7

CVSS3.1

CVE-2024-39708 -

An issue was discovered in the Agent in Delinea Privilege Manager (formerly Thycotic Privilege Manager) before 12.0.1096 on Windows. Sometimes, a non-administrator user can copy a crafted DLL file to a temporary directory (used by .NET Shadow Copies) such that privilege escalation can occur if the โ€ฆ

๐Ÿ“… Published: June 27, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.8

CVSS3.1

CVE-2024-39156 -

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=add.

๐Ÿ“… Published: June 27, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2025, 5:01 p.m.

6.8

CVSS3.1

CVE-2024-39155 -

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=add.

๐Ÿ“… Published: June 27, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2025, 5:01 p.m.

6.5

CVSS3.1

CVE-2024-1493 - Uncontrolled Resource Consumption in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, with the processing logic for generating link in dependency files can lead to a regular expression DoS attack on the server

๐Ÿ“… Published: June 26, 2024, 11:31 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 8:50 a.m.

5.3

CVSS3.1

CVE-2024-1816 - Uncontrolled Resource Consumption in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows for an attacker to cause a denial of service using a crafted OpenAPI file.

๐Ÿ“… Published: June 26, 2024, 11:31 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 8:51 a.m.

5.3

CVSS3.1

CVE-2024-2191 - Improper Access Control in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows merge request title to be visible publicly despite being set as project members only.

๐Ÿ“… Published: June 26, 2024, 11:31 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:09 a.m.

4.3

CVSS3.1

CVE-2024-3115 - Exposure of Sensitive Information to an Unauthorized Actor in GitLab

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to access issues and epics without having an SSO session using Duo Chat.

๐Ÿ“… Published: June 26, 2024, 11:31 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:28 a.m.

6.5

CVSS3.1

CVE-2024-3959 - Improper Authorization in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.

๐Ÿ“… Published: June 26, 2024, 11:31 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:30 a.m.

3.1

CVSS3.1

CVE-2024-4011 - Improper Access Control in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.

๐Ÿ“… Published: June 26, 2024, 11:31 p.m. ๐Ÿ”„ Last Modified: Jan. 9, 2025, 9:38 p.m.

6.5

CVSS3.1

CVE-2024-4557 - Uncontrolled Resource Consumption in GitLab

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1 which allowed an attacker to cause resource exhaustion via banzai pipeline.

๐Ÿ“… Published: June 26, 2024, 11:31 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:43 a.m.
Total resulsts: 349182
Page 9322 of 34,919
ยซ previous page ยป next page
Filters