Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-10 CVE-2024-9788 SQL Injection vulnerability in Lylme Spage 1.9.5
A vulnerability has been found in LyLme_spage 1.9.5 and classified as critical.
network
low complexity
lylme CWE-89
7.2
2024-10-10 CVE-2024-9789 SQL Injection vulnerability in Lylme Spage 1.9.5
A vulnerability was found in LyLme_spage 1.9.5 and classified as critical.
network
low complexity
lylme CWE-89
7.2
2024-10-10 CVE-2024-9785 Classic Buffer Overflow vulnerability in Dlink Dir-619L Firmware 2.06B1
A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06.
network
low complexity
dlink CWE-120
8.8
2024-10-10 CVE-2024-9786 Classic Buffer Overflow vulnerability in Dlink Dir-619L Firmware 2.06B1
A vulnerability, which was classified as critical, has been found in D-Link DIR-619L B1 2.06.
network
low complexity
dlink CWE-120
8.8
2024-10-10 CVE-2024-6530 Cross-site Scripting vulnerability in Gitlab
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2.
network
low complexity
gitlab CWE-79
5.4
2024-10-10 CVE-2024-9782 Classic Buffer Overflow vulnerability in Dlink Dir-619L Firmware 2.06
A vulnerability was found in D-Link DIR-619L B1 2.06.
network
low complexity
dlink CWE-120
8.8
2024-10-10 CVE-2024-9783 Classic Buffer Overflow vulnerability in Dlink Dir-619L Firmware 2.06
A vulnerability was found in D-Link DIR-619L B1 2.06.
network
low complexity
dlink CWE-120
8.8
2024-10-10 CVE-2024-9784 Classic Buffer Overflow vulnerability in Dlink Dir-619L Firmware 2.06
A vulnerability classified as critical has been found in D-Link DIR-619L B1 2.06.
network
low complexity
dlink CWE-120
8.8
2024-10-10 CVE-2024-48902 Missing Authorization vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API
network
low complexity
jetbrains CWE-862
5.4
2024-10-10 CVE-2024-9201 SQL Injection vulnerability in Seur
The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the ‘id_order’ parameter of the ‘/modules/seur/ajax/saveCodFee.php’ endpoint.
network
low complexity
seur CWE-89
critical
9.8