4.7
CVE-2024-39694 - Duende IdentityServer Open Redirect vulnerability
Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and trusted. If such a Url is returned as a redirect, some browsers will follow it to β¦
5.4
CVE-2024-39318 - Ibexa Admin UI vulnerable to DOM-based Cross-site Scripting in file upload widget
The Ibexa Admin UI Bundle contains all the necessary parts to run the Ibexa DXP Back Office interface. The file upload widget is vulnerable to XSS payloads in filenames. Access permission to upload files is required. As such, in most cases only authenticated editors and administrators will have theβ¦
9.1
CVE-2024-41947 - XWiki Platform XSS through conflict resolution
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side of the other user, which compromises the confidenβ¦
10
CVE-2024-37901 - XWiki Platform vulnerable to remote code execution from account via SearchSuggestConfigSheet
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can perform arbitrary remote code execution by adding instances of `XWiki.SearchSuggestConfig` and `XWiki.SearchSuggestSourceClass` to their user profile or β¦
6.4
CVE-2024-37900 - XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploader
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading an attachment with a malicious filename, malicious JavaScript code could be executed. This requires a social engineering attack to get the victim into uploading a file with a maliβ¦
4.3
CVE-2024-37898 - XWiki Platform vulnerable to document deletion and overwrite from edit
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit right on a page in XWiki, that user can delete the page and replace it by a page with new content without having delete right. The previous version of the page β¦
8.8
CVE-2024-7340 - W&B Weave server remote arbitrary file leak and privilege escalation
The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.
3.3
CVE-2024-37135 -
DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application β¦
3.3
CVE-2024-31203 -
A βCWE-121: Stack-based Buffer Overflowβ in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacker to possibly trigger a Denial-of-Service (DoS) condition on the target component.
7.8
CVE-2024-31202 -
A βCWE-732: Incorrect Permission Assignment for Critical Resourceβ in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.