Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.4

    CVSS31
    CVE-2024-9201

    The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the ‘id_order’ parameter of the ‘/modules/seur/ajax/saveCodFee.php’ endpoint.... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 5.4

    CVSS31
    CVE-2024-48902

    In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 4.9

    CVSS31
    CVE-2024-9623

    An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows deploy keys to push to an archived repository.... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 3.7

    CVSS31
    CVE-2024-9596

    An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for an unauthenticated attacker to determine the GitLab version number for a Git... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 8.2

    CVSS31
    CVE-2024-8977

    An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF a... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 2.7

    CVSS31
    CVE-2024-45149

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass secu... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 8.8

    CVSS31
    CVE-2024-45148

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to gain unauth... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 2.7

    CVSS31
    CVE-2024-45135

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An admin attacker could leverage this vulnerability to bypass security mea... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 2.7

    CVSS31
    CVE-2024-45134

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a low impact on c... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 2.7

    CVSS31
    CVE-2024-45133

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a low impact on c... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 6.5

    CVSS31
    CVE-2024-45132

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security m... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 5.4

    CVSS31
    CVE-2024-45131

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass secur... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 4.3

    CVSS31
    CVE-2024-45130

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass secu... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 4.3

    CVSS31
    CVE-2024-45129

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security ... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 5.4

    CVSS31
    CVE-2024-45128

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass secur... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 4.8

    CVSS31
    CVE-2024-45127

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. Malicious Java... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 4.3

    CVSS31
    CVE-2024-45125

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to have a low i... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 5.3

    CVSS31
    CVE-2024-45124

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures ... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 6.1

    CVSS31
    CVE-2024-45123

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScrip... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
  • 4.3

    CVSS31
    CVE-2024-45122

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass secu... Read more

    Affected Products :
    • Published: Oct. 10, 2024
    • Modified: Oct. 10, 2024
Showing 20 of 354 Results