7.5
CVE-2024-45239 -
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a null eContent field. Fort dereferences the pointer without sanitizing it first. Because Fort is an RPKI Relying Partyโฆ
7.5
CVE-2024-45238 -
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a bit string that doesn't properly decode into a Subject Public Key. OpenSSL does not report this problem during parsโฆ
6.3
CVE-2024-38207 - Microsoft Edge (HTML-based) Memory Corruption Vulnerability
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
6.5
CVE-2024-45190 - Mage AI pipeline interaction request remote arbitrary file leak
Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "Pipeline Interaction" request
6.5
CVE-2024-45189 - Mage AI git content request remote arbitrary file leak
Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "Git Content" request
6.5
CVE-2024-45188 - Mage AI file content request remote arbitrary file leak
Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "File Content" request
7.1
CVE-2024-45187 - Mage AI allows deleted users to use the terminal server with admin access, leading to remote code eโฆ
Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute arbitrary code through the Mage AI terminal server
9.8
CVE-2024-7954 - SPIP porte_plume Plugin Arbitrary PHP Execution
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
4.8
CVE-2024-7427 - Potential Cross-Site Scripting vulnerability affect OpenTextโข Network Node Manager i (NNMi).
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenTextโข Network Node Manager i (NNMi) could allow Cross-Site Scripting (XSS).This issue affects Network Node Manager i (NNMi): 2022.11, 2023.05, 23.4, 24.2.
4.8
CVE-2024-7428 - Potential Open Redirect issues affect OpenTextโข Network Node Manager i (NNMi).
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in OpenTextโข Network Node Manager i (NNMi) allows URL Redirector Abuse.This issue affects Network Node Manager i (NNMi): 2022.11, 2023.05, 23.4, 24.2.