8.8

CVSS3.1

CVE-2023-34444 - Cross-site Scripting vulnerability on pages/ajax.searchform.php in Combodo iTop

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of script tags. This issue has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this vulnera…

📅 Published: Nov. 4, 2024, 11:30 p.m. 🔄 Last Modified: Nov. 6, 2024, 2:28 p.m.

8.8

CVSS3.1

CVE-2023-34443 - Cross-site Scripting vulnerability in the run_query.php page in Combodo iTop

Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (XSS) are possible for scripts outside of script tags. This has been fixed in versions 2.7.9, 3.0.4, 3.1.0. All users are advised to upgrade. There are no known workarounds for this…

📅 Published: Nov. 4, 2024, 11:29 p.m. 🔄 Last Modified: Nov. 6, 2024, 2:25 p.m.

5.1

CVSS4.0

CVE-2024-50346 - WebFeed HTML injection vulnerabilities

WebFeed is a lightweight web feed reader extension for Firefox/Chrome. Multiple HTML injection vulnerabilities in WebFeed can lead to CSRF and UI spoofing attacks. A remote attacker can provide malicious RSS feeds and attract the victim user to visit it using WebFeed. The attacker can then inject m…

📅 Published: Nov. 4, 2024, 11:13 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6

CVSS4.0

CVE-2024-51498 - [@imput/cobalt-web] Cross-site Scripting when downloading picker image from malicious instance

cobalt is a media downloader that doesn't piss you off. A malicious cobalt instance could serve links with the `javascript:` protocol, resulting in Cross-site Scripting (XSS) when the user tries to download an item from a picker. This issue has been present since commit `66bac03e`, was mitigated in…

📅 Published: Nov. 4, 2024, 11:07 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-51500 - Failure to check for packets from the broadcast address allows potential DDoS amplification attack …

Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets claiming to be from the special broadcast address (0xFFFFFFFF) which could result in unexpected behavior and potential for DDoS attacks on the network. A malicious actor could cra…

📅 Published: Nov. 4, 2024, 11 p.m. 🔄 Last Modified: Oct. 15, 2025, 5:53 p.m.

10

CVSS4.0

CVE-2024-51501 - CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes

Refit is an automatic type-safe REST library for .NET Core, Xamarin and .NET The various header-related Refit attributes (Header, HeaderCollection and Authorize) are vulnerable to CRLF injection. The way HTTP headers are added to a request is via the `HttpHeaders.TryAddWithoutValidation` method. Th…

📅 Published: Nov. 4, 2024, 10:56 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2024-51502 - Panic Vulnerability in loona-hpack

loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the same vulnerability as the original `hpack` as documented in issue #11. All users who try to decode untrusted input using the Decoder are vulnerable to this exploit. This issue has…

📅 Published: Nov. 4, 2024, 10:42 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2024-10805 - code-projects University Event Management System doedit.php sql injection

A vulnerability was found in code-projects University Event Management System 1.0. It has been classified as critical. This affects an unknown part of the file doedit.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has bee…

📅 Published: Nov. 4, 2024, 10:31 p.m. 🔄 Last Modified: Nov. 7, 2024, 5:09 p.m.

8.7

CVSS4.0

CVE-2024-51734 - User data deletion by anoynmous users in Zope

Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delete the user data maintained by an `AccessControl.userfolder.UserFolder` which may prevent any privileged access. This problem has been fixed in version 7.2. Users are advised to up…

📅 Published: Nov. 4, 2024, 10:25 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

3.1

CVSS3.1

CVE-2024-51744 - Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations…

golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially not checking errors in the way they should be. Especially, if a token is both expired and invalid, the errors returned by `ParseWi…

📅 Published: Nov. 4, 2024, 9:47 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8032 of 34,919
« previous page » next page
Filters