4.8

CVSS4.0

CVE-2024-56410 - PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability in custom properties

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability in custom properties. The HTML page is generated without clearing custom properties. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 …

πŸ“… Published: Jan. 3, 2025, 5:17 p.m. πŸ”„ Last Modified: April 17, 2025, 2:35 a.m.

8.3

CVSS4.0

CVE-2024-56409 - PhpSpreadsheet vulnerable to unauthorized reflected XSS in Currency.php file

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the `Currency.php` file. Using the `/vendor/phpoffice/phpspreadsheet/samples/Wizards/NumberFormat/Currency.ph…

πŸ“… Published: Jan. 3, 2025, 5:05 p.m. πŸ”„ Last Modified: April 21, 2025, 5:14 p.m.

8.3

CVSS4.0

CVE-2024-56366 - PhpSpreadsheet vulnerable to unauthorized reflected XSS in the Accounting.php file

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the `Accounting.php` file. Using the `/vendor/phpoffice/phpspreadsheet/samples/Wizards/NumberFormat/Accountin…

πŸ“… Published: Jan. 3, 2025, 5:01 p.m. πŸ”„ Last Modified: April 21, 2025, 4:57 p.m.

8.3

CVSS4.0

CVE-2024-56365 - PhpSpreadsheet vulnerable to unauthorized reflected XSS in the constructor of the Downloader class

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the constructor of the `Downloader` class. Using the `/vendor/phpoffice/phpspreadsheet/samples/download.php` …

πŸ“… Published: Jan. 3, 2025, 4:56 p.m. πŸ”„ Last Modified: April 21, 2025, 4:57 p.m.

5.3

CVSS3.1

CVE-2025-21610 - Trix allows Cross-site Scripting via `javascript:` url in a link

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.12 are vulnerable to cross-site scripting when pasting malicious code in the link field. An attacker could trick the user to copy&paste a malicious `javascript:` URL as a link that would execute arbi…

πŸ“… Published: Jan. 3, 2025, 4:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-21609 - SiYuan has an arbitrary file deletion vulnerability

SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attacker can craft a payload to exploit this vulnerability, resul…

πŸ“… Published: Jan. 3, 2025, 4:26 p.m. πŸ”„ Last Modified: May 14, 2025, 2:39 p.m.

5.3

CVSS4.0

CVE-2024-56514 - Karmada Tar Slips in CRDs archive extraction

Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, both in karmadactl and karmada-operator, it is possible to supply a filesystem path, or an HTTP(s) URL to retrieve the custom resourc…

πŸ“… Published: Jan. 3, 2025, 4:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2024-56513 - Karmada PULL Mode Cluster Privilege Escalation

Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, the PULL mode clusters registered with the `karmadactl register` command have excessive privileges to access control plane resources.…

πŸ“… Published: Jan. 3, 2025, 4:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS4.0

CVE-2024-56408 - PhpSpreadsheet allows unauthorized reflected XSS in `Convert-Online.php` file

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have no sanitization in the `/vendor/phpoffice/phpspreadsheet/samples/Engineering/Convert-Online.php` file, which leads to the possibility of a cross-site scripting attack. V…

πŸ“… Published: Jan. 3, 2025, 4:05 p.m. πŸ”„ Last Modified: May 20, 2025, 7:15 p.m.

2.1

CVSS4.0

CVE-2024-56324 - GoCD vulnerable to XXE injection via abuse of pipeline XML "snippet" editing by group admins

GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD server. Theoretically, the XXE vulnerability can result in additi…

πŸ“… Published: Jan. 3, 2025, 3:56 p.m. πŸ”„ Last Modified: Aug. 1, 2025, 7:22 p.m.
Total resulsts: 344980
Page 6869 of 34,498
Β« previous page Β» next page
Filters