4.8

CVSS4.0

CVE-2024-56412 - PhpSpreadsheet vulnerable to bypass of the XSS sanitizer using the javascript protocol and special …

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to bypass of the cross-site scripting sanitizer using the javascript protocol and special characters. An attacker can use special characters, so that the libra…

πŸ“… Published: Jan. 3, 2025, 5:20 p.m. πŸ”„ Last Modified: March 6, 2025, 1:30 p.m.

4.8

CVSS4.0

CVE-2024-56411 - PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page …

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability of the hyperlink base in the HTML page header. The HTML page is formed without sanitizing the hyperlink base. Versions 3.7.0, …

πŸ“… Published: Jan. 3, 2025, 5:19 p.m. πŸ”„ Last Modified: March 6, 2025, 1:30 p.m.

4.8

CVSS4.0

CVE-2024-56410 - PhpSpreadsheet has Cross-Site Scripting (XSS) vulnerability in custom properties

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 have a cross-site scripting (XSS) vulnerability in custom properties. The HTML page is generated without clearing custom properties. Versions 3.7.0, 2.3.5, 2.1.6, and 1.29.7 …

πŸ“… Published: Jan. 3, 2025, 5:17 p.m. πŸ”„ Last Modified: April 17, 2025, 2:35 a.m.

8.3

CVSS4.0

CVE-2024-56409 - PhpSpreadsheet vulnerable to unauthorized reflected XSS in Currency.php file

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the `Currency.php` file. Using the `/vendor/phpoffice/phpspreadsheet/samples/Wizards/NumberFormat/Currency.ph…

πŸ“… Published: Jan. 3, 2025, 5:05 p.m. πŸ”„ Last Modified: April 21, 2025, 5:14 p.m.

8.3

CVSS4.0

CVE-2024-56366 - PhpSpreadsheet vulnerable to unauthorized reflected XSS in the Accounting.php file

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the `Accounting.php` file. Using the `/vendor/phpoffice/phpspreadsheet/samples/Wizards/NumberFormat/Accountin…

πŸ“… Published: Jan. 3, 2025, 5:01 p.m. πŸ”„ Last Modified: April 21, 2025, 4:57 p.m.

8.3

CVSS4.0

CVE-2024-56365 - PhpSpreadsheet vulnerable to unauthorized reflected XSS in the constructor of the Downloader class

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1.29.7 are vulnerable to unauthorized reflected cross-site scripting in the constructor of the `Downloader` class. Using the `/vendor/phpoffice/phpspreadsheet/samples/download.php` …

πŸ“… Published: Jan. 3, 2025, 4:56 p.m. πŸ”„ Last Modified: April 21, 2025, 4:57 p.m.

5.3

CVSS3.1

CVE-2025-21610 - Trix allows Cross-site Scripting via `javascript:` url in a link

Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.12 are vulnerable to cross-site scripting when pasting malicious code in the link field. An attacker could trick the user to copy&paste a malicious `javascript:` URL as a link that would execute arbi…

πŸ“… Published: Jan. 3, 2025, 4:29 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2025-21609 - SiYuan has an arbitrary file deletion vulnerability

SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attacker can craft a payload to exploit this vulnerability, resul…

πŸ“… Published: Jan. 3, 2025, 4:26 p.m. πŸ”„ Last Modified: May 14, 2025, 2:39 p.m.

5.3

CVSS4.0

CVE-2024-56514 - Karmada Tar Slips in CRDs archive extraction

Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, both in karmadactl and karmada-operator, it is possible to supply a filesystem path, or an HTTP(s) URL to retrieve the custom resourc…

πŸ“… Published: Jan. 3, 2025, 4:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2024-56513 - Karmada PULL Mode Cluster Privilege Escalation

Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes clusters and clouds. Prior to version 1.12.0, the PULL mode clusters registered with the `karmadactl register` command have excessive privileges to access control plane resources.…

πŸ“… Published: Jan. 3, 2025, 4:11 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7289 of 34,919
Β« previous page Β» next page
Filters