Category: CVE

CVE-2024-11026 | Intelligent Apps Freenow App 12.10.0 on Android Keystore SSL.java DEFAULT_KEYSTORE_PASSWORD hard-coded password

A vulnerability was found in Intelligent Apps Freenow App 12.10.0 on Android. It has been rated as problematic. Affected by this issue is some unknown functionality of the file ch/qos/logback/core/net/ssl/SSL.java of the component Keystore Handler. The manipulation of the argument DEFAULT_KEYSTORE_PASSWORD with the input changeit leads to use of hard-coded password. This vulnerability is handled as CVE-2024-11026. The attack may be launched remotely. Furthermore, there is an exploit available. The vendor was contacted early about this disclosure but did not respond in any way. The vendor was contacted early about this disclosure but did not respond in any...

Read More

CVE-2024-50592 | Hasomed Elefant prior 1.4.2.1811 Update Service PostESUUpdate.exe toctou

A vulnerability was found in Hasomed Elefant. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file PostESUUpdate.exe of the component Update Service. The manipulation leads to time-of-check time-of-use. This vulnerability is known as CVE-2024-50592. The attack can only be done within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-50593 | Hasomed Elefant 1.4.2.1811 Hotline hard-coded credentials

A vulnerability was found in Hasomed Elefant 1.4.2.1811. It has been classified as critical. Affected is an unknown function of the component Hotline. The manipulation leads to hard-coded credentials. This vulnerability is traded as CVE-2024-50593. The attack needs to be approached within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-50591 | Hasomed Elefant prior 1.4.2.1811 Update Service command injection

A vulnerability was found in Hasomed Elefant and classified as critical. This issue affects some unknown processing of the component Update Service. The manipulation leads to command injection. The identification of this vulnerability is CVE-2024-50591. An attack has to be approached locally. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-50590 | Hasomed Elefant 1.4.2.1811/24.03.03 fbserver.exe default permission

A vulnerability has been found in Hasomed Elefant 1.4.2.1811/24.03.03 and classified as critical. This vulnerability affects unknown code of the file C:Elefant1Firebird_2binfbserver.exe. The manipulation leads to incorrect default permissions. This vulnerability was named CVE-2024-50590. The attack needs to be approached locally. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-50589 | Hasomed Elefant 1.4.2.1811/24.03.03 FHIR API missing authentication

A vulnerability, which was classified as critical, was found in Hasomed Elefant 1.4.2.1811/24.03.03. This affects an unknown part of the component FHIR API. The manipulation leads to missing authentication. This vulnerability is uniquely identified as CVE-2024-50589. The attack needs to be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-10839 | Zoho ManageEngine SharePoint Manager Plus up to 4503 Management Option xml external entity reference

A vulnerability, which was classified as critical, has been found in Zoho ManageEngine SharePoint Manager Plus up to 4503. Affected by this issue is some unknown functionality of the component Management Option. The manipulation leads to xml external entity reference. This vulnerability is handled as CVE-2024-10839. The attack may be launched remotely. There is no exploit...

Read More

CVE-2024-50588 | Hasomed Elefant prior 24.03.03 default password

A vulnerability classified as very critical was found in Hasomed Elefant. Affected by this vulnerability is an unknown functionality. The manipulation leads to use of default password. This vulnerability is known as CVE-2024-50588. The attack can only be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-24409 | Zoho ManageEngine ADManager Plus up to 7203 Modify Computers Option privileges management

A vulnerability classified as critical has been found in Zoho ManageEngine ADManager Plus up to 7203. Affected is an unknown function of the component Modify Computers Option. The manipulation leads to improper privilege management. This vulnerability is traded as CVE-2024-24409. It is possible to launch the attack remotely. There is no exploit...

Read More

CVE-2024-10187 | myCred Plugin up to 2.7.4 on WordPress Shortcode mycred_link cross site scripting

A vulnerability was found in myCred Plugin up to 2.7.4 on WordPress. It has been rated as problematic. This issue affects the function mycred_link of the component Shortcode Handler. The manipulation leads to cross site scripting. The identification of this vulnerability is CVE-2024-10187. The attack may be initiated remotely. There is no exploit...

Read More

CVE-2024-10325 | Elementor Header & Footer Builder Plugin up to 1.6.45 on WordPress SVG File Upload cross site scripting

A vulnerability was found in Elementor Header & Footer Builder Plugin up to 1.6.45 on WordPress. It has been declared as problematic. This vulnerability affects unknown code of the component SVG File Upload Handler. The manipulation leads to cross site scripting. This vulnerability was named CVE-2024-10325. The attack can be initiated remotely. There is no exploit...

Read More

CVE-2024-7982 | Registrations for the Events Calendar Plugin up to 2.12.3 on WordPress cross site scripting

A vulnerability was found in Registrations for the Events Calendar Plugin up to 2.12.3 on WordPress. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2024-7982. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More
Loading