4.4

CVSS3.1

CVE-2024-4201 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTMLโ€ฆ

๐Ÿ“… Published: June 12, 2024, 11:01 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:42 a.m.

8.4

CVSS4.0

CVE-2024-3468 - Deserialization of Untrusted Data in AVEVA PI Web API

There is a vulnerability in AVEVA PI Web API that could allow malicious code to execute on the PI Web API environment under the privileges of an interactive user that was socially engineered to use API XML import functionality with content supplied by an attacker.

๐Ÿ“… Published: June 12, 2024, 9:04 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS4.0

CVE-2024-3467 - Deserialization of Untrusted Data in AVEVA PI Asset Framework Client

There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.

๐Ÿ“… Published: June 12, 2024, 9:04 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:29 a.m.

0.0

CVE-2024-5934 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

๐Ÿ“… Published: June 12, 2024, 8:10 p.m. ๐Ÿ”„ Last Modified: June 14, 2024, 4:15 p.m.

0.0

CVE-2024-5927 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: June 12, 2024, 7:52 p.m. ๐Ÿ”„ Last Modified: June 13, 2024, 11:15 a.m.

5.3

CVSS3.1

CVE-2023-29267 - IBM Db2 denial of service

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5is vulnerable to a denial of service, under specific configurations, as the server may crash when using a specially crafted SQL statement by an authenticated user. IBM X-Force ID: 287612.

๐Ÿ“… Published: June 12, 2024, 6:24 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 7:56 a.m.

6.5

CVSS3.1

CVE-2024-31881 - IBM Db2 denial of service

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server may crash when using a specially crafted query on certain columnar tables by an authenticated user. IBM X-Force ID: 287613.

๐Ÿ“… Published: June 12, 2024, 6:21 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 5:15 p.m.

5.3

CVSS3.1

CVE-2024-28762 - IBM Db2 denial of service

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 285246.

๐Ÿ“… Published: June 12, 2024, 5:54 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 5:15 p.m.

7.8

CVSS3.1

CVE-2024-0865 -

CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.

๐Ÿ“… Published: June 12, 2024, 5:23 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 8:47 a.m.

6.1

CVSS3.1

CVE-2024-5559 -

CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gaining full control of the relay when a specially crafted reset token is entered into the front panel of the device.

๐Ÿ“… Published: June 12, 2024, 5:18 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:47 a.m.
Total resulsts: 349182
Page 9480 of 34,919
ยซ previous page ยป next page
Filters