7.5

CVSS3.1

CVE-2024-52299 - The PDF viewer macro allows accessing any attachment without access right checks

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService can access any attachment stored in the wiki as the "key" that is passed to prevent this is computed incorrectly, calling skip on the digest stream doesn't update the digest. Thiโ€ฆ

๐Ÿ“… Published: Nov. 13, 2024, 3:29 p.m. ๐Ÿ”„ Last Modified: Nov. 18, 2024, 5:29 p.m.

9.1

CVSS3.1

CVE-2024-52300 - macro-pdfviewer has a XSS through the width parameter

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for any user who can edit a page. XSS can impact the confidentiality, integrity and availability of the whole XWiki installation when an admin visitโ€ฆ

๐Ÿ“… Published: Nov. 13, 2024, 3:24 p.m. ๐Ÿ”„ Last Modified: Nov. 18, 2024, 5:29 p.m.

7.1

CVSS3.1

CVE-2024-7295 - Hard-coded credentials used for temporary and cache data encryption

In Progressยฎ Telerikยฎ Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information.

๐Ÿ“… Published: Nov. 13, 2024, 3:22 p.m. ๐Ÿ”„ Last Modified: Nov. 18, 2024, 5:41 p.m.

6.5

CVSS3.1

CVE-2024-8049 - Telerik Document Processing Improper Handling of Memory Resources

In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use of computing resources leaving the application process unavailable.

๐Ÿ“… Published: Nov. 13, 2024, 3:20 p.m. ๐Ÿ”„ Last Modified: Nov. 18, 2024, 5:46 p.m.

6.5

CVSS3.1

CVE-2024-52305 - UnoPim Stored XSS : Cookie hijacking through Create User function

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an emโ€ฆ

๐Ÿ“… Published: Nov. 13, 2024, 3:20 p.m. ๐Ÿ”„ Last Modified: Nov. 19, 2024, 6:04 p.m.

7.8

CVSS3.1

CVE-2024-10012 - Progress UI for WPF format provider unsafe deserialization vulnerability

In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulnerability.

๐Ÿ“… Published: Nov. 13, 2024, 3:19 p.m. ๐Ÿ”„ Last Modified: Jan. 7, 2025, 3:59 p.m.

7.8

CVSS3.1

CVE-2024-10013 - Progress UI for WinForms format provider unsafe deserialization vulnerability

In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.

๐Ÿ“… Published: Nov. 13, 2024, 3:17 p.m. ๐Ÿ”„ Last Modified: July 3, 2025, 6:30 p.m.

7.7

CVSS3.1

CVE-2024-52306 - FileManager Deserialization of Untrusted Data

FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter could lead to remote code execution. This vulnerability is fixed in 3.0.9.

๐Ÿ“… Published: Nov. 13, 2024, 3:15 p.m. ๐Ÿ”„ Last Modified: Nov. 19, 2024, 3:02 p.m.

7

CVSS4.0

CVE-2024-49504 - grub2 allows bypassing TPM-bound disk encryption on SL(E)M encrypted Images

grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.

๐Ÿ“… Published: Nov. 13, 2024, 2:44 p.m. ๐Ÿ”„ Last Modified: Nov. 13, 2024, 7:35 p.m.

4.6

CVSS4.0

CVE-2024-9477 - XSS in AirTies' Air4443 Firmware

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AirTies Air4443 Firmware allows Cross-Site Scripting (XSS).This issue affects Air4443 Firmware: through 14102024. NOTE: The vendor was contacted and it was learned that the product classifโ€ฆ

๐Ÿ“… Published: Nov. 13, 2024, 2:29 p.m. ๐Ÿ”„ Last Modified: Nov. 15, 2024, 10:54 p.m.
Total resulsts: 343919
Page 7372 of 34,392
ยซ previous page ยป next page
Filters