Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-26 CVE-2024-11744 SQL Injection vulnerability in 1000Projects Portfolio Management System MCA 1.0
A vulnerability has been found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical.
network
low complexity
1000projects CWE-89
critical
9.8
2024-11-26 CVE-2024-11745 Out-of-bounds Write vulnerability in Tenda AC8 Firmware 16.03.34.09
A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical.
network
low complexity
tenda CWE-787
critical
9.8
2024-11-26 CVE-2024-10240 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions starting from 17.5 before 17.5.2 in which an unauthenticated user may be able to read some information about an MR in a private project, under certain circumstances.
network
low complexity
gitlab
5.3
2024-11-26 CVE-2024-11742 Unspecified vulnerability in Mayurik Best House Rental Management System 1.0
A vulnerability, which was classified as problematic, has been found in SourceCodester Best House Rental Management System 1.0.
network
low complexity
mayurik
5.4
2024-11-26 CVE-2024-11743 Cross-Site Request Forgery (CSRF) vulnerability in Mayurik Best House Rental Management System 1.0
A vulnerability, which was classified as problematic, was found in SourceCodester Best House Rental Management System 1.0.
network
low complexity
mayurik CWE-352
4.3
2024-11-26 CVE-2024-49035 Unspecified vulnerability in Microsoft Partner Center
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.
network
low complexity
microsoft
critical
9.8
2024-11-26 CVE-2024-49038 Unspecified vulnerability in Microsoft Copilot Studio
Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.
network
low complexity
microsoft
critical
9.6
2024-11-26 CVE-2024-49052 Unspecified vulnerability in Microsoft Azure Functions
Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.
network
low complexity
microsoft
critical
9.8
2024-11-26 CVE-2024-11668 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1.
network
low complexity
gitlab
5.3
2024-11-26 CVE-2024-11669 Unspecified vulnerability in Gitlab
An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1.
network
low complexity
gitlab
7.5