Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-17 CVE-2024-44198 Integer Overflow or Wraparound vulnerability in Apple products
An integer overflow was addressed through improved input validation.
local
low complexity
apple CWE-190
5.5
2024-09-17 CVE-2024-44202 Improper Authentication vulnerability in Apple Iphone OS
An authentication issue was addressed with improved state management.
network
low complexity
apple CWE-287
5.3
2024-09-16 CVE-2024-4283 Open Redirect vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2.
network
low complexity
gitlab CWE-601
6.1
2024-09-16 CVE-2024-6685 Unspecified vulnerability in Gitlab
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2, where group runners information was disclosed to unauthorised group members.
network
low complexity
gitlab
4.3
2024-09-16 CVE-2024-32034 Cross-site Scripting vulnerability in Decidim
decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations.
network
low complexity
decidim CWE-79
4.8
2024-09-16 CVE-2024-39910 Cross-site Scripting vulnerability in Decidim
decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations.
network
low complexity
decidim CWE-79
4.8
2024-09-16 CVE-2024-8661 Cross-site Scripting vulnerability in Concretecms Concrete CMS
Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block.
network
low complexity
concretecms CWE-79
4.8
2024-09-16 CVE-2024-28170 Unspecified vulnerability in Intel Raid web Console
Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel
5.5
2024-09-16 CVE-2024-32666 NULL Pointer Dereference vulnerability in Intel Raid web Console
NULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of service via local access.
local
low complexity
intel CWE-476
5.5
2024-09-16 CVE-2024-32940 Unspecified vulnerability in Intel Raid web Console
Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of service via adjacent access.
low complexity
intel
5.7