CVE-2024-2878 – GitLab Branch Name Search Denial of Service Vulnerability
The following table lists the changes that have been made to the CVE-2024-2878 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 05, 2025 Action […]
New Veeam Flaw Allows Arbitrary Code Execution via Man-in-the-Middle Attack
New Veeam Flaw Allows Arbitrary Code Execution via Man-in-the-Middle Attack Vulnerability / Data Protection Veeam has released patches to address a critical security flaw impacting its Backup software that could allow an attacker to execute arbitrary code on susceptible syste … Read more Published Date: Feb 05, 2025 (2 hours, 44 minutes ago) Vulnerabilities has been mentioned […]
CVE-2024-52365 – IBM Cloud Pak for Business Automation Stored Cross-Site Scripting Vulnerability
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2024-52364 – IBM Cloud Pak for Business Automation Cross-Site Scripting
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2024-49348 – IBM Cloud Pak for Business Automation Comment Reassignment Privilege Escalation Vulnerability
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows restricting access to organizational data to valid contexts. The fact that tasks of type comment can be reassigned via API implicitly grants access to user queries in an unexpected context.
CVE-2024-3976 – GitLab Information Disclosure (Confidential Issue)
The following table lists the changes that have been made to the CVE-2024-3976 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 05, 2025 Action […]
CVE-2024-9631 – GitLab CE/EE Slow Diff View Vulnerability
The following table lists the changes that have been made to the CVE-2024-9631 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 05, 2025 Action […]
CVE-2024-5528 – GitLab Pages Subdomain Takeover Remote Code Execution Vulnerability
The following table lists the changes that have been made to the CVE-2024-5528 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 05, 2025 Action […]
CVE-2024-49352 – IBM Cognos Analytics XXE Injection Vulnerability
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
CISA Updates KEV Catalog with High-Severity Vulnerabilities—Patch Now!
CISA Updates KEV Catalog with High-Severity Vulnerabilities—Patch Now! The Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) Catalog by adding several new vulnerabilities that have been actively exploit … Read more Published Date: Feb 05, 2025 (2 hours, 1 minute ago) Vulnerabilities has been mentioned in this article. CVE-2024-21287 CVE-2024-45195 CVE-2024-29059 […]