5.3
CVE-2024-37380 -
A misconfiguration on UniFi U6+ Access Point could cause an incorrect VLAN traffic forwarding to APs meshed to UniFi U6+ Access Point. Affected Products: UniFi U6+ Access Point (Version 6.6.65 and earlier) Mitigation: Update your UniFi U6+ Access Point to Version 6.6.74 or later.
5.4
CVE-2024-41130 - llama.cpp null pointer dereference in gguf_init_from_file
llama.cpp provides LLM inference in C/C++. Prior to b3427, llama.cpp contains a null pointer dereference in gguf_init_from_file. This vulnerability is fixed in b3427.
6.5
CVE-2024-39688 - fishaudio/Bert-VITS2 Limited File Write in webui_preprocess.py generate_config function
Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is concatenated with other folders and used to open a new file in the generate_config function, which leads to a limited file write. The issue allows for writing /config/config.json file in arbitraβ¦
9.8
CVE-2024-39686 - fishaudio/Bert-VITS2 Command Injection in webui_preprocess.py bert_gen function
Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with subprocess.run(cmd, shell=True) in the bert_gen function, which leads to arbitrary command execution. This affects fishaudio/Bert-VITS2 2.3 and earlier.
9.8
CVE-2024-39685 - fishaudio/Bert-VITS2 Command Injection in webui_preprocess.py resample function
Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with subprocess.run(cmd, shell=True) in the resample function, which leads to arbitrary command execution. This affects fishaudio/Bert-VITS2 2.3 and earlier.
3.5
CVE-2024-41829 -
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
2.6
CVE-2024-41828 -
In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
7.4
CVE-2024-41827 -
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
3.5
CVE-2024-41826 -
In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
4.6
CVE-2024-41825 -
In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab