6.1

CVSS3.1

CVE-2024-8648 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL.

📅 Published: Nov. 14, 2024, 1:02 p.m. 🔄 Last Modified: Dec. 12, 2024, 9:45 p.m.

8.8

CVSS3.1

CVE-2024-10979 - PostgreSQL PL/Perl environment variable changes execute arbitrary code

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions…

📅 Published: Nov. 14, 2024, 1 p.m. 🔄 Last Modified: Nov. 3, 2025, 10:16 p.m.

4.2

CVSS3.1

CVE-2024-10978 - PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID

Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE, SET SESSION AUTHORIZATION, or an equivalent feature. The problem arises when an application query uses p…

📅 Published: Nov. 14, 2024, 1 p.m. 🔄 Last Modified: Nov. 3, 2025, 10:16 p.m.

3.1

CVSS3.1

CVE-2024-10977 - PostgreSQL libpq retains an error message from man-in-the-middle

Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes…

📅 Published: Nov. 14, 2024, 1 p.m. 🔄 Last Modified: Nov. 3, 2025, 10:16 p.m.

4.2

CVSS3.1

CVE-2024-10976 - PostgreSQL row security below e.g. subqueries disregards user ID changes

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invok…

📅 Published: Nov. 14, 2024, 1 p.m. 🔄 Last Modified: Nov. 3, 2025, 10:16 p.m.

5.3

CVSS4.0

CVE-2024-11207 - Apereo CAS login redirect

A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirect_uri leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to…

📅 Published: Nov. 14, 2024, 12:31 p.m. 🔄 Last Modified: Nov. 4, 2025, 5:57 p.m.

5.3

CVSS3.1

CVE-2024-45642 - IBM Security ReaQta information disclosure

IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

📅 Published: Nov. 14, 2024, 12:04 p.m. 🔄 Last Modified: Nov. 16, 2024, 12:13 a.m.

3.1

CVSS3.1

CVE-2024-45099 - IBM Security ReaQta cross-site scripting

IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

📅 Published: Nov. 14, 2024, 12:02 p.m. 🔄 Last Modified: Nov. 16, 2024, 12:11 a.m.

7.4

CVSS3.1

CVE-2022-31668 - User permission validation failure and disclosure of P2P preheat execution logs

Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id that belongs to a project that the currently authenticated user doesn't have access to, the attacker could modify p2p preheat policies configured in other…

📅 Published: Nov. 14, 2024, 11:56 a.m. 🔄 Last Modified: Nov. 19, 2024, 3:25 p.m.

6.4

CVSS3.1

CVE-2022-31667 - Harbor fails to validate the user permissions when updating a robot account

Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to.  By sending a request that attempts to update a robot account, and specifying a robot account id and robot account name that belongs to a differ…

📅 Published: Nov. 14, 2024, 11:50 a.m. 🔄 Last Modified: Nov. 19, 2024, 3:25 p.m.
Total resulsts: 343948
Page 7355 of 34,395
« previous page » next page
Filters