6.9

CVSS4.0

CVE-2024-55660 - SiYuan has an SSTI via /api/template/renderSprig

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it allows attackers to access environment variablesโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 10:54 p.m. ๐Ÿ”„ Last Modified: June 5, 2025, 8:42 p.m.

8.7

CVSS4.0

CVE-2024-55659 - SiYuan has an arbitrary file write in the host via /api/asset/upload

SiYuan is a personal knowledge management system. Prior to version 3.1.16, the `/api/asset/upload` endpoint in Siyuan is vulnerable to both arbitrary file write to the host and stored cross-site scripting (via the file write). Version 3.1.16 contains a patch for the issue.

๐Ÿ“… Published: Dec. 11, 2024, 10:53 p.m. ๐Ÿ”„ Last Modified: June 5, 2025, 8:41 p.m.

8.7

CVSS4.0

CVE-2024-55658 - SiYuan has an arbitrary file read and path traversal via /api/export/exportResources

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is possible to manipulate the paths parameter to access and download arbitrary files from the host system by traversingโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 10:47 p.m. ๐Ÿ”„ Last Modified: June 5, 2025, 8:41 p.m.

8.7

CVSS4.0

CVE-2024-55657 - SiYuan has an arbitrary file read via /api/template/render

SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vulnerability exists in Siyuan's `/api/template/render` endpoint. The absence of proper validation on the path parameter allows attackers to access sensitive files on the host system. Version 3.1.16 coโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 10:44 p.m. ๐Ÿ”„ Last Modified: June 5, 2025, 8:41 p.m.

6.5

CVSS3.1

CVE-2024-55652 - PwnDoc Server-Side Template Injection vulnerability - Sandbox Escape to RCE using custom filters

PenDoc is a penetration testing reporting application. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an attacker can write a malicious docx template containing expressions that escape the JavaScript sandbox to execute arbitrary code on the system. An attacker who can control the contentโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 10:41 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.6

CVSS4.0

CVE-2024-53845 - AES/CBC Constant IV Vulnerability in ESPTouch v2

ESPTouch is a connection protocol for internet of things devices. In the ESPTouchV2 protocol, while there is an option to use a custom AES key, there is no option to set the IV (Initialization Vector) prior to versions 5.3.2, 5.2.4, 5.1.6, and 5.0.8. The IV is set to zero and remains constant throuโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 10:35 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-12490 - code-projects Online Class and Exam Scheduling System teacher_save.php sql injection

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /pages/teacher_save.php. The manipulation of the argument salut leads to sql injection. The attack can be initiated remotely.โ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 10:31 p.m. ๐Ÿ”„ Last Modified: April 7, 2025, 3:16 p.m.

2

CVSS4.0

CVE-2024-53274 - GHSL-2024-111: Reflected XSS in /home in habitica

Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `home.vue` containsa reflected XSS vulnerability due to an incorrect sanitization function. An attacker can specify a malicious `redirectTo` paramโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 10:16 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 9:37 p.m.

5

CVSS4.0

CVE-2024-53273 - GHSL-2024-110: Reflected XSS in /register in habitica

Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `RegisterLoginReset.vue` contains a reflected XSS vulnerability due to an incorrect sanitization function. An attacker can specify a malicious `reโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 10:13 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 9:38 p.m.

5

CVSS4.0

CVE-2024-53272 - GHSL-2024-109: Reflected XSS in /login in habitica

Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `login` and `social media` function in `RegisterLoginReset.vue` contains two reflected XSS vulnerabilities due to an incorrect sanitization function. An attacker can speโ€ฆ

๐Ÿ“… Published: Dec. 11, 2024, 10:06 p.m. ๐Ÿ”„ Last Modified: Sept. 5, 2025, 9:38 p.m.
Total resulsts: 349182
Page 7517 of 34,919
ยซ previous page ยป next page
Filters