Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-17 CVE-2024-8906 Unspecified vulnerability in Google Chrome
Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page.
network
low complexity
google
4.3
2024-09-17 CVE-2024-8907 Cross-site Scripting vulnerability in Google Chrome
Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (XSS) via a crafted set of UI gestures.
network
low complexity
google CWE-79
6.1
2024-09-17 CVE-2024-8908 Unspecified vulnerability in Google Chrome
Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page.
network
low complexity
google
4.3
2024-09-17 CVE-2024-8909 Unspecified vulnerability in Google Chrome
Inappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page.
network
low complexity
google
4.3
2024-09-17 CVE-2024-8957 OS Command Injection vulnerability in Ptzoptics Pt30X-Ndi-Xx-G2 Firmware and Pt30X-Sdi Firmware
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue.
network
low complexity
ptzoptics CWE-78
critical
9.8
2024-09-17 CVE-2024-45398 Unrestricted Upload of File with Dangerous Type vulnerability in Contao
Contao is an Open Source CMS.
network
low complexity
contao CWE-434
8.8
2024-09-17 CVE-2024-45604 Path Traversal vulnerability in Contao
Contao is an Open Source CMS.
network
low complexity
contao CWE-22
4.3
2024-09-17 CVE-2024-45605 Authorization Bypass Through User-Controlled Key vulnerability in Sentry 24.1.2
Sentry is a developer-first error tracking and performance monitoring platform.
network
low complexity
sentry CWE-639
4.3
2024-09-17 CVE-2024-45606 Authorization Bypass Through User-Controlled Key vulnerability in Sentry
Sentry is a developer-first error tracking and performance monitoring platform.
network
low complexity
sentry CWE-639
4.3
2024-09-17 CVE-2024-8951 Cross-site Scripting vulnerability in Oretnom23 Resort Reservation System 1.0
A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0.
network
low complexity
oretnom23 CWE-79
6.1