CVE-2024-5706 – Hitachi Vantara Pentaho JNDI Identifier Injection Vulnerability
The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CWE-99) Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, do not restrict […]
CVE-2024-5705 – Hitachi Vantara Pentaho Business Analytics Server Authorization Bypass Vulnerability
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions. (CWE-863) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, have modules enabled by default […]
CVE-2024-37360 – Hitachi Vantara Pentaho Business Analytics Server Cross-site Scripting Vulnerability
Hitachi Vantara Pentaho Business Analytics Server – Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79) Hitachi Vantara Pentaho Business Analytics Server […]
CVE-2024-10339 – Apache Struts Remote Code Execution Vulnerability
The following table lists the changes that have been made to the CVE-2024-10339 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Rejected by [email protected] Feb. 19, 2025 Action Type […]
CVE-2024-37359 – Hitachi Vantara Pentaho Business Analytics Server Host Header Injection
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. (CWE-918) Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, do not validate the […]
CVE-2023-51305 – PHPJabbers Car Park Booking System Stored XSS
The following table lists the changes that have been made to the CVE-2023-51305 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 19, 2025 Action […]
CVE-2025-27090 – Sliver Teamserver Unauthenticated Reverse Port Forwarding Vulnerability
The following table lists the changes that have been made to the CVE-2025-27090 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 19, 2025 Action […]
CVE-2025-25196 – OpenFGA Authorization Bypass Vulnerability
The following table lists the changes that have been made to the CVE-2025-25196 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 19, 2025 Action […]
CVE-2023-51303 – PHPJabbers Event Ticketing System HTML Injection
The following table lists the changes that have been made to the CVE-2023-51303 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 19, 2025 Action […]
CVE-2023-51302 – PHPJabbers Hotel Booking System CSV Injection Remote Code Execution Vulnerability
The following table lists the changes that have been made to the CVE-2023-51302 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 19, 2025 Action […]