9.3
CVE-2024-39671 -
Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
5.5
CVE-2023-7271 -
Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability.
6.2
CVE-2024-39670 -
Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability.
6.2
CVE-2024-39674 -
Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.
6.8
CVE-2024-39673 -
Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
8.8
CVE-2024-6589 - LearnPress <= 4.2.6.8.2 - Authenticated (Contributor+) Local File Inclusion
The LearnPress β WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.6.8.2 via the 'render_content_block_template' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include β¦
9.8
CVE-2024-37084 - CVE-2024-37084: Remote code execution in Spring Cloud Data Flow
In Spring Cloud Data Flow versions prior to 2.11.4,Β Β a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromising the server
7.7
CVE-2024-3056 - Podman: kernel: containers in shared ipc namespace are vulnerable to denial of service attack
A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The malicious container will continue to exhaust resources untiβ¦
6.5
CVE-2024-6972 -
In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text.
2.2
CVE-2024-4811 -
In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.