NA - CVE-2024-9048 - A vulnerability was found in y_project RuoYi up...
A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is the function SysUserServiceImpl of the file...
NA - CVE-2024-42323 - SnakeYaml Deser Load Malicious xml rce...
SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat...
NA - CVE-2024-47210 - Gladys Assistant before 4.45.1 allows Privilege...
Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.
NA - CVE-2024-9075 - A vulnerability was found in Stirling-Tools...
A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnerability affects unknown code of the component Markdown-to-PDF. The...
NA - CVE-2024-45806 - Envoy is a cloud-native high-performance...
Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external clients to manipulate Envoy headers, potentially leading to unauthorized access...
NA - CVE-2024-45807 - Envoy is a cloud-native high-performance...
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2 codec, and there are potential bugs around stream management in the...
NA - CVE-2024-45808 - Envoy is a cloud-native high-performance...
Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to inject unexpected content into access logs. This...
NA - CVE-2024-45809 - Envoy is a cloud-native high-performance...
Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear route cache with remote JWKs. In the following case: 1. remote JWKs are used,...
NA - CVE-2024-45810 - Envoy is a cloud-native high-performance...
Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handling `sendLocalReply` under some circumstance, e.g., websocket upgrade, and...
NA - CVE-2024-46999 - Zitadel is an open source identity management...
Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correctly. Deactivated user grants were still provided in token, which could...