3.1

CVSS3.1

CVE-2024-45843 - Weak SSRF Filtering

Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to possibly cause an SSRF if Mattermost was deployed in Oracle Cloud or Alibaba.

📅 Published: Sept. 26, 2024, 8:03 a.m. 🔄 Last Modified: Sept. 26, 2024, 6:42 p.m.

3.1

CVSS3.1

CVE-2024-47145 - Unauthorized access on archived channels via file links

Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.

📅 Published: Sept. 26, 2024, 8:01 a.m. 🔄 Last Modified: Sept. 26, 2024, 6:42 p.m.

7.5

CVSS3.1

CVE-2024-47197 - Maven Archetype Plugin: Maven Archetype integration-test may package local settings into the publis…

Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This issue affects Maven Archetype Plugin: from 3.2.1 before 3.3.0. Users are recommended to upgrade to version 3.3.0, which fixes the issue. Archetype i…

📅 Published: Sept. 26, 2024, 8:01 a.m. 🔄 Last Modified: March 17, 2025, 6:15 p.m.

6.4

CVSS3.1

CVE-2024-8861 - ProfileGrid – User Profiles, Groups and Communities <= 5.9.3.2 - Authenticated (Contributor+) Store…

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.9.3.2 due to incorrect use of the wp_kses_allowed_html function, which allows the 'onclick' attribute for certain HTML elements without s…

📅 Published: Sept. 26, 2024, 7:34 a.m. 🔄 Last Modified: April 8, 2026, 4:44 p.m.

5.5

CVSS3.1

CVE-2024-4278 - Incorrect Synchronization in GitLab

An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. A maintainer could obtain a Dependency Proxy password by editing a certain Dependency Proxy setting.

📅 Published: Sept. 26, 2024, 6:30 a.m. 🔄 Last Modified: Oct. 8, 2024, 7:51 p.m.

6.1

CVSS3.1

CVE-2024-6517 - Contact Form 7 Math Captcha <= 2.0.1 - Reflected XSS

The Contact Form 7 Math Captcha WordPress plugin through 2.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users.

📅 Published: Sept. 26, 2024, 6 a.m. 🔄 Last Modified: March 14, 2025, 4:15 p.m.

4.1

CVSS3.1

CVE-2024-0133 - nvidia-container-toolkit: Data tampering in NVIDIA Container Toolkit

NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to d…

📅 Published: Sept. 26, 2024, 5:21 a.m. 🔄 Last Modified: Oct. 2, 2024, 2:43 p.m.

9

CVSS3.1

CVE-2024-0132 - nvidia-container-toolkit: Time-of-check Time-of-use (TOCTOU) Race Condition in NVIDIA Container too…

NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of…

📅 Published: Sept. 26, 2024, 5:18 a.m. 🔄 Last Modified: Oct. 2, 2024, 2:45 p.m.

8.1

CVSS3.1

CVE-2024-7781 - Jupiter X Core <= 4.7.5 - Limited Unauthenticated Authentication Bypass to Account Takeover

The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper authentication via the Social Login widget. This makes it possible for unauthenticated attackers to log in as the first user to have logged in with a s…

📅 Published: Sept. 26, 2024, 4:29 a.m. 🔄 Last Modified: April 8, 2026, 5:32 p.m.

9.8

CVSS3.1

CVE-2024-7772 - Jupiter X Core <= 4.6.5 - Unauthenticated Arbitrary File Upload

The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function in all versions up to, and including, 4.6.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's serv…

📅 Published: Sept. 26, 2024, 4:29 a.m. 🔄 Last Modified: April 8, 2026, 4:55 p.m.
Total resulsts: 349182
Page 8468 of 34,919
« previous page » next page
Filters