Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-22 CVE-2024-43173 Unspecified vulnerability in IBM Concert 1.0.0/1.0.1
IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
network
high complexity
ibm
3.7
2024-10-22 CVE-2024-43177 Improper Certificate Validation vulnerability in IBM Concert 1.0.0/1.0.1
IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
network
low complexity
ibm CWE-295
critical
9.8
2024-10-22 CVE-2024-8980 Cross-Site Request Forgery (CSRF) vulnerability in Liferay Digital Experience Platform and Liferay Portal
The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack 102 and 6.2 GA through fix pack 173 does not sufficiently protect against Cross-Site Request Forgery (CSRF) attacks, which allows remote attackers to execute arbitrary Groovy script via a crafted URL or a XSS vulnerability.
network
low complexity
liferay CWE-352
6.1
2024-10-22 CVE-2024-10234 Cross-site Scripting vulnerability in Redhat products
A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system.
network
low complexity
redhat CWE-79
7.3
2024-10-22 CVE-2024-50312 Unspecified vulnerability in Redhat Openshift Container Platform 4.0
A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query.
network
low complexity
redhat
5.3
2024-10-22 CVE-2024-10189 Cross-site Scripting vulnerability in Jesweb Anchor Episodes Index
The Anchor Episodes Index (Spotify for Podcasters) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's anchor_episodes shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
jesweb CWE-79
5.4
2024-10-22 CVE-2024-9231 Cross-site Scripting vulnerability in Butlerblog Wp-Members
The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.9.5.
network
low complexity
butlerblog CWE-79
6.1
2024-10-22 CVE-2024-35308 Path Traversal vulnerability in Pandorafms Pandora FMS 742/746
A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3.
network
low complexity
pandorafms CWE-22
8.8
2024-10-22 CVE-2024-9987 SQL Injection vulnerability in Pandorafms Pandora FMS 742/746
A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv functionality. This issue affects Pandora FMS: from 700 through <777.3.
network
low complexity
pandorafms CWE-89
8.8
2024-10-22 CVE-2023-52918 NULL Pointer Dereference vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: media: pci: cx23885: check cx23885_vdev_init() return cx23885_vdev_init() can return a NULL pointer, but that pointer is used in the next line without a check. Add a NULL pointer check and go to the error unwind if it is NULL.
local
low complexity
linux CWE-476
5.5