Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-09-12 CVE-2024-8695 Unspecified vulnerability in Docker Desktop
A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.
network
low complexity
docker
critical
9.8
2024-09-12 CVE-2024-8696 Unspecified vulnerability in Docker Desktop
A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.
network
low complexity
docker
critical
9.8
2024-09-12 CVE-2024-2743 Incorrect Authorization vulnerability in Gitlab
An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables.
network
low complexity
gitlab CWE-863
critical
9.1
2024-09-12 CVE-2024-45823 Unspecified vulnerability in Rockwellautomation Factorytalk Batch View 2.01.00
CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product.
network
low complexity
rockwellautomation
critical
9.8
2024-09-12 CVE-2024-28990 Use of Hard-coded Credentials vulnerability in Solarwinds Access Rights Manager
SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability.
network
low complexity
solarwinds CWE-798
critical
9.8
2024-09-12 CVE-2024-45824 Command Injection vulnerability in Rockwellautomation Factorytalk View 12.0/13.0
CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products.
network
low complexity
rockwellautomation CWE-77
critical
9.8
2024-09-12 CVE-2021-22533 Information Exposure Through Log Files vulnerability in Microfocus Edirectory
Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.
network
low complexity
microfocus CWE-532
critical
9.1
2024-09-12 CVE-2021-38132 Server-Side Request Forgery (SSRF) vulnerability in Microfocus Edirectory
Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory.
network
low complexity
microfocus CWE-918
critical
9.8
2024-09-12 CVE-2024-29847 Deserialization of Untrusted Data vulnerability in Ivanti Endpoint Manager
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
network
low complexity
ivanti CWE-502
critical
9.8
2024-09-11 CVE-2024-8692 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tduckcloud Tduckpro
A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3.
network
low complexity
tduckcloud CWE-640
critical
9.8