In Magento versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier a critical severity vulnerability CVE-2024-34107 was detected. This vulnerability relates to improper access control and allows attackers to bypass security measures and view minor unauthorized information. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34107.
Read more E-commerceIn MongoDB Server versions 5.0 to 5.0.27, 6.0 to 6.0.16, 7.0 to 7.0.12, 7.3 to 7.3.3, MongoDB C Driver versions to 1.26.2, and MongoDB PHP Driver versions to 1.18.1 a high severity vulnerability CVE-2024-7553 was detected. This vulnerability allows local privilege escalation on Windows by improperly validating files from untrusted directories. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-7553.
In Django versions 5.0 before 5.0.8, 4.2 before 4.2.15 a critical severity vulnerability CVE-2024-42005 was detected. This vulnerability allows an attacker to inject malicious SQL through specially crafted input, which can compromise database security. To address this issue users should upgrade Django to versions 5.0.8 or 4.2.15. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-42005.
Read more Application DevelopmentIn Magento Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier a high severity Server-Side Request Forgery (SSRF) vulnerability CVE-2024-34111 was detected. This vulnerability allows attackers to force the application to make arbitrary requests, potentially leading to arbitrary file system reads. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34111.
Read more E-commerceIn Magento Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier a high severity vulnerability CVE-2024-34108 was detected. This improper input validation vulnerability allows attackers to execute arbitrary code within the context of the current user. Although no user interaction is required for exploitation, admin privileges are needed, and the scope of the attack is changed. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-34108.
Read more E-commerceIn Gitea version 1.22.0 a high severity vulnerability CVE-2024-6886 was detected. This vulnerability allows attackers to add harmful scripts to the website, which other users might see, leading to stolen data or hijacked accounts. To fix this problem, users should upgrade Gitea to version 1.23.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-6886.
Read more Developer ToolsIn Rocket.Chat versions prior to 6.10.1 a high severity vulnerability CVE-2024-39713 was detected. This vulnerability allows attackers to make the server send requests to unintended locations, potentially accessing or manipulating private information. To fix this problem, users should upgrade Rocket.Chat to version 6.10.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-37313.
Read more CommunicationIn OpenStack versions 16.1/16.2/17.0 a high severity vulnerability CVE-2024-7319 was detected. This vulnerability allows the disclosure of sensitive information through the OpenStack stack abandon command. To fix this issue, users should upgrade to version 22.0.2. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-7319.
Read more Cloud ComputingIn OpenShift versions using Podman a medium severity vulnerability CVE-2024-3056 was detected. This vulnerability allows an attacker to create a container that uses up memory and IPC resources, eventually leading to system instability. If the container is set to restart automatically, the attack can be repeated. Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-3056.