Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-19 CVE-2024-47159 Incorrect Authorization vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project
network
low complexity
jetbrains CWE-863
4.3
2024-09-19 CVE-2024-47160 Incorrect Authorization vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
network
low complexity
jetbrains CWE-863
5.3
2024-09-19 CVE-2024-47162 Insufficiently Protected Credentials vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page
network
low complexity
jetbrains CWE-522
5.3
2024-09-19 CVE-2024-8963 Path Traversal vulnerability in Ivanti Endpoint Manager Cloud Services Appliance 4.6
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
network
low complexity
ivanti CWE-22
critical
9.1
2024-09-19 CVE-2024-31570 Out-of-bounds Write vulnerability in Freeimage Project Freeimage
libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file.
network
low complexity
freeimage-project CWE-787
critical
9.8
2024-09-19 CVE-2024-38016 Unspecified vulnerability in Microsoft products
Microsoft Office Visio Remote Code Execution Vulnerability
local
low complexity
microsoft
7.8
2024-09-19 CVE-2024-8651 Information Exposure Through Discrepancy vulnerability in Netcat Content Management System
A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists in the system, which could be a basis for further attacks. This issue affects NetCat CMS v.
network
low complexity
netcat CWE-203
5.3
2024-09-19 CVE-2024-8652 Cross-site Scripting vulnerability in Netcat Content Management System
A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site. This issue affects NetCat CMS v.
network
low complexity
netcat CWE-79
6.1
2024-09-19 CVE-2024-8653 Cross-site Scripting vulnerability in Netcat Content Management System
A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific paths on the site. This issue affects NetCat CMS v.
network
low complexity
netcat CWE-79
6.1
2024-09-19 CVE-2024-45752 Unspecified vulnerability in Pixlone Logiops
logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an unrestricted D-Bus service, including setting malicious keyboard macros.
local
low complexity
pixlone
7.3