Vulnerabilities
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-10-08 | CVE-2024-45231 | Unspecified vulnerability in Djangoproject Django An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. | 5.3 |
2024-10-08 | CVE-2024-47161 | Insufficiently Protected Credentials vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API | 6.5 |
2024-10-08 | CVE-2024-47948 | Path Traversal vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups | 7.5 |
2024-10-08 | CVE-2024-47949 | Path Traversal vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location | 7.5 |
2024-10-08 | CVE-2024-47950 | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings | 5.4 |
2024-10-08 | CVE-2024-47951 | Cross-site Scripting vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings | 5.4 |
2024-10-08 | CVE-2024-8215 | Cross-site Scripting vulnerability in Payara Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Code Inclusion.This issue affects Payara Server: from 5.20.0 before 5.68.0, from 6.0.0 before 6.19.0, from 6.2022.1 before 6.2024.10, from 4.1.2.191.1 before 4.1.2.191.51. | 8.4 |
2024-10-08 | CVE-2024-45330 | Unspecified vulnerability in Fortinet Fortianalyzer and Fortianalyzer Cloud A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted requests. | 7.2 |
2024-10-08 | CVE-2024-8431 | The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajaxGetGalleryJson() function in all versions up to, and including, 3.2.21. | 4.3 |
2024-10-08 | CVE-2024-8482 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.3.982 due to insufficient input sanitization and output escaping. | 6.4 |