CVE Severity Distribution (Last 30 Days)
Found 11 CVEs in the last 30 days.
CVE-2024-3400
CRITICAL
CVSS: 10.0
EPSS: 100.0%
VulnCheck KEV
Weaponized
Metasploit
ExploitDB
GHDB
CWE-20
CWE-77
CWE-77
T1190
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.
Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.
Published: 2024-04-12
CVE-2024-34007
HIGH
CVSS: 8.8
EPSS: 0.4%
CWE-352
CWE-352
T1189
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
Published: 2024-05-31
CVE-2024-34008
HIGH
CVSS: 8.8
EPSS: 0.4%
CWE-352
CWE-352
T1189
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
Published: 2024-05-31
CVE-2024-34001
HIGH
CVSS: 8.4
EPSS: 0.4%
CWE-352
CWE-352
T1189
Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.
Published: 2024-05-31
CVE-2024-34009
HIGH
CVSS: 7.5
EPSS: 0.4%
CWE-20
T1190
Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA is utilized.
Published: 2024-05-31
CVE-2024-34002
MEDIUM
CVSS: 6.5
EPSS: 0.5%
CWE-200
T1005
T1083
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore feedback modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
Published: 2024-05-31
CVE-2024-34004
MEDIUM
CVSS: 6.5
EPSS: 0.5%
CWE-200
T1005
T1083
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore wiki modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
Published: 2024-05-31
CVE-2024-34005
MEDIUM
CVSS: 6.5
EPSS: 0.5%
CWE-200
T1005
T1083
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
Published: 2024-05-31
CVE-2024-34003
MEDIUM
CVSS: 5.9
EPSS: 0.4%
CWE-200
T1005
T1083
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
Published: 2024-05-31
CVE-2024-34000
MEDIUM
CVSS: 4.3
EPSS: 0.5%
CWE-79
CWE-79
T1189
ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.
Published: 2024-05-31
CVE-2024-34006
MEDIUM
CVSS: 4.3
EPSS: 0.4%
CWE-838
CWE-838
The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in plaintext instead of being rendered.
Published: 2024-05-31