NA - CVE-2024-47070 - authentik is an open-source identity provider....
authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header with an...
NA - CVE-2024-47077 - authentik is an open-source identity provider....
authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user...
NA - CVE-2024-6983 - mudler/localai version 2.17.1 is vulnerable to...
mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backend receives inputs not only from the configuration file but also from other...
NA - CVE-2024-22170 - Improper Restriction of Operations within the...
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects My Cloud: before...
NA - CVE-2024-38809 - Applications that parse ETags from "If-Match"...
Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of affected versions should upgrade to the corresponding fixed version. Users...
NA - CVE-2024-46366 - A Client-side Template Injection (CSTI)...
A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the...
NA - CVE-2024-46367 - A Stored Cross-Site Scripting (XSS)...
A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field....