Category: CVE

CVE-2024-41151 | Apache HertzBeat up to 1.6.0 Notice Template deserialization

A vulnerability, which was classified as critical, was found in Apache HertzBeat up to 1.6.0. This affects an unknown part of the component Notice Template Handler. The manipulation leads to deserialization. This vulnerability is uniquely identified as CVE-2024-41151. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-45505 | Apache HertzBeat up to 1.6.0 command injection

A vulnerability, which was classified as critical, has been found in Apache HertzBeat up to 1.6.0. Affected by this issue is some unknown functionality. The manipulation leads to command injection. This vulnerability is handled as CVE-2024-45505. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-47208 | Apache OFBiz up to 18.12.16 Groovy Expression server-side request forgery

A vulnerability classified as critical was found in Apache OFBiz up to 18.12.16. Affected by this vulnerability is an unknown functionality of the component Groovy Expression Handler. The manipulation leads to server-side request forgery. This vulnerability is known as CVE-2024-47208. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-45791 | Apache Hertzbeat up to 1.6.0 Query String information disclosure

A vulnerability classified as problematic has been found in Apache Hertzbeat up to 1.6.0. Affected is an unknown function of the component Query String Handler. The manipulation leads to information disclosure. This vulnerability is traded as CVE-2024-45791. The attack needs to be approached within the local network. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2017-13314 | Google Android 7/8/8.1 NetworkManagementService.java setAllowOnlyVpnForUids permission

A vulnerability, which was classified as critical, was found in Google Android 7/8/8.1. Affected is the function setAllowOnlyVpnForUids of the file NetworkManagementService.java. The manipulation leads to permission issues. This vulnerability is traded as CVE-2017-13314. The attack needs to be approached locally. There is no exploit available. It is recommended to apply a patch to fix this...

Read More

CVE-2024-10883 | SimpleForm Plugin up to 2.2.0 on WordPress add_query_arg/remove_query_arg cross site scripting

A vulnerability, which was classified as problematic, has been found in SimpleForm Plugin up to 2.2.0 on WordPress. This issue affects the function add_query_arg/remove_query_arg. The manipulation leads to cross site scripting. The identification of this vulnerability is CVE-2024-10883. The attack may be initiated remotely. There is no exploit...

Read More
Loading