5.4

CVSS3.1

CVE-2024-47048 -

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the marketplace and private apps.

๐Ÿ“… Published: Sept. 24, 2024, midnight ๐Ÿ”„ Last Modified: March 25, 2025, 5:16 p.m.

7.5

CVSS3.1

CVE-2024-46936 -

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue. Attackers can abuse the UpdateOTRAck method to send ephemeral messages as if they were any other user they choose.

๐Ÿ“… Published: Sept. 24, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2023-26690 -

File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu.

๐Ÿ“… Published: Sept. 24, 2024, midnight ๐Ÿ”„ Last Modified: April 24, 2025, 2:16 p.m.

9.8

CVSS3.1

CVE-2024-46612 -

IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.

๐Ÿ“… Published: Sept. 24, 2024, midnight ๐Ÿ”„ Last Modified: April 28, 2025, 6:15 p.m.

6.1

CVSS3.1

CVE-2024-46934 -

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able to abuse the UpdateOTRAck method to forge a message that contains an XSS payload.

๐Ÿ“… Published: Sept. 24, 2024, midnight ๐Ÿ”„ Last Modified: March 25, 2025, 5:16 p.m.

7.2

CVSS3.1

CVE-2023-26691 -

Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a new add-on.

๐Ÿ“… Published: Sept. 24, 2024, midnight ๐Ÿ”„ Last Modified: April 24, 2025, 2:16 p.m.

9.8

CVSS3.1

CVE-2024-42797 -

An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music playlist entries.

๐Ÿ“… Published: Sept. 24, 2024, midnight ๐Ÿ”„ Last Modified: April 28, 2025, 5:10 p.m.

9.8

CVSS3.1

CVE-2024-46957 -

Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.

๐Ÿ“… Published: Sept. 24, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-46935 -

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser.

๐Ÿ“… Published: Sept. 24, 2024, midnight ๐Ÿ”„ Last Modified: March 25, 2025, 5:16 p.m.

7.6

CVSS3.1

CVE-2024-46610 -

An access control issue in IceCMS v3.4.7 and before allows attackers to arbitrarily modify users' information, including username and password, via a crafted POST request sent to the endpoint /User/ChangeUser/s in the ChangeUser function in UserController.java

๐Ÿ“… Published: Sept. 24, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:38 a.m.
Total resulsts: 349182
Page 8490 of 34,919
ยซ previous page ยป next page
Filters