A vulnerability, which was classified as critical, has been found in GitLab up to 15.8.4/15.9.3/15.10.0. This issue affects some unknown processing. The manipulation leads to permission issues.
The identification of this vulnerability is CVE-2023-1071. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in SalesAgility SuiteCRM up to 7.12.8. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to path traversal: '\..\filename'.
The identification of this vulnerability is CVE-2023-1034. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Red Hat Discovery Server 11/12. Affected is an unknown function of the component LDAP Handler. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2023-1055. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in MonicaHQ 4.0.0 and classified as critical. Affected by this issue is some unknown functionality of the component CSTI. The manipulation of the argument first_name leads to privilege escalation.
This vulnerability is handled as CVE-2023-1031. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Xuxueli xxl-job 2.2.0. Affected is an unknown function of the file xxl-job-admin/user/add. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2020-24922. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in Esoteric YamlBeans up to 1.15. Affected is an unknown function of the component YAML Document Handler. The manipulation leads to deserialization.
This vulnerability is traded as CVE-2023-24621. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability was found in margox braft-editor 2.3.8. It has been declared as problematic. This vulnerability affects unknown code of the component Embed Media Handler. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2021-27524. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in Linux Kernel up to 5.10.209/5.15.148/6.1.78/6.6.17/6.7.5. It has been classified as critical. Affected is the function memblock_alloc of the component powerpc. The manipulation leads to memory corruption.
This vulnerability is traded as CVE-2024-26712. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.1.78/6.6.17/6.7.5. Affected is an unknown function of the component KASAN Thread Handler. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2024-26710. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.6.17/6.7.5 and classified as problematic. This issue affects the function clk_init_data of the component ad4130. The manipulation leads to improper initialization.
The identification of this vulnerability is CVE-2024-26711. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in Linux Kernel up to 6.7.5. This vulnerability affects the function iommu_group_put of the component powerpc. The manipulation leads to memory leak.
This vulnerability was named CVE-2024-26709. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.6.17/6.7.5. It has been declared as problematic. This vulnerability affects the function subflow_state_change of the component mptcp. The manipulation leads to race condition.
This vulnerability was named CVE-2024-26708. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
Currently trending CVE - Hype Score: 19 - In the Linux kernel, the following vulnerability has been resolved:
net_sched: sch_sfq: move the limit validation
It is not sufficient to directly validate the limit on the data that
the user passes as it can be updated based on how the other parameters
are changed.
Move the ...
A vulnerability has been found in xwiki-platform up to 16.10.5/17.2.2 and classified as critical. This vulnerability affects unknown code of the file getdeleteddocuments.vm. The manipulation leads to sql injection.
This vulnerability was named CVE-2025-32429. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.10.209/5.15.148/6.1.78/6.6.17/6.7.5. It has been classified as problematic. This affects the function send_hsr_supervision_frame of the file net/hsr/hsr_device.c of the component hsr. The manipulation leads to allocation of resources.
This vulnerability is uniquely identified as CVE-2024-26707. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Linux Kernel up to 6.1.78/6.6.17/6.7.5. This affects the function emulate_ldd of the component parisc. The manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2024-26706. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.