5.3

CVSS3.1

CVE-2024-38322 - IBM Storage Defender information disclosure

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 agent username and password error response discrepancy exposes product to brute force enumeration. IBM X-Force ID: 294869.

πŸ“… Published: June 28, 2024, 6:34 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:25 a.m.

6.5

CVSS3.1

CVE-2024-25031 - IBM Storage Defender information disclosure

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allow an attacker on the network to brute force account credentials. IBM X-Force ID: 281678.

πŸ“… Published: June 28, 2024, 6:32 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9 a.m.

5.9

CVSS3.1

CVE-2024-35116 - IBM MQ denial of service

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, and 9.3 CD is vulnerable to a denial of service attack caused by an error applying configuration changes. IBM X-Force ID: 290335.

πŸ“… Published: June 28, 2024, 6:20 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:19 a.m.

6.5

CVSS3.1

CVE-2024-35156 - IBM MQ information disclosure

IBM MQ 9.3 LTS and 9.3 CD could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 292766.

πŸ“… Published: June 28, 2024, 6:12 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:19 a.m.

7.4

CVSS3.1

CVE-2024-38514 - NextChat Server-Side Request Forgery (SSRF)

NextChat is a cross-platform ChatGPT/Gemini UI. There is a Server-Side Request Forgery (SSRF) vulnerability due to a lack of validation of the `endpoint` GET parameter on the WebDav API endpoint. This SSRF can be used to perform arbitrary HTTPS request from the vulnerable instance (MKCOL, PUT and G…

πŸ“… Published: June 28, 2024, 6:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2024-38371 - Insufficient access control for OAuth2 Device Code flow in authentik

authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially allow users without the correct authorization to get OAuth tokens for an application and access it. This issue has been patch…

πŸ“… Published: June 28, 2024, 5:58 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 4:01 p.m.

6.5

CVSS3.1

CVE-2024-35155 - IBM MQ information disclosure

IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 292765.

πŸ“… Published: June 28, 2024, 5:40 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:19 a.m.

7.5

CVSS3.1

CVE-2024-31912 - IBM MQ privilege escalation

IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations due to incorrect privilege assignment. IBM X-Force ID: 289894.

πŸ“… Published: June 28, 2024, 5:38 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:14 a.m.

5.9

CVSS3.1

CVE-2024-31919 - IBM MQ denial of service

IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service attack caused by an error processing messages when an API Exit using MQBUFMH is used. IBM X-Force ID: 290259.

πŸ“… Published: June 28, 2024, 5:34 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:14 a.m.

8.8

CVSS3.1

CVE-2024-37905 - Improper Access Control and Incorrect Authorization in github.com/goauthentik/authentik

authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit of the issue will result in a user gaining full admin access to the Authentik application, including r…

πŸ“… Published: June 28, 2024, 5:09 p.m. πŸ”„ Last Modified: Aug. 21, 2025, 4:14 p.m.
Total resulsts: 349182
Page 9305 of 34,919
Β« previous page Β» next page
Filters