Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
a-member vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2003-0689
The getgrouplist function in GNU libc (glibc) 2.2.4 and previous versions allows malicious users to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.
Redhat Enterprise Linux 2.1
5.4
CVSSv3
CVE-2021-24128
Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions prior to 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged authenticated attacker (contributor+) to inject arbitrary web script or HTML via the 'Descript...
Wpdarko Team Members
NA
CVE-2024-1942
Mattermost versions 8.1.x prior to 8.1.9, 9.2.x prior to 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an authenticated malicious user to access the contents of individual posts in channels they are not a mem...
NA
CVE-2024-1952
Mattermost version 8.1.x prior to 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels they are not a mem...
4.3
CVSSv3
CVE-2023-4532
An issue has been discovered in GitLab affecting all versions starting from 16.2 prior to 16.2.8, all versions starting from 16.3 prior to 16.3.5, all versions starting from 16.4 prior to 16.4.1. Users were capable of linking CI/CD jobs of private projects which they are not a me...
Gitlab Gitlab
Gitlab Gitlab 16.4.0
NA
CVE-2008-0898
The distributed queue feature in JMS in BEA WebLogic Server 9.0 up to and including 10.0, in certain configurations, does not properly handle when a client cannot send a message to a member of a distributed queue, which allows remote authenticated users to bypass intended access ...
Bea Weblogic Server 10.0
Bea Weblogic Server 9.0
Bea Weblogic Server 9.1
Bea Weblogic Server 9.2
7.5
CVSSv3
CVE-2022-29585
In Mahara prior to 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of)...
Mahara Mahara 22.04.0
Mahara Mahara
3.5
CVSSv3
CVE-2023-3511
An issue has been discovered in GitLab EE affecting all versions starting from 8.17 prior to 16.4.4, all versions starting from 16.5 prior to 16.5.4, all versions starting from 16.6 prior to 16.6.2. It was possible for auditor users to fork and submit merge requests to private pr...
Gitlab Gitlab
7.5
CVSSv3
CVE-2022-2229
An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 before 14.10.5, 15.0 before 15.0.4, and 15.1 before 15.1.1 allows an malicious user to extract the value of an unprotected variable they know the name of in public projects or private projects they...
Gitlab Gitlab 15.1.0
Gitlab Gitlab
NA
CVE-2024-1888
Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the ...
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »