Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2024-6891
Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.
Journyx
No fix yet
HIGH 7.5
CVE-2024-6893EPSS 33%
The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attack…
Journyx
No fix yet
MEDIUM 6.1
CVE-2024-6892
Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.
Journyx
Mitigation only
HIGH 8.8
CVE-2024-6890
Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can brut…
Journyx
No fix yet