4.1
CVE-2024-7091 - Exposure of Sensitive Information to an Unauthorized Actor in GitLab
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where it was possible to disclose limited information of an exported group or project to another user.
5.3
CVE-2024-7081 - itsourcecode Tailoring Management System expcatadd.php sql injection
A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file expcatadd.php. The manipulation of the argument id/title leads to sql injection. The attack may be launched remotely. The exploiโฆ
6.8
CVE-2024-41136 - Authenticated Command Injection in HPE Aruba Networking EdgeConnect SD-WAN Command Line Interface
An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
7.2
CVE-2024-41135 - Authenticated Remote Code Execution in HPE Aruba Networking EdgeConnect SD-WAN Command Line Interfaโฆ
A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as rโฆ
7.2
CVE-2024-41134 - Authenticated Remote Code Execution in HPE Aruba Networking EdgeConnect SD-WAN Command Line Interfaโฆ
A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as rโฆ
7.2
CVE-2024-41133 - Authenticated Remote Code Execution in HPE Aruba Networking EdgeConnect SD-WAN Command Line Interfaโฆ
A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as rโฆ
6.9
CVE-2024-7080 - SourceCodester Insurance Management System direct request
A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /E-Insurance/. The manipulation leads to direct request. The attack can be launched remotely. The exploit has beenโฆ
7.2
CVE-2024-33519 - Authenticated Server-Side prototype pollution Leading to Information Disclosure
A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commaโฆ
4.3
CVE-2024-21684 -
There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 and 8.19.0 to 8.19.1 are affected by this vulnerability. It is patched in 8.9.13 and 8.19.2. This open redirect vulnerability, with a CVSS Score of 3โฆ
7.5
CVE-2024-41672 - DuckDB: sniff_csv provides filesystem access even when enable_external_access is disabled
DuckDB is a SQL database management system. In versions 1.0.0 and prior, content in filesystem is accessible for reading using `sniff_csv`, even with `enable_external_access=false`. This vulnerability provides an attacker with access to filesystem even when access is expected to be disabled and othโฆ