In Mautic versions 1.0.2 to 4.4.11 and 5.0.0-alpha to 5.0.3 a high severity vulnerability CVE-2022-25776 was detected. This vulnerability allows attackers to access restricted areas of the application, potentially exposing sensitive data such as names, surnames, company names, and stage names. To fix this issue, users must upgrade to version 4.4.12 or 5.0.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2022-25776.
Read more Marketing AutomationIn Mautic versions 2.14.1 before 4.4.12, and 5.0.0 before 5.0.4 a high severity vulnerability CVE-2024-25775 was detected. This vulnerability allows attackers to redirect users to fake websites, where they could steal personal information or take over user accounts. To fix this issue, users should upgrade Mautic to versions 4.4.12, 5.0.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-25775.
Read more Marketing AutomationIn pgAdmin versions 8.11 and earlier a critical severity vulnerability in OAuth2 authentication CVE-2024-9014 was detected. This vulnerability allows attackers to potentially obtain the client ID and secret, leading to unauthorized access to user data. Currently there is no fix version for that issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-9014.
Read more DatabaseIn OpenShift environments using QEMU NBD Server versions a high severity vulnerability CVE-2024-7409 was detected. This vulnerability allows attackers to perform a denial of service (DoS) attack by exploiting improper synchronization during socket closure when a client keeps a socket open as the server is taken offline. Currently, there is no fix version for that issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-7409.
Read more Developer ToolsIn Grafana Plugin SDK versions before 0.249.0 a critical severity vulnerability CVE-2024-8986 was detected. This vulnerability allows attackers to access credentials if included in the repository URI, which becomes embedded in the final binary. To fix this issue, users must upgrade to version 0.250.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8986.
Read more Data AnalyticsIn Mautic versions 5.1.0 to 5.1.1 a medium severity vulnerability CVE-2024-47059 was detected. This vulnerability allows attackers to infer whether a username is valid based on differing error messages for incorrect usernames and weak passwords. To fix this issue, users must upgrade to version 5.1.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-47059.
Read more Marketing AutomationIn Mautic versions 1.0.0-beta4 to 4.4.11 and 5.0.0-alpha to 5.0.3 a medium severity vulnerability CVE-2022-25777 was detected. This vulnerability allows attackers to read system files and access internal addresses via a Server-Side Request Forgery (SSRF) flaw. To fix this issue, users must upgrade to version 4.4.12 or 5.0.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2022-25777.
Read more Marketing AutomationIn Couchbase versions 7.6.x prior to 7.6.2, 7.2.x prior to 7.2.6 a medium severity vulnerability CVE-2024-25673 was detected. This vulnerability allows attackers to perform HTTP Host header injection, potentially leading to redirecting requests to malicious sites or influencing server-side logic based on manipulated host headers. Such attacks could compromise the integrity and security of the server. To fix this issue, users should upgrade Couchbase to versions 7.6.2, 7.2.6, or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-25673.
Read more DatabaseIn Keycloak versions before version 24.0.8 a medium severity vulnerability CVE-2024-8883 was detected. This vulnerability allows attackers to redirect users to fake websites, potentially stealing sensitive information like login details and taking over user accounts. To fix this issue, users should upgrade Keycloak to version 25.0.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8883.
Read more Security