, there is an exploit...

Read More

CVE-2025-0565 | ZZCMS 2023 /index.php id sql injection

A vulnerability was found in ZZCMS 2023. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument id leads to sql injection. This vulnerability is handled as CVE-2025-0565. The attack may be launched remotely. Furthermore, there is an exploit...

Read More

CVE-2025-0564 | code-projects Fantasy-Cricket 1.0 /authenticate.php uname sql injection

A vulnerability was found in code-projects Fantasy-Cricket 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /authenticate.php. The manipulation of the argument uname leads to sql injection. This vulnerability is known as CVE-2025-0564. The attack can be launched remotely. Furthermore, there is an exploit...

Read More
Loading