8.2
CVE-2024-52269 - AI Assistant PDF Document Spoofing in DocuSign
User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. The SaaS AI assistant ignores hidden content that is rendered after signing, misleading the user. For reference see:Β CVE-2024-52276 This issue affects DocuSign: through 2024-12-04.
3.5
CVE-2024-54158 -
In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
4.3
CVE-2024-54157 -
In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
4.2
CVE-2024-54156 -
In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
3.7
CVE-2024-54155 -
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication
8
CVE-2024-54154 -
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
3.1
CVE-2024-54153 -
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter
0.0
CVE-2024-52278 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
6.4
CVE-2024-8962 - WPBITS Addons For Elementor Page Builder <= 1.5.2 - Authenticated (Author+) Stored Cross-Site Scripβ¦
The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Authorβ¦
6.4
CVE-2024-11854 - Listdom β Business Directory and Classified Ads Listings WordPress Plugin <= 3.7.0 - Authenticated β¦
The Listdom β Business Directory and Classified Ads Listings WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βshortcodeβ parameter in all versions up to, and including, 3.7.0 due to insufficient input sanitization and output escaping. This makes it possiblβ¦