In GitLab CE/EE versions starting from 15.5 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1 a medium severity vulnerability CVE-2024-12431 was detected. This vulnerability allows attackers to change the status of issues in public projects on GitLab, even if they are not authorized. To fix this issue, users should upgrade GitLab CE/EE to versions 15.5, 17.6.3, 17.7.1. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-12431.
Read more Developer ToolsIn MonicaHQ version 4.1.2 a medium severity vulnerability CVE-2024-54999 was detected. This vulnerability allows attackers to exploit a Client-Side Injection via the `last_name` parameter in the General Information module. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-54999.
Read more CRMIn MonicaHQ version 4.1.1 a medium severity vulnerability CVE-2024-54997 was detected. This vulnerability allows attackers to exploit an authenticated Client-Side Injection via the `entry` text field at `/journal/entries/ID/edit`. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-54997.
Read more CRMIn GitLab CE/EE versions starting from 17.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3 and starting from 17.7 prior to 17.7.1 a medium severity vulnerability CVE-2025-0194 was detected. This vulnerability allows attackers to access tokens that may have been logged when API requests were made in a specific manner. To address this issue, users should upgrade GitLab CE/EE to versions 17.5.5, 17.6.3, or 17.7.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0194.
Read more Developer ToolsIn GitLab CE/EE versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1 a medium severity vulnerability CVE-2024-13041 was detected. This vulnerability allows attackers to bypass user access restrictions, potentially giving unauthorized users access to internal projects or groups in GitLab. To fix this issue, users should upgrade GitLab CE/EE to versions 17.5.5, 17.6.3, 17.7.1. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-13041.
Read more Developer ToolsIn Drupal Node Access Rebuild Progressive versions from 7.X-1.0 to before 7.X-1.2 a medium severity vulnerability CVE-2024-13249 was detected. This vulnerability allows attackers to influence target behavior via framing. To address this issue, users should upgrade Node Access Rebuild Progressive to version 7.X-1.2 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-13249.
Read more CMSIn Nagios XI version 2024R1.1.4 a medium severity vulnerability CVE-2024-42898 was detected. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-42898.
Read more MonitoringIn Vaultwarden versions before 1.32.5 a critical severity vulnerability CVE-2024-55225 was detected. This vulnerability allows attackers to impersonate users, including administrators, through a crafted authorization request. To address this issue, users should upgrade Vaultwarden to version 1.32.5 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-55225.
Read more SecurityIn PostgreSQL versions before 17.1, 16.5, 15.9, 14.14, 13.17 and 12.21 a high severity vulnerability CVE-2024-10979 was detected. This vulnerability allows an unprivileged database user to change sensitive process environment variables (e.g., PATH). This often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. To address this issue, users should upgrade PostgreSQL to versions 17.1, 16.5, 15.9, 14.14, 13.17 or 12.21. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-10979.
Read more Database