NA - CVE-2024-11668 - An issue has been discovered in GitLab CE/EE...
An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially bypass...
NA - CVE-2024-11669 - An issue was discovered in GitLab CE/EE...
An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized...
NA - CVE-2024-11828 - A denial of service (DoS) condition was...
A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. By leveraging this vulnerability an...
NA - CVE-2024-32965 - Lobe Chat is an open-source, AI chat framework....
Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests to cause SSRF without...
NA - CVE-2024-52008 - Fides is an open-source privacy engineering...
Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords by...
NA - CVE-2024-53267 - sigstore-java is a sigstore java client for...
sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a validly-signed but "mismatched" bundle is...
NA - CVE-2024-53619 - An authenticated arbitrary file upload...
An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.
NA - CVE-2024-53620 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the...
NA - CVE-2024-53844 - E.D.D.I (Enhanced Dialog Driven Interface) is a...
E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. A path traversal vulnerability exists in the backup export functionality of EDDI, as implemented in...
NA - CVE-2024-8114 - An issue has been discovered in GitLab CE/EE...
An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's...