5.3

CVSS3.1

CVE-2024-45297 - Prevent topic list filtering by hidden tags for unauthorized users in Discourse

Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. This issue has been patched in the latest stable, beta and tests-passed version of Discourse. All users area are advised to upgrade. There are no known work…

πŸ“… Published: Oct. 7, 2024, 8:24 p.m. πŸ”„ Last Modified: Sept. 25, 2025, 8:27 p.m.

8.2

CVSS3.1

CVE-2024-45051 - Bypass of email address validation via encoded email addresses in Discourse

Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites, categories and/or groups. This issue has been patched in the latest stable, beta and tests-passed version …

πŸ“… Published: Oct. 7, 2024, 8:23 p.m. πŸ”„ Last Modified: Sept. 25, 2025, 8:27 p.m.

7.1

CVSS3.1

CVE-2024-45060 - Unauthenticated Cross-Site-Scripting (XSS) in sample file in PHPSpreadsheet

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. One of the sample scripts in PhpSpreadsheet is susceptible to a cross-site scripting (XSS) vulnerability due to improper handling of input where a number is expected leading to formula injection. The code in in `45_Quad…

πŸ“… Published: Oct. 7, 2024, 8:15 p.m. πŸ”„ Last Modified: Oct. 17, 2024, 2:14 p.m.

7.7

CVSS3.1

CVE-2024-45290 - Path traversal and Server-Side Request Forgery when opening XLSX files in PHPSpreadsheet

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file which links media from external URLs. When opening the XLSX file, PhpSpreadsheet retrieves the image size and type by reading the file contents, if the provided pa…

πŸ“… Published: Oct. 7, 2024, 8:12 p.m. πŸ”„ Last Modified: Oct. 16, 2024, 7:54 p.m.

6.3

CVSS3.1

CVE-2024-45291 - Path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled in P…

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links images from arbitrary paths. When embedding images has been enabled in HTML writer with `$writer->setEmbedImages(true);` those files will be included in…

πŸ“… Published: Oct. 7, 2024, 8:09 p.m. πŸ”„ Last Modified: Oct. 16, 2024, 7:09 p.m.

5.4

CVSS3.1

CVE-2024-45292 - PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinks

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. `\PhpOffice\PhpSpreadsheet\Writer\Html` does not sanitize "javascript:" URLs from hyperlink `href` attributes, resulting in a Cross-Site Scripting vulnerability. This issue has been addressed in release versions 1.29.2,…

πŸ“… Published: Oct. 7, 2024, 8:06 p.m. πŸ”„ Last Modified: March 7, 2025, 4:48 p.m.

7.5

CVSS3.1

CVE-2024-45293 - XML External Entity Reference (XXE) in PHPSpreadsheet's XLSX reader

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for preventing XXE attacks in the XLSX reader can be bypassed by slightly modifying the XML structure, utilizing white-spaces. On servers that allow users to upload their own Excel (XLSX…

πŸ“… Published: Oct. 7, 2024, 8:03 p.m. πŸ”„ Last Modified: March 7, 2025, 4:48 p.m.

6.4

CVSS3.1

CVE-2024-47079 - Unauthorized usage of remote hardware module because of missing channel verification

Meshtastic is an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtastic firmware is an open source firmware implementation for the broader project. The remote hardware module of the firmware does not have proper checks to ensure a remote hardwar…

πŸ“… Published: Oct. 7, 2024, 7:55 p.m. πŸ”„ Last Modified: Oct. 21, 2025, 2:06 p.m.

7

CVSS3.1

CVE-2024-31449 - Lua library commands may lead to stack overflow and RCE in Redis

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting.…

πŸ“… Published: Oct. 7, 2024, 7:51 p.m. πŸ”„ Last Modified: Sept. 4, 2025, 7:03 p.m.

5.5

CVSS3.1

CVE-2024-31228 - Denial-of-service due to unbounded pattern matching in Redis

Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service by using specially crafted, long string match patterns on supported commands such as `KEYS`, `SCAN`, `PSUBSCRIBE`, `FUNCTION LIST`, `COMMAND LIST` and ACL definitions. Matching of …

πŸ“… Published: Oct. 7, 2024, 7:51 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.
Total resulsts: 349182
Page 8373 of 34,919
Β« previous page Β» next page
Filters