Currently trending CVE - Hype Score: 1 - A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx ...
Currently trending CVE - Hype Score: 1 - A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the ...
Currently trending CVE - Hype Score: 1 - A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of ...
Currently trending CVE - Hype Score: 1 - A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and ...
A vulnerability was found in SAP NetWeaver Application Server ABAP and ABAP Platform up to 796 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-32733. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability classified as problematic was found in SAP NetWeaver Application server for ABAP and ABAP Platform up to 796. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-34687. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in SAP UI5 754/755/756/757/758 and classified as problematic. Affected by this issue is some unknown functionality of the component PDFViewer. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-33007. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in SAP BusinessObjects Business Intelligence Platform 430/440. It has been classified as problematic. This affects an unknown part of the component Opendocument URL Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-28165. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in SAP S4 HANA. It has been declared as problematic. This vulnerability affects unknown code of the component Document Service Handler for DPS. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2024-33002. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability was found in SAP NetWeaver Application Server ABAP and ABAP Platform. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to unrestricted upload.
The identification of this vulnerability is CVE-2024-33006. The attack may be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability, which was classified as problematic, was found in Puneeth Reddy Online Shopping System Advanced. Affected is an unknown function of the component URL Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-3579. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Ultimate Blocks Plugin up to 3.1.6 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-3241. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
Microsoft has removed the 'BypassNRO.cmd' script from Windows 11 preview builds, which allowed users to bypass the requirement to use a Microsoft Account when installing the operating system. [...]
A vulnerability has been found in RSS Aggregator Plugin up to 4.23.8 on WordPress and classified as problematic. Affected by this vulnerability is an unknown functionality of the component GET Parameter Handler. The manipulation of the argument notice_id leads to cross site scripting.
This vulnerability is known as CVE-2024-4860. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Solidus up to 4.3.4 and classified as problematic. Affected by this issue is some unknown functionality of the component Order Tracking URL Handler. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-4859. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Siemens Parasolid and classified as critical. This issue affects some unknown processing of the component X_T File Handler. The manipulation leads to out-of-bounds read.
The identification of this vulnerability is CVE-2024-32636. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Siemens Parasolid. It has been classified as problematic. Affected is an unknown function of the component X_T File Handler. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2024-32637. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in Apache Airflow up to 2.9.0. This affects an unknown part of the component Task Instance Log Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-32077. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Siemens Tecnomatix Plant Simulation V2302. It has been classified as critical. This affects an unknown part of the component MODEL File Handler. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2024-32639. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.