High - CVE-2024-39516 - An Out-of-Bounds Read vulnerability in
the...
An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a...
High - CVE-2024-39525 - An Improper Handling of Exceptional Conditions...
An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker...
NA - CVE-2024-7037 - In version v0.3.8 of open-webui/open-webui, the...
In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized file.filename concatenation with CACHE_DIR. This...
NA - CVE-2024-7041 - An Insecure Direct Object Reference (IDOR)...
An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint...
NA - CVE-2024-48933 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a username if userControl has been...
NA - CVE-2024-8264 - Fortra's Robot Schedule Enterprise Agent...
Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.
NA - CVE-2024-37179 - SAP BusinessObjects Business Intelligence...
SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine...