5.3

CVSS3.1

CVE-2024-42354 - Shopware vulnerable to Improper Access Control with ManyToMany associations in store-api

Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be marked as ApiAware in the EntityDefinition. So only ApiAware fields of the EntityDefinition will be encoded to the final JSON. Prior to versions 6.6.5.1 a…

πŸ“… Published: Aug. 8, 2024, 2:44 p.m. πŸ”„ Last Modified: Aug. 12, 2024, 3:49 p.m.

7.2

CVSS3.1

CVE-2024-41942 - JupyterHub has a privilege escalation vulnerability with the `admin:users` scope

JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the `admin:users` scope, they may escalate their own privileges by making themselves a full admin user. The impact is relatively small in that `admin:u…

πŸ“… Published: Aug. 8, 2024, 2:36 p.m. πŸ”„ Last Modified: Aug. 12, 2024, 3:53 p.m.

10

CVSS4.0

CVE-2024-3659 - Command injection in KAONΒ AR2140 routers

Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router.

πŸ“… Published: Aug. 8, 2024, 12:24 p.m. πŸ”„ Last Modified: Nov. 17, 2025, 5:15 p.m.

6.5

CVSS3.1

CVE-2024-2800 - Uncontrolled Resource Consumption in GitLab

ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of service via Regex backtracking.

πŸ“… Published: Aug. 8, 2024, 10:31 a.m. πŸ”„ Last Modified: Sept. 18, 2024, 12:42 p.m.

6.8

CVSS3.1

CVE-2024-3035 - Authorization Bypass Through User-Controlled Key in GitLab

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.

πŸ“… Published: Aug. 8, 2024, 10:31 a.m. πŸ”„ Last Modified: Sept. 17, 2024, 3:29 p.m.

4.3

CVSS3.1

CVE-2024-3114 - Uncontrolled Resource Consumption in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, with the processing logic for parsing invalid commits can lead to a regular expression DoS attack on the server.

πŸ“… Published: Aug. 8, 2024, 10:31 a.m. πŸ”„ Last Modified: Aug. 30, 2024, 2:15 p.m.

5.3

CVSS3.1

CVE-2024-3958 - Improper Control of Generation of Code ('Code Injection') in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cl…

πŸ“… Published: Aug. 8, 2024, 10:31 a.m. πŸ”„ Last Modified: Sept. 17, 2024, 3:31 p.m.

4.4

CVSS3.1

CVE-2024-4207 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specif…

πŸ“… Published: Aug. 8, 2024, 10:31 a.m. πŸ”„ Last Modified: Sept. 18, 2024, 12:41 p.m.

6.5

CVSS3.1

CVE-2024-5423 - Uncontrolled Resource Consumption in GitLab

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2 which allowed an attacker to cause resource exhaustion via banzai pipeline.

πŸ“… Published: Aug. 8, 2024, 10:31 a.m. πŸ”„ Last Modified: Aug. 29, 2024, 3:41 p.m.

4.9

CVSS3.1

CVE-2024-7554 - Exposure of Sensitive Information to an Unauthorized Actor in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions starting from 17.2 before 17.2.2. Under certain conditions, access tokens may have been logged when an API request was made in a specific…

πŸ“… Published: Aug. 8, 2024, 10:30 a.m. πŸ”„ Last Modified: Aug. 29, 2024, 3:42 p.m.
Total resulsts: 349182
Page 8915 of 34,919
Β« previous page Β» next page
Filters