Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2024-09-26 CVE-2024-4278 Unspecified vulnerability in Gitlab
An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1.
network
low complexity
gitlab
2.7
2024-09-26 CVE-2024-0133 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Nvidia Container Toolkit and Nvidia GPU Operator
NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system.
network
high complexity
nvidia CWE-367
3.4
2024-09-26 CVE-2023-52947 Missing Authentication for Critical Function vulnerability in Synology Active Backup for Business Agent
Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3-3101 allows local users to logout the client via unspecified vectors.
local
low complexity
synology CWE-306
3.3
2024-09-25 CVE-2024-8350 Missing Authorization vulnerability in Uncannyowl Uncanny Groups for Learndash
The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API endpoint in all versions up to, and including, 6.1.0.1.
network
low complexity
uncannyowl CWE-862
2.7
2024-09-23 CVE-2024-8263 Unspecified vulnerability in Github Enterprise Server
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags.
network
low complexity
github
2.7
2024-09-20 CVE-2024-8612 A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices.
local
low complexity
CWE-200
3.8
2024-09-18 CVE-2024-46794 Unspecified vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix data leak in mmio_read() The mmio_read() function makes a TDVMCALL to retrieve MMIO data for an address from the VMM. Sean noticed that mmio_read() unintentionally exposes the value of an initialized variable (val) on the stack to the VMM. This variable is only needed as an output value.
local
low complexity
linux
3.3
2024-09-17 CVE-2024-40791 Information Exposure Through Log Files vulnerability in Apple Macos
A privacy issue was addressed with improved private data redaction for log entries.
local
low complexity
apple CWE-532
3.3
2024-09-17 CVE-2024-40830 Unspecified vulnerability in Apple Iphone OS
This issue was addressed with improved data protection.
local
low complexity
apple
3.3
2024-09-17 CVE-2024-40838 Unspecified vulnerability in Apple Macos
A privacy issue was addressed by moving sensitive data to a protected location.
local
low complexity
apple
3.3