5.1

CVSS3.1

CVE-2024-6157 -

An attacker who successfully exploited these vulnerabilities could cause the robot to stop. A vulnerability exists in the PROFINET stack included in the RobotWare versions listed below.Β  This vulnerability arises under specific condition when specially crafted message is processed by the system…

πŸ“… Published: Oct. 10, 2024, 12:21 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-6530 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2. When adding a authorizing an application, it can be made to render as HTML under specific circumstances.

πŸ“… Published: Oct. 10, 2024, 12:02 p.m. πŸ”„ Last Modified: Oct. 16, 2024, 4:53 p.m.

8.7

CVSS4.0

CVE-2024-9784 - D-Link DIR-619L B1 formResetStatistic buffer overflow

A vulnerability classified as critical has been found in D-Link DIR-619L B1 2.06. Affected is the function formResetStatistic of the file /goform/formResetStatistic. The manipulation of the argument curTime leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been…

πŸ“… Published: Oct. 10, 2024, noon πŸ”„ Last Modified: Oct. 16, 2024, 2:12 p.m.

8.7

CVSS4.0

CVE-2024-9783 - D-Link DIR-619L B1 formLogDnsquery buffer overflow

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been rated as critical. This issue affects the function formLogDnsquery of the file /goform/formLogDnsquery. The manipulation of the argument curTime leads to buffer overflow. The attack may be initiated remotely. The exploit has been dis…

πŸ“… Published: Oct. 10, 2024, 11:31 a.m. πŸ”„ Last Modified: Oct. 16, 2024, 4:43 p.m.

8.7

CVSS4.0

CVE-2024-9782 - D-Link DIR-619L B1 formEasySetupWWConfig buffer overflow

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been declared as critical. This vulnerability affects the function formEasySetupWWConfig of the file /goform/formEasySetupWWConfig. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. T…

πŸ“… Published: Oct. 10, 2024, 11:31 a.m. πŸ”„ Last Modified: Oct. 16, 2024, 4:44 p.m.

5.4

CVSS3.1

CVE-2024-48902 -

In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API

πŸ“… Published: Oct. 10, 2024, 10:34 a.m. πŸ”„ Last Modified: Oct. 16, 2024, 4:57 p.m.

9.4

CVSS3.1

CVE-2024-9201 - SQL injection vulnerability in SEUR plugin

The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the β€˜id_order’ parameter of the β€˜/modules/seur/ajax/saveCodFee.php’ endpoint.

πŸ“… Published: Oct. 10, 2024, 10:25 a.m. πŸ”„ Last Modified: Oct. 16, 2024, 4:55 p.m.

8.2

CVSS3.1

CVE-2024-8977 - Server-Side Request Forgery (SSRF) in GitLab

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.

πŸ“… Published: Oct. 10, 2024, 10:02 a.m. πŸ”„ Last Modified: Oct. 16, 2024, 5:10 p.m.

3.7

CVSS3.1

CVE-2024-9596 - Inclusion of Sensitive Information in Source Code in GitLab

An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for an unauthenticated attacker to determine the GitLab version number for a GitLab instance.

πŸ“… Published: Oct. 10, 2024, 10:02 a.m. πŸ”„ Last Modified: Oct. 16, 2024, 5 p.m.

4.8

CVSS3.1

CVE-2024-45127 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser…

πŸ“… Published: Oct. 10, 2024, 9:58 a.m. πŸ”„ Last Modified: Oct. 11, 2024, 10:06 p.m.
Total resulsts: 349182
Page 8328 of 34,919
Β« previous page Β» next page
Filters