Latest CVE Feed
-
9.4
CVSS31CVE-2024-9201
The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the ‘id_order’ parameter of the ‘/modules/seur/ajax/saveCodFee.php’ endpoint.... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
5.4
CVSS31CVE-2024-48902
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
4.9
CVSS31CVE-2024-9623
An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows deploy keys to push to an archived repository.... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
3.7
CVSS31CVE-2024-9596
An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for an unauthenticated attacker to determine the GitLab version number for a Git... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
8.2
CVSS31CVE-2024-8977
An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF a... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
2.7
CVSS31CVE-2024-45149
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass secu... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
8.8
CVSS31CVE-2024-45148
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to gain unauth... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
2.7
CVSS31CVE-2024-45135
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An admin attacker could leverage this vulnerability to bypass security mea... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
2.7
CVSS31CVE-2024-45134
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a low impact on c... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
2.7
CVSS31CVE-2024-45133
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An admin attacker could leverage this vulnerability to have a low impact on c... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
6.5
CVSS31CVE-2024-45132
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security m... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
5.4
CVSS31CVE-2024-45131
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass secur... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
4.3
CVSS31CVE-2024-45130
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass secu... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
4.3
CVSS31CVE-2024-45129
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security ... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
5.4
CVSS31CVE-2024-45128
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass secur... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
4.8
CVSS31CVE-2024-45127
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. Malicious Java... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
4.3
CVSS31CVE-2024-45125
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could exploit this vulnerability to have a low i... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
5.3
CVSS31CVE-2024-45124
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures ... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
6.1
CVSS31CVE-2024-45123
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScrip... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024
-
4.3
CVSS31CVE-2024-45122
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass secu... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 10, 2024