NA - CVE-2024-25606 - XXE vulnerability in Liferay Portal 7.2.0...
XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before fix pack 20, and older unsupported...
NA - CVE-2023-49109 - Exposure of Remote Code Execution in Apache...
Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1,...
NA - CVE-2023-49250 - Because the HttpUtils class did not verify...
Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server. This issue...
NA - CVE-2023-50270 - Session Fixation Apache DolphinScheduler before...
Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which fixes this issue.
NA - CVE-2023-51770 - Arbitrary File Read Vulnerability in Apache...
Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1,...
NA - CVE-2024-25607 - The default password hashing algorithm...
The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, 7.2...
NA - CVE-2024-25608 - HtmlUtil.escapeRedirect in Liferay Portal 7.2.0...
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older...
NA - CVE-2024-25609 - HtmlUtil.escapeRedirect in Liferay Portal 7.2.0...
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack 15 through 18, and older...
NA - CVE-2023-7245 - The nodejs framework in OpenVPN Connect 3.0...
The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context...
High - CVE-2024-24793 - A use-after-free vulnerability exists in the...
A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature freeing of memory that...