|
312131
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
BT: HCI: adv_ext_report Improper discarding in adv_ext_report
|
CWE-787
Out-of-bounds Write
|
CVE-2024-6259
|
2024-09-19 10:33 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312132
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
BT: Classic: SDP OOB access in get_att_search_list
|
CWE-787
Out-of-bounds Write
|
CVE-2024-6137
|
2024-09-19 10:33 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312133
|
6.5 |
MEDIUM
Network
|
microfocus
|
edirectory
|
Possible
External Service Interaction attack
in eDirectory has been discovered in
OpenText™ eDirectory. This impact all version before 9.2.6.0000.
|
CWE-521
Weak Password Requirements
|
CVE-2021-38133
|
2024-09-19 06:05 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312134
|
9.8 |
CRITICAL
Network
|
microfocus
|
edirectory
|
Possible
External Service Interaction attack
in eDirectory has been discovered in
OpenText™ eDirectory. This impact all version before 9.2.6.0000.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-38132
|
2024-09-19 06:04 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312135
|
6.1 |
MEDIUM
Network
|
microfocus
|
edirectory
|
Possible Cross-Site Scripting (XSS) Vulnerability
in eDirectory has been discovered in
OpenText™ eDirectory 9.2.5.0000.
|
CWE-79
Cross-site Scripting
|
CVE-2021-38131
|
2024-09-19 06:00 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312136
|
6.1 |
MEDIUM
Network
|
i-doit
|
i-doit
|
Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticated user due to lack of proper sanitization of the …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8750
|
2024-09-19 05:38 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312137
|
5.3 |
MEDIUM
Network
|
ordat
|
ordat.erp
|
User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password func…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2024-34336
|
2024-09-19 05:32 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312138
|
6.1 |
MEDIUM
Network
|
ordat
|
ordat.erp
|
ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page.
|
CWE-79
Cross-site Scripting
|
CVE-2024-34335
|
2024-09-19 05:32 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312139
|
7.5 |
HIGH
Network
|
ordat
|
ordat.erp
|
ORDAT FOSS-Online before v2.24.01 was discovered to contain a SQL injection vulnerability via the forgot password function.
|
CWE-89
SQL Injection
|
CVE-2024-34334
|
2024-09-19 05:32 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312140
|
9.8 |
CRITICAL
Network
|
soplanning
|
soplanning
|
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publ…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-27115
|
2024-09-19 05:32 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|