Latest CVE Feed
-
9.8
CRITICALCVE-2024-8212
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. ... Read more
Affected Products : dns-320_firmware dnr-322l_firmware dns-320l_firmware dns-320l dns-120_firmware dns-120 dnr-202l_firmware dnr-202l dns-315l_firmware dns-315l +30 more products- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-8213
A vulnerability classified as critical has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and ... Read more
Affected Products : dns-320_firmware dnr-322l_firmware dns-320l_firmware dns-320l dns-120_firmware dns-120 dnr-202l_firmware dnr-202l dns-315l_firmware dns-315l +30 more products- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024
-
6.5
MEDIUMCVE-2024-3958
An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line ... Read more
Affected Products : gitlab- Published: Aug. 08, 2024
- Modified: Aug. 29, 2024
-
6.5
MEDIUMCVE-2024-7610
A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause catastrophic backtracking while parsin... Read more
Affected Products : gitlab- Published: Aug. 08, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-8214
A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1... Read more
Affected Products : dns-320_firmware dnr-322l_firmware dns-320l_firmware dns-320l dns-120_firmware dns-120 dnr-202l_firmware dnr-202l dns-315l_firmware dns-315l +30 more products- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024
-
6.5
MEDIUMCVE-2024-7554
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logge... Read more
Affected Products : gitlab- Published: Aug. 08, 2024
- Modified: Aug. 29, 2024
-
6.5
MEDIUMCVE-2024-5423
Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resourc... Read more
Affected Products : gitlab- Published: Aug. 08, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-8217
A vulnerability has been found in SourceCodester E-Commerce Website 1.0 and classified as critical. This vulnerability affects unknown code of the file /Admin/registration.php. The manipulation of the argument fname leads to sql injection. The attack can ... Read more
Affected Products : e-commerce_website- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-8218
A vulnerability was found in code-projects Online Quiz Site 1.0 and classified as critical. This issue affects some unknown processing of the file index.php. The manipulation of the argument loginid leads to sql injection. The attack may be initiated remo... Read more
Affected Products : online_quiz_site- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-8219
A vulnerability was found in code-projects Responsive Hotel Site 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument name/phone/email leads to sql injection. It is possible to la... Read more
- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-8221
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/categories/manage_category.php. The manipulation of the argument id leads to sql inj... Read more
- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024
-
9.1
CRITICALCVE-2024-42167
The function "generate_app_certificates" in controllers/saml2/saml2.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Command properly. This allows an authenticated user with permissions to create applications to execute comma... Read more
Affected Products : keyrock- Published: Aug. 12, 2024
- Modified: Aug. 29, 2024
-
9.1
CRITICALCVE-2024-42166
The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Command properly. This allows an authenticated user with permissions to create applications to execute commands... Read more
Affected Products : keyrock- Published: Aug. 12, 2024
- Modified: Aug. 29, 2024
-
5.4
MEDIUMCVE-2024-7852
A vulnerability was found in SourceCodester Yoga Class Registration System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/inquiries/view_inquiry.php. The manipulation of the argument message leads to cross... Read more
- Published: Aug. 16, 2024
- Modified: Aug. 29, 2024
-
8.8
HIGHCVE-2024-7853
A vulnerability was found in SourceCodester Yoga Class Registration System up to 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=categories/view_category. The manipulation of the argument id leads to sql i... Read more
- Published: Aug. 16, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-7851
A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vulnerability affects unknown code of the file /classes/Users.php?f=save of the component Add User Handler. The manipulation leads to impr... Read more
- Published: Aug. 16, 2024
- Modified: Aug. 29, 2024
-
6.3
MEDIUMCVE-2024-42165
Insufficiently random values for generating activation token in FIWARE Keyrock <= 8.4 allow attackers to activate accounts of any user by predicting the token for the activation link.... Read more
Affected Products : keyrock- Published: Aug. 12, 2024
- Modified: Aug. 29, 2024
-
4.3
MEDIUMCVE-2024-42164
Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two factor authorization of any user by predicting the token for the disable_2fa link.... Read more
Affected Products : keyrock- Published: Aug. 12, 2024
- Modified: Aug. 29, 2024
-
8.3
HIGHCVE-2024-42163
Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to take over the account of any user by predicting the token for the password reset link.... Read more
Affected Products : keyrock- Published: Aug. 12, 2024
- Modified: Aug. 29, 2024
-
9.8
CRITICALCVE-2024-8222
A vulnerability classified as critical has been found in SourceCodester Music Gallery Site 1.0. This affects an unknown part of the file /admin/?page=musics/manage_music. The manipulation of the argument id leads to sql injection. It is possible to initia... Read more
- Published: Aug. 27, 2024
- Modified: Aug. 29, 2024