In WooCommerce in all versions up to and including 2.2.9 a medium severity vulnerability CVE-2024-10852 was detected. This vulnerability allows attackers with low-level access to export plugin settings, potentially exposing sensitive data. To fix this problem, users should upgrade to the latest version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10852.
Read more E-commerceIn WordPress in all versions up to and including 16.6 a high severity vulnerability CVE-2024-10800 was detected. This vulnerability allows attackers with low-level access to escalate their privileges to administrator, potentially compromising the site. To fix this problem, users should upgrade to version 16.7. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10800.
Read more CMSIn WordPress in all versions up to and including 16.6 a critical severity vulnerability CVE-2024-11150 was detected. This vulnerability allows attackers to delete arbitrary files on the server, potentially enabling remote code execution. To fix this problem, users should upgrade to version 16.7. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11150.
Read more CMSIn WooCommerce in all versions up to and including 2.2.9 a medium severity vulnerability CVE-2024-10854 was detected. This vulnerability allows attackers with low-level access to import and modify plugin settings, potentially compromising data. To fix this problem, users should upgrade to the latest version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10854.
Read more E-commerceIn GitLab CE/EE versions starting from 16.3 before 17.3.7, from 17.4 before 17.4.4, and from 17.5 before 17.5.2 a low severity vulnerability CVE-2024-9633 was detected. This vulnerability allows attackers to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks. Currently, there is no fixed version available for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-9633.
Read more Developer ToolsIn GitLab CE/EE versions starting from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2 a medium severity vulnerability CVE-2024-8648 was detected. This vulnerability allows attackers to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL. To fix this issue, users should upgrade GitLab CE/EE to versions 17.5.2, 17.4.4, and 17.3.7. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-8648.
Read more Developer ToolsIn GitLab CE/EE versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2 a medium severity vulnerability CVE-2024-7404 was detected. This vulnerability allows attackers to gain full API access as the victim via the Device OAuth flow. To fix this issue, users should upgrade GitLab CE/EE to versions 17.5.2, 17.4.4, and 17.3.7. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-7404.
Read more Developer ToolsIn Grafana OSS and Grafana Enterprise version 11.2.0 a medium severity vulnerability CVE-2024-9476 was detected. This vulnerability allows users to access other organization’s resources via the Cloud Migration Assistant. It affects instances using the Organizations feature for resource isolation. To address this issue, users are advised to upgrade to versions 11.2.3+security-01 or 11.3.0+security-01. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-9476.
Read more Data AnalyticsIn Harbor versions 1.0.0 and above, 1.10.12 and prior, 2.0.0 and above, 2.4.2 and prior, 2.5.0 and above, 2.5.1 and prior a high severity vulnerability CVE-2022-31671 was detected. This vulnerability allows malicious authenticated users to access or modify job execution logs in Harbor by sending requests with different job IDs, exposing all logs stored in the Harbor database due to improper permission validation. To fix this issue, users need to update Harbor to version 2.5.2 or above. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2022-31671.
Read more Developer Tools