Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In October 2024
In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
CVSS Score
3.5
EPSS Score
0.015
Published
2024-10-08
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Code Inclusion.This issue affects Payara Server: from 5.20.0 before 5.68.0, from 6.0.0 before 6.19.0, from 6.2022.1 before 6.2024.10, from 4.1.2.191.1 before 4.1.2.191.51.
CVSS Score
8.7
EPSS Score
0.004
Published
2024-10-08
In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API
CVSS Score
4.3
EPSS Score
0.003
Published
2024-10-08
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
CVSS Score
4.9
EPSS Score
0.005
Published
2024-10-08
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
CVSS Score
4.9
EPSS Score
0.235
Published
2024-10-08
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
CVSS Score
3.5
EPSS Score
0.015
Published
2024-10-08
An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.
CVSS Score
7.5
EPSS Score
0.258
Published
2024-10-08
An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to enumerate user e-mail addresses by sending password reset requests and observing the outcome (only when e-mail sending is consistently failing).
CVSS Score
5.3
EPSS Score
0.008
Published
2024-10-08
A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted requests.
CVSS Score
7.2
EPSS Score
0.006
Published
2024-10-08
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrative Domain (ADOM) to access device summary of unauthorized ADOMs via crafted HTTP requests.
CVSS Score
3.3
EPSS Score
0.004
Published
2024-10-08


Contact Us

Shodan ® - All rights reserved