CVE-2024-28752 |
Description: A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.
EPSS Score: 0.06%
February 14th, 2025 (5 months ago)
|
CVE-2024-28746 |
Description: Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access.
Users of Apache Airflow are recommended to upgrade to version 2.8.3 or newer to mitigate the risk associated with this vulnerability
EPSS Score: 0.29%
February 14th, 2025 (5 months ago)
|
CVE-2024-28736 |
Description: An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page function.
EPSS Score: 0.04%
February 14th, 2025 (5 months ago)
|
CVE-2024-28285 |
Description: A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reside in the same system with a victim process to disclose information and escalate privileges.
EPSS Score: 0.04%
February 14th, 2025 (5 months ago)
|
CVE-2024-28279 |
Description: Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.
EPSS Score: 0.04%
February 14th, 2025 (5 months ago)
|
CVE-2024-28277 |
Description: In Sourcecodester School Task Manager v1.0, a vulnerability was identified within the subject_name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to manipulate the subject's name, potentially leading to the execution of malicious JavaScript payloads.
EPSS Score: 0.05%
February 14th, 2025 (5 months ago)
|
CVE-2024-28276 |
Description: Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=.
EPSS Score: 0.04%
February 14th, 2025 (5 months ago)
|
CVE-2024-28162 |
Description: In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections fails to take effect until Jenkins is restarted when switching from disabled validation to enabled validation.
EPSS Score: 0.04%
February 14th, 2025 (5 months ago)
|
CVE-2024-28161 |
Description: In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled by default.
EPSS Score: 0.04%
February 14th, 2025 (5 months ago)
|
CVE-2024-28160 |
Description: Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
EPSS Score: 0.04%
February 14th, 2025 (5 months ago)
|