CVE-2024-5005 Incorrect Provision of Specified Functionality in GitLab

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 1 ...

Continue Reading
CVE-2024-39534 Junos OS Evolved: Connections to the network and broadcast address accepted

An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker to create sessions or send traffic ...

Continue Reading
CVE-2024-6985 Path Traversal in api open_personality_folder in parisneo/lollms-webui

A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnerability allows an attacker to read any folder in the personality_folder on the vi ...

Continue Reading
Lord of Large Language Models (LoLLMs) path traversal vulnerability in the api open_personality_folder endpoint

A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms. This vulnerability allows an attacker to read any folder in the personality_folder on the victim&# ...

Continue Reading
Extract has insufficient checks allowing attacker to create symlinks outside the extraction directory.

Impact A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. Patches Please use version 4.0.0 or later github.com/codeclysm/extract/v4. Any p ...

Continue Reading
Extract has insufficient checks allowing attacker to create symlinks outside the extraction directory.

Impact A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. Patches Please use version 4.0.0 or later github.com/codeclysm/extract/v4. Any p ...

Continue Reading
JetBrains TeamCity < 2024.7.3 Multiple Vulnerabilities

The version of JetBrains TeamCity installed on the remote host is prior to 2024.7.3. It is, therefore, affected by multiple vulnerabilities: In JetBrains TeamCity before 2024.07.3 password could be ...

Continue Reading
CVE-2024-39534

An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker to create sessions or send traffic ...

Continue Reading

Back to Main

Subscribe for the latest news: