5

CVSS3.1

CVE-2024-39879 -

In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings

๐Ÿ“… Published: July 1, 2024, 5:07 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:28 a.m.

4.1

CVSS3.1

CVE-2024-39878 -

In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection

๐Ÿ“… Published: July 1, 2024, 5:07 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:28 a.m.

4.6

CVSS3.1

CVE-2024-36997 - Persistent Cross-site Scripting (XSS) in conf-web/settings REST endpoint

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin user could store and execute arbitrary JavaScript code in the browser context of another Splunk user through the conf-web/settings REST endpoint. This could potentially cause a pโ€ฆ

๐Ÿ“… Published: July 1, 2024, 4:57 p.m. ๐Ÿ”„ Last Modified: Feb. 28, 2025, 11:03 a.m.

5.4

CVSS3.1

CVE-2024-36993 - Persistent Cross-site Scripting (XSS) in Web Bulletin

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through a Splunk Web Bulletin Messages that could result in eโ€ฆ

๐Ÿ“… Published: July 1, 2024, 4:54 p.m. ๐Ÿ”„ Last Modified: Feb. 28, 2025, 11:03 a.m.

4.3

CVSS3.1

CVE-2024-36995 - Low-privileged user could create experimental items

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold the admin or power Splunk roles could create experimental items.

๐Ÿ“… Published: July 1, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: Feb. 28, 2025, 11:03 a.m.

7.5

CVSS3.1

CVE-2024-21586 - Junos OS: SRX Series and NFX Series: Specific valid traffic leads to a PFE crash

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series and NFX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If an affected device receives specific valid โ€ฆ

๐Ÿ“… Published: July 1, 2024, 4:34 p.m. ๐Ÿ”„ Last Modified: Jan. 22, 2026, 9:41 p.m.

7.5

CVSS3.1

CVE-2024-36982 - Denial of Service through null pointer reference in โ€œcluster/configโ€ REST endpoint

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer reference on the cluster/config REST endpoint, which could result in a crash of the Splunk daemon.

๐Ÿ“… Published: July 1, 2024, 4:31 p.m. ๐Ÿ”„ Last Modified: Feb. 28, 2025, 11:03 a.m.

7.5

CVSS3.1

CVE-2024-36991 - Path Traversal on the โ€œ/modules/messaging/โ€œ endpoint in Splunk Enterprise on Windows

In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.

๐Ÿ“… Published: July 1, 2024, 4:31 p.m. ๐Ÿ”„ Last Modified: Feb. 28, 2025, 11:03 a.m.

6.5

CVSS3.1

CVE-2024-36990 - Denial of Service (DoS) on the datamodel/web REST endpoint

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an authenticated, low-privileged user that does not hold the admin or power Splunk roles could send a specially crafted HTTP POST request to the datamodel/web REST endpoint in Splunk โ€ฆ

๐Ÿ“… Published: July 1, 2024, 4:30 p.m. ๐Ÿ”„ Last Modified: Feb. 28, 2025, 11:03 a.m.

8.8

CVSS3.1

CVE-2024-36985 - Remote Code Execution (RCE) through an external lookup due to โ€œcopybuckets.pyโ€œ script in the โ€œsplunโ€ฆ

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a Remote Code Execution through an external lookup that references the โ€œsplunk_archiverโ€œ application.

๐Ÿ“… Published: July 1, 2024, 4:30 p.m. ๐Ÿ”„ Last Modified: Feb. 28, 2025, 11:03 a.m.
Total resulsts: 347731
Page 9144 of 34,774
ยซ previous page ยป next page
Filters