CVE-2024-37082 : CLOUD FOUNDRY UP TO 0.206.0 HAPROXY AUTHENTICATION SPOOFING
Description Security check loophole in HAProxy release (in combination with routing release) in Cloud Foundry prior to v40.17.0 potentially allows
Description Security check loophole in HAProxy release (in combination with routing release) in Cloud Foundry prior to v40.17.0 potentially allows
Description A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management 1.0. This affects an
Description GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and
Description mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
Description Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card
Description Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause
Description In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint
Description httpTokenCacheKey uses path.Base to extract the expected HTTP-01 token value to lookup in the DirCache implementation. On Windows, path.Base
Description Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn’t sanitize
Description aimeos/ai-controller-frontend is the Aimeos frontend controller. Prior to versions 2024.04.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, aimeos/ai-controller-frontend doesn’t reset the
Description Pomerium is an identity and context-aware access proxy. Prior to version 0.26.1, the Pomerium user info page (at `/.pomerium`)
Description SkillTree is a micro-learning gamification platform. Prior to version 2.12.6, the endpoint `/admin/projects/{projectname}/skills/{skillname}/video` (and probably others) is open to
Description Improper Validation of Array Index vulnerability in Samsung Open Source Walrus Webassembly runtime engine allows a segmentation fault issue.
Description GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.6,
Description Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a
Description gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has
Description The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is
Description The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all
Description FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0 References
Description Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A
Description trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older pods which migrated from the
Description Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNMP Agent on Windows, Hitachi Job
Description Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.
Description A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability exists due to improper neutralization