Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-14 CVE-2024-45741 Cross-site Scripting vulnerability in Splunk and Splunk Cloud Platform
In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create a malicious payload through a custom configuration file that the "api.uri" parameter from the "/manager/search/apps/local" endpoint in Splunk Web calls.
network
low complexity
splunk CWE-79
5.4
2024-10-14 CVE-2023-50780 Unspecified vulnerability in Apache Activemq Artemis
Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint.
network
low complexity
apache
8.8
2024-10-14 CVE-2024-6762 Allocation of Resources Without Limits or Throttling vulnerability in Eclipse Jetty
Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.
network
low complexity
eclipse CWE-770
6.5
2024-10-14 CVE-2024-6763 Unspecified vulnerability in Eclipse Jetty
Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine .
network
low complexity
eclipse
5.3
2024-10-14 CVE-2024-8184 Allocation of Resources Without Limits or Throttling vulnerability in Eclipse Jetty
There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack.
network
low complexity
eclipse CWE-770
6.5
2024-10-14 CVE-2024-48251 SQL Injection vulnerability in Wavelog 1.8.5
Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
network
low complexity
wavelog CWE-89
critical
9.8
2024-10-14 CVE-2024-48257 SQL Injection vulnerability in Wavelog 1.8.5
Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.
network
low complexity
wavelog CWE-89
critical
9.8
2024-10-14 CVE-2024-48119 Cross-site Scripting vulnerability in Vtiger CRM 8.2.0
Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter.
network
low complexity
vtiger CWE-79
5.4
2024-10-14 CVE-2024-48120 Cross-site Scripting vulnerability in X2Engine X2Crm 8.5
X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module.
network
low complexity
x2engine CWE-79
5.4
2024-10-14 CVE-2024-48253 SQL Injection vulnerability in Magicbug Cloudlog 2.6.15
Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.
network
low complexity
magicbug CWE-89
critical
9.8