CRITICAL
CVSS: 9.8
Critical Remote Code Execution in Apache HTTP Server mod_proxy
A critical vulnerability in Apache HTTP Server mod_proxy allows unauthenticated remote attackers to execute arbitrary code via crafted HTTP requests. This affects versions 2.4.0 through 2.4.59.
محصولات تحت تأثیر:
cpe:2.3:a:apache:http_server:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:http_server:2.4.59:*:*:*:*:*:*:*
HIGH
CVSS: 8.1
SQL Injection in WordPress Plugin WPForms
The WPForms plugin for WordPress is vulnerable to SQL Injection via the form_id parameter in versions before 1.8.9. This allows authenticated attackers to extract sensitive data.
محصولات تحت تأثیر:
cpe:2.3:a:wpforms:wpforms:*:*:*:*:*:wordpress:*:*
CRITICAL
CVSS: 9.1
Authentication Bypass in Jenkins Core
Jenkins Core contains an authentication bypass vulnerability that allows unauthorized users to access administrative functions. Affects LTS versions prior to 2.440.3.
محصولات تحت تأثیر:
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*
HIGH
CVSS: 7.2
Cross-Site Scripting in GitLab CE/EE
An XSS vulnerability in GitLab CE/EE allows attackers to inject malicious scripts via the markdown renderer. Affects versions 16.0 to 16.11.2.
محصولات تحت تأثیر:
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
HIGH
CVSS: 8.2
Buffer Overflow in OpenSSL TLS Handshake
A buffer overflow vulnerability in OpenSSL during TLS handshake processing can lead to denial of service or remote code execution. Affects OpenSSL 3.0.0 to 3.0.13.
محصولات تحت تأثیر:
cpe:2.3:a:openssl:openssl:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:openssl:openssl:3.0.13:*:*:*:*:*:*:*
HIGH
CVSS: 7.8
Privilege Escalation in Linux Kernel netfilter
A use-after-free vulnerability in the Linux Kernel netfilter subsystem allows local users to escalate privileges to root. Affects kernel versions 5.15 to 6.7.
محصولات تحت تأثیر:
cpe:2.3:o:linux:linux_kernel:5.15:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.7:*:*:*:*:*:*:*
MEDIUM
CVSS: 6.5
Path Traversal in Python urllib
Python urllib module is vulnerable to path traversal attacks when processing malformed URLs. This can lead to unauthorized file access on the server.
محصولات تحت تأثیر:
cpe:2.3:a:python:python:3.11.0:*:*:*:*:*:*:*
cpe:2.3:a:python:python:3.12.0:*:*:*:*:*:*:*
MEDIUM
CVSS: 5.3
Information Disclosure in MongoDB Compass
MongoDB Compass exposes sensitive connection credentials in log files when debugging is enabled. This affects versions 1.40.0 through 1.42.0.
محصولات تحت تأثیر:
cpe:2.3:a:mongodb:mongodb_compass:1.40.0:*:*:*:*:*:*:*
CRITICAL
CVSS: 9.3
Command Injection in Docker BuildKit
Docker BuildKit is vulnerable to command injection via malicious Dockerfile instructions. This allows attackers to execute arbitrary commands during image builds.
محصولات تحت تأثیر:
cpe:2.3:a:docker:buildkit:*:*:*:*:*:*:*:*
HIGH
CVSS: 8.0
SSRF in Kubernetes API Server
The Kubernetes API Server is vulnerable to Server-Side Request Forgery (SSRF) via the webhook validation mechanism. Affects versions 1.28.0 to 1.29.2.
محصولات تحت تأثیر:
cpe:2.3:a:kubernetes:kubernetes:1.28.0:*:*:*:*:*:*:*
cpe:2.3:a:kubernetes:kubernetes:1.29.2:*:*:*:*:...
MEDIUM
CVSS: 5.9
Race Condition in Nginx HTTP/2 Module
A race condition in the Nginx HTTP/2 module can cause memory corruption leading to denial of service. Affects nginx versions 1.24.0 and earlier.
محصولات تحت تأثیر:
cpe:2.3:a:nginx:nginx:1.24.0:*:*:*:*:*:*:*
CRITICAL
CVSS: 9.4
Heap Overflow in Redis Server
Redis server contains a heap overflow vulnerability in the Lua scripting engine that allows remote code execution. Affects Redis 7.0.0 through 7.2.4.
محصولات تحت تأثیر:
cpe:2.3:a:redis:redis:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redis:redis:7.2.4:*:*:*:*:*:*:*