Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-20 CVE-2024-45810 Unspecified vulnerability in Envoyproxy Envoy
Envoy is a cloud-native high-performance edge/middle/service proxy.
network
low complexity
envoyproxy
7.5
2024-09-20 CVE-2024-46999 Unspecified vulnerability in Zitadel
Zitadel is an open source identity management platform.
network
low complexity
zitadel
6.5
2024-09-20 CVE-2024-47000 Unspecified vulnerability in Zitadel
Zitadel is an open source identity management platform.
network
low complexity
zitadel
7.5
2024-09-20 CVE-2024-47060 Incorrect Authorization vulnerability in Zitadel
Zitadel is an open source identity management platform.
network
low complexity
zitadel CWE-863
6.5
2024-09-20 CVE-2024-9009 SQL Injection vulnerability in Fabianros Online Quiz Site 1.0
A vulnerability, which was classified as critical, has been found in code-projects Online Quiz Site 1.0.
network
low complexity
fabianros CWE-89
critical
9.8
2024-09-19 CVE-2023-27584 Use of Hard-coded Credentials vulnerability in D7Y Dragonfly
Dragonfly is an open source P2P-based file distribution and image acceleration system.
network
low complexity
d7y CWE-798
critical
9.8
2024-09-19 CVE-2024-45410 Insufficient Verification of Data Authenticity vulnerability in Traefik
Traefik is a golang, Cloud Native Application Proxy.
network
low complexity
traefik CWE-345
7.5
2024-09-19 CVE-2024-45614 HTTP Request Smuggling vulnerability in Puma
Puma is a Ruby/Rack web server built for parallelism.
network
high complexity
puma CWE-444
5.4
2024-09-19 CVE-2024-46983 Unspecified vulnerability in Antfin Sofa-Hessian
sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd.
network
low complexity
antfin
critical
9.8
2024-09-19 CVE-2024-46984 XXE vulnerability in Gematik Reference Validator
The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperability standards.
network
low complexity
gematik CWE-611
critical
9.8