8.3

CVSS3.1

CVE-2024-53979 - Ansible collection "ibm.ibm_zhmc" has passwords in clear text in log file and in output of some mod…

ibm.ibm_zhmc is an Ansible collection for the IBM Z HMC. The Ansible collection "ibm.ibm_zhmc" writes password-like properties in clear text into its log file and into the output returned by some of its Ansible module in the following cases: 1. The 'boot_ftp_password' and 'ssc_master_pw' properties…

📅 Published: Nov. 29, 2024, 6:50 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.3

CVSS3.1

CVE-2024-53865 - Python package "zhmcclient" has passwords in clear text in its HMC and API logs

zhmcclient is a pure Python client library for the IBM Z HMC Web Services API. In affected versions the Python package "zhmcclient" writes password-like properties in clear text into its HMC and API logs in the following cases: 1. The 'boot-ftp-password' and 'ssc-master-pw' properties when creating…

📅 Published: Nov. 29, 2024, 6:48 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-53864 - Cross-site Scripting in a field that is used in the Content name pattern in ibexa/admin-ui

Ibexa Admin UI Bundle is all the necessary parts to run the Ibexa DXP Back Office interface. The Content name pattern is used to build Content names from one or more fields. An XSS vulnerability has been found in this mechanism. Content edit permission is required to exploit it. After the fix, any …

📅 Published: Nov. 29, 2024, 6:45 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.2

CVSS3.1

CVE-2024-53861 - Issuer field partial matches allowed in pyjwt

pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `"acb"` being accepted for `"_abc_"`. This is a bug introduced in version 2.10.0: checking the "iss" claim changed from `isinstance(issuer, list)` to `isinstance(issuer, Sequen…

📅 Published: Nov. 29, 2024, 6:43 p.m. 🔄 Last Modified: Sept. 22, 2025, 6:09 p.m.

7.1

CVSS3.1

CVE-2024-53848 - check-jsonschema default caching for remote schemas allows for cache confusion

check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the basename of a remote schema as the name of the file in the cache, e.g. `https://example.org/schema.json` will be stored as `schema.json`. This naming allows for conflicts. If an atta…

📅 Published: Nov. 29, 2024, 6:39 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-52810 - Prototype Pollution in @intlify/shared >=9.7.0 <= 10.0.4

@intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the glo…

📅 Published: Nov. 29, 2024, 6:36 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-52809 - Cross-site Scripting vulnerability with prototype pollution in vue-i18n

vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are generated in development mode there is a possibility of Cross-site Scripting attack. This issue has been addressed in versio…

📅 Published: Nov. 29, 2024, 6:32 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-52801 - Brute force takeover of OpenID Connect session cookies in sftpgo

sftpgo is a full-featured and highly configurable event-driven file transfer solution. Server protocols: SFTP, HTTP/S, FTP/S, WebDAV. The OpenID Connect implementation allows authenticated users to brute force session cookies and thereby gain access to other users' data, since the cookies are gener…

📅 Published: Nov. 29, 2024, 6:26 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

2.3

CVSS4.0

CVE-2024-52800 - Potential XXE (XML External Entity Injection) vulnerability in veraPDF CLI

veraPDF is an open source PDF/A validation library. Executing policy checks using custom schematron files via the CLI invokes an XSL transformation that may theoretically lead to a remote code execution (RCE) vulnerability. This doesn't affect the standard validation and policy checks functionality…

📅 Published: Nov. 29, 2024, 6:20 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS4.0

CVE-2024-52003 - X-Forwarded-Prefix Header still allows for Open Redirect in traefik

Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix header from an untrusted source. This issue has been addressed in versions 2.11.14 and 3.2.1. Users are advised to upgrade. There are…

📅 Published: Nov. 29, 2024, 6:15 p.m. 🔄 Last Modified: Nov. 25, 2025, 1:48 p.m.
Total resulsts: 349182
Page 7668 of 34,919
« previous page » next page
Filters