Latest CVE Feed
-
4.9
MEDIUMCVE-2024-45739
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for local native authentication Splunk users. This exposure could happen when you configure the Splunk Enterprise AdminManager log channel at... Read more
Affected Products : splunk- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
4.9
MEDIUMCVE-2024-45738
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters to the `_internal` index. This exposure could happen if you configure the Splunk Enterprise `REST_Calls` log channel at the DEBUG loggi... Read more
Affected Products : splunk- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
4.3
MEDIUMCVE-2024-45737
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the "admin" or "power" Splunk roles could change the maintenance mode state of Ap... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
6.5
MEDIUMCVE-2024-45736
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a search query with... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
4.3
MEDIUMCVE-2024-45735
In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform versions below 3.4.259, 3.6.17, and 3.7.0, a low-privileged user that does not hold the "admin" or "power" Splunk roles can see App Key Value ... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
4.3
MEDIUMCVE-2024-45734
In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could view images on the machine that runs Splunk Enterprise by using the PDF export feature in Splunk classic dashboards. ... Read more
Affected Products : splunk- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
8.8
HIGHCVE-2024-45733
In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) due to an insecure session storage configuration.... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
7.1
HIGHCVE-2024-45732
In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles cou... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
8.0
HIGHCVE-2024-45731
In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows Syst... Read more
- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024
-
6.5
MEDIUMCVE-2024-8184
There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted requests, attackers can trigger OutofMemory errors ... Read more
Affected Products : jetty- Published: Oct. 14, 2024
- Modified: Nov. 08, 2024
-
5.3
MEDIUMCVE-2024-6763
Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI class does insufficient validation on the authority segment of a URI. However the behaviou... Read more
Affected Products : jetty- Published: Oct. 14, 2024
- Modified: Jul. 10, 2025
-
6.5
MEDIUMCVE-2024-6762
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.... Read more
Affected Products : jetty- Published: Oct. 14, 2024
- Modified: Nov. 08, 2024
-
9.8
CRITICALCVE-2024-48153
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig function.... Read more
- Published: Oct. 14, 2024
- Modified: Apr. 10, 2025
-
9.8
CRITICALCVE-2024-48150
D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.... Read more
- Published: Oct. 14, 2024
- Modified: May. 21, 2025
-
6.6
MEDIUMCVE-2024-41997
An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulnerability exists in the Docker integration functionality. An attacker can create a specially crafted hyperlink using the `warp://action/... Read more
Affected Products :- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
8.8
HIGHCVE-2023-50780
Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposur... Read more
Affected Products : activemq_artemis- Published: Oct. 14, 2024
- Modified: Mar. 19, 2025
-
7.5
HIGHCVE-2024-9823
There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using DosFilter. By repeatedly sending crafted requests, attackers can trigger OutofMemory... Read more
- Published: Oct. 14, 2024
- Modified: Jul. 30, 2025
-
7.3
HIGHCVE-2024-48259
Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.... Read more
Affected Products : cloudlog- Published: Oct. 14, 2024
- Modified: May. 02, 2025
-
9.8
CRITICALCVE-2024-48257
Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.... Read more
Affected Products : wavelog- Published: Oct. 14, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-48251
Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.... Read more
Affected Products : wavelog- Published: Oct. 14, 2024
- Modified: Oct. 17, 2024