Latest CVE Feed
-
8.7
HIGHCVE-2024-39515
An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause r... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
6.7
MEDIUMCVE-2024-38818
VMware NSX contains a local privilege escalation vulnerability. An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than previously assigned.... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
6.7
MEDIUMCVE-2024-38817
VMware NSX contains a command injection vulnerability. A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
4.3
MEDIUMCVE-2024-38815
VMware NSX contains a content spoofing vulnerability. An unauthenticated malicious actor may be able to craft a URL and redirect a victim to an attacker controlled domain leading to sensitive information disclosure.... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
5.7
MEDIUMCVE-2024-30118
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of improperly handling the request data.... Read more
Affected Products : connections- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
2.7
LOWCVE-2024-7038
An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides diff... Read more
Affected Products : open_webui- Published: Oct. 09, 2024
- Modified: Nov. 03, 2024
-
6.5
MEDIUMCVE-2024-47833
Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been addressed in rel... Read more
Affected Products : taipy- Published: Oct. 09, 2024
- Modified: Oct. 16, 2024
-
9.8
CRITICALCVE-2024-47832
ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass attacks. An attacker can carry out signature bypass if you have access to certain IDP-signed messages. The underlying mechanism exploits... Read more
Affected Products : ssoready- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
6.5
MEDIUMCVE-2024-47828
ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to delete objects (Playlist, smartlist etc.). Cross-Site Request Forgery (CSRF) is an attack that forces authenticated users to submit a req... Read more
Affected Products : ampache- Published: Oct. 09, 2024
- Modified: Oct. 17, 2024
-
6.4
MEDIUMCVE-2024-47816
ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the database to tell who made what requests. Therefore, if a user on another wiki happens to have the same actor ID as someone on the centr... Read more
Affected Products :- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
6.0
MEDIUMCVE-2024-47815
IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a variety of Cross-site Scripting issues, though all of them require elevated permissions. Some are available to anyone who has the `editinc... Read more
Affected Products :- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
6.0
MEDIUMCVE-2024-47812
ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface strings of a wiki (typically administrators and interface admins) can embed XSS payloads in the messages for dates, and thus XSS anyone w... Read more
Affected Products :- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
8.1
HIGHCVE-2024-3656
A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to perform actions reserved for administrators, potentially leading to data breaches or... Read more
- Published: Oct. 09, 2024
- Modified: Dec. 23, 2024
-
2.9
LOWCVE-2024-47813
Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s internal type registry was susceptible to double-unregistration bugs due to a race condition, leading to panics and potentially type regis... Read more
Affected Products : wasmtime- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
5.5
MEDIUMCVE-2024-47763
Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with stack traces can result in a runtime crash in certain WebAssembly modules. The runtime crash may be undefined behavior if Wasmtime was co... Read more
Affected Products : wasmtime- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
7.8
HIGHCVE-2024-9473
A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to NT AUTHORITY/SYSTEM through the use of the repair functionality offe... Read more
- Published: Oct. 09, 2024
- Modified: Nov. 21, 2024
-
5.1
MEDIUMCVE-2024-9471
A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use a compromised XML API key to perform actions as a higher privileged PAN-OS admin... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 15, 2024
-
5.3
MEDIUMCVE-2024-9470
A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data.... Read more
Affected Products : cortex_xsoar- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024
-
5.7
MEDIUMCVE-2024-9469
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR agent and t... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 15, 2024
-
8.2
HIGHCVE-2024-9468
A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data plane, resulting in a denial of service (DoS) condition. Repeated attempts to trigger this ... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 10, 2024