5.1
CVE-2024-6157 -
An attacker who successfully exploited these vulnerabilities could cause the robot to stop. A vulnerability exists in the PROFINET stack included in the RobotWare versions listed below.Β This vulnerability arises under specific condition when specially crafted message is processed by the systemβ¦
7.3
CVE-2024-6530 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2. When adding a authorizing an application, it can be made to render as HTML under specific circumstances.
8.7
CVE-2024-9784 - D-Link DIR-619L B1 formResetStatistic buffer overflow
A vulnerability classified as critical has been found in D-Link DIR-619L B1 2.06. Affected is the function formResetStatistic of the file /goform/formResetStatistic. The manipulation of the argument curTime leads to buffer overflow. It is possible to launch the attack remotely. The exploit has beenβ¦
8.7
CVE-2024-9783 - D-Link DIR-619L B1 formLogDnsquery buffer overflow
A vulnerability was found in D-Link DIR-619L B1 2.06. It has been rated as critical. This issue affects the function formLogDnsquery of the file /goform/formLogDnsquery. The manipulation of the argument curTime leads to buffer overflow. The attack may be initiated remotely. The exploit has been disβ¦
8.7
CVE-2024-9782 - D-Link DIR-619L B1 formEasySetupWWConfig buffer overflow
A vulnerability was found in D-Link DIR-619L B1 2.06. It has been declared as critical. This vulnerability affects the function formEasySetupWWConfig of the file /goform/formEasySetupWWConfig. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. Tβ¦
5.4
CVE-2024-48902 -
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API
9.4
CVE-2024-9201 - SQL injection vulnerability in SEUR plugin
The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the βid_orderβ parameter of the β/modules/seur/ajax/saveCodFee.phpβ endpoint.
8.2
CVE-2024-8977 - Server-Side Request Forgery (SSRF) in GitLab
An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.
3.7
CVE-2024-9596 - Inclusion of Sensitive Information in Source Code in GitLab
An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for an unauthenticated attacker to determine the GitLab version number for a GitLab instance.
4.8
CVE-2024-45127 - Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victimβs browserβ¦