2

CVSS4.0

CVE-2024-52008 - Password Policy Bypass Vulnerability in Fides Webserver

Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords by bypassing client-side validation. While the UI enforces password complexity requirements, direct API calls…

πŸ“… Published: Nov. 26, 2024, 6:52 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 1:43 p.m.

5.5

CVSS3.1

CVE-2024-53267 - Vulnerability with bundle verification in sigstore-java

sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a validly-signed but "mismatched" bundle is presented as proof of inclusion into a transparency log. This bug impacts clients using any variation o…

πŸ“… Published: Nov. 26, 2024, 6:41 p.m. πŸ”„ Last Modified: Nov. 26, 2024, 7:46 p.m.

4.3

CVSS3.1

CVE-2024-11828 - Inefficient Algorithmic Complexity in GitLab

A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. By leveraging this vulnerability an attacker could create a DoS condition by sending crafted API calls. This was a regression of an earlie…

πŸ“… Published: Nov. 26, 2024, 6:41 p.m. πŸ”„ Last Modified: Dec. 12, 2024, 9:07 p.m.

6.5

CVSS3.1

CVE-2024-11669 - Incorrect Authorization in GitLab

An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized access to sensitive data due to overly broad application of token scopes.

πŸ“… Published: Nov. 26, 2024, 6:41 p.m. πŸ”„ Last Modified: Dec. 12, 2024, 9:11 p.m.

6.3

CVSS3.1

CVE-2024-53844 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in labsai/eddi

E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. A path traversal vulnerability exists in the backup export functionality of EDDI, as implemented in `RestExportService.java`. This vulnerability allows an attacker to access sensitive files on the server …

πŸ“… Published: Nov. 26, 2024, 6:37 p.m. πŸ”„ Last Modified: Nov. 26, 2024, 9:03 p.m.

8.2

CVSS3.1

CVE-2024-8114 - Missing Authorization in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.

πŸ“… Published: Nov. 26, 2024, 6:31 p.m. πŸ”„ Last Modified: Dec. 12, 2024, 8:54 p.m.

5.3

CVSS3.1

CVE-2024-8177 - Inefficient Algorithmic Complexity in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 prior to 17.6.1 which could cause Denial of Service via integrating a malicious harbor registry.

πŸ“… Published: Nov. 26, 2024, 6:31 p.m. πŸ”„ Last Modified: Dec. 13, 2024, 1:29 a.m.

6.5

CVSS3.1

CVE-2024-8237 - Inefficient Algorithmic Complexity in GitLab

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5, 17.5 prior to 17.5.3, and 17.6 prior to 17.6.1. An attacker could cause a denial of service with a crafted cargo.toml file.

πŸ“… Published: Nov. 26, 2024, 6:31 p.m. πŸ”„ Last Modified: Dec. 13, 2024, 1:32 a.m.

4.2

CVSS3.1

CVE-2024-11668 - Insufficient Session Expiration in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially bypass authentication controls, allowing unauthorized access to streaming results.

πŸ“… Published: Nov. 26, 2024, 6:30 p.m. πŸ”„ Last Modified: Dec. 12, 2024, 9:42 p.m.

8.1

CVSS3.1

CVE-2024-32965 - ssrf vulnerability in lobe-chat

Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests to cause SSRF without logging in, attack intranet services, and leak sensitive information. The jwt token header X-Lobe-Chat-A…

πŸ“… Published: Nov. 26, 2024, 6:25 p.m. πŸ”„ Last Modified: Sept. 23, 2025, 2:16 p.m.
Total resulsts: 343968
Page 7172 of 34,397
Β« previous page Β» next page
Filters