CVE-2024-31899 – IBM Cognos Command Center information disclosure
https://notcve.org/view.php?id=CVE-2024-31899
IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user with physical access to the device. • https://www.ibm.com/support/pages/node/7149734 • CWE-256: Plaintext Storage of a Password •
CVE-2023-46175 – IBM Cloud Pak for Multicloud Management information disclosure
https://notcve.org/view.php?id=CVE-2023-46175
IBM Cloud Pak for Multicloud Management 2.3 through 2.3 FP8 stores user credentials in a log file plain clear text which can be read by a privileged user. • https://www.ibm.com/support/pages/node/7170411 • CWE-532: Insertion of Sensitive Information into Log File •
CVE-2024-4278 – Incorrect Synchronization in GitLab
https://notcve.org/view.php?id=CVE-2024-4278
An information disclosure issue has been discovered in GitLab EE affecting all versions starting from 16.5 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. • https://gitlab.com/gitlab-org/gitlab/-/issues/458484 https://hackerone.com/reports/2466205 • CWE-821: Incorrect Synchronization •
CVE-2024-0132
https://notcve.org/view.php?id=CVE-2024-0132
A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. • https://nvidia.custhelp.com/app/answers/detail/a_id/5582 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •
CVE-2024-44860
https://notcve.org/view.php?id=CVE-2024-44860
An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access sensitive data via a crafted request. • https://www.solvait.com https://gist.github.com/walhajri/e03974097d1fd4eb698a6a80931bdd45 • CWE-284: Improper Access Control •