NA - CVE-2024-45744 - TopQuadrant TopBraid EDG stores external...
TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords...
NA - CVE-2024-45745 - TopQuadrant TopBraid EDG before version 8.0.1...
TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute JavaScript to read local files or access URLs (XXE). Fixed in 8.0.1 (bug fix:...
NA - CVE-2024-47070 - authentik is an open-source identity provider....
authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header with an...
NA - CVE-2024-47077 - authentik is an open-source identity provider....
authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and used to impersonate the user...
NA - CVE-2024-6983 - mudler/localai version 2.17.1 is vulnerable to...
mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backend receives inputs not only from the configuration file but also from other...
NA - CVE-2024-22170 - Improper Restriction of Operations within the...
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects My Cloud: before...
NA - CVE-2024-38809 - Applications that parse ETags from "If-Match"...
Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of affected versions should upgrade to the corresponding fixed version. Users...
NA - CVE-2024-46366 - A Client-side Template Injection (CSTI)...
A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the...
NA - CVE-2024-46367 - A Stored Cross-Site Scripting (XSS)...
A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field....