|
251671
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows deploy keys…
|
CWE-863
Incorrect Authorization
|
CVE-2024-9623
|
2024-10-17 01:59 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251672
|
5.4 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API
|
CWE-862
Missing Authorization
|
CVE-2024-48902
|
2024-10-17 01:57 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251673
|
9.8 |
CRITICAL
Network
|
seur
|
seur
|
The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the ‘id_order’ parameter of the ‘/modules/seur/ajax/saveCodFee.php’ endpoint.
|
CWE-89
SQL Injection
|
CVE-2024-9201
|
2024-10-17 01:55 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251674
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2. When add…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6530
|
2024-10-17 01:53 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251675
|
6.7 |
MEDIUM
Local
|
openatom
|
openharmony
|
in OpenHarmony v4.1.0 allow a local attacker with high privileges arbitrary code execution in pre-installed apps through use after free.
|
CWE-416
Use After Free
|
CVE-2024-39831
|
2024-10-17 01:53 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251676
|
5.5 |
MEDIUM
Local
|
openatom
|
openharmony
|
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-39806
|
2024-10-17 01:49 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251677
|
8.8 |
HIGH
Network
|
dlink
|
dir-619l_firmware
|
A vulnerability was found in D-Link DIR-619L B1 2.06. It has been declared as critical. This vulnerability affects the function formEasySetupWWConfig of the file /goform/formEasySetupWWConfig. The ma…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-9782
|
2024-10-17 01:44 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251678
|
4.8 |
MEDIUM
Network
|
wikimedia
|
apex
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Apex skin allows Stored XSS.This issue affects Mediaw…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47840
|
2024-10-17 01:44 |
2024-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251679
|
8.8 |
HIGH
Network
|
dlink
|
dir-619l_firmware
|
A vulnerability was found in D-Link DIR-619L B1 2.06. It has been rated as critical. This issue affects the function formLogDnsquery of the file /goform/formLogDnsquery. The manipulation of the argum…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-9783
|
2024-10-17 01:43 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251680
|
6.1 |
MEDIUM
Network
|
mediawiki
|
cargo
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross-Site Scripting (XSS).This issue af…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47847
|
2024-10-17 01:42 |
2024-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|