NVD disclosure day

Published threat advisories for September 25, 2024

CVE advisoryCRITICAL

CVE-2024-4657

Talent BAP Automation Cross-Site Scripting Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the BAP Automation web application allows for the injection of malicious scripts, potentially leading to unauthorized access to data and systems. This stored cross-site scripting (XSS) flaw enables attackers to execute code within a user's browser, which can result in session hijacking or further pri

CVE advisoryCRITICAL

CVE-2024-6593

WatchGuard Authentication Gateway Improper Authorization Allows Command Execution.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An improper authorization vulnerability in WatchGuard Authentication Gateway on Windows allows an attacker with network access to execute restricted management commands. This could lead to unauthorized retrieval of usernames and group memberships or tampering with the agent's configuration, though it does not expose us

CVE advisoryCRITICAL

CVE-2024-9142

Olgu Computer Systems e-Belediye: Path Manipulation Risk.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in e-Belediye that permits manipulation of web input, which could impact file system operations. This may affect the integrity and confidentiality of critical resources, posing a business risk of unauthorized access and data modification. Organizations using affected e-Belediye systems should ass