5.4

CVSS3.1

CVE-2024-41877 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page…

📅 Published: Aug. 23, 2024, 4:53 p.m. 🔄 Last Modified: Oct. 7, 2024, 12:30 p.m.

4.8

CVSS3.1

CVE-2024-41842 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page…

📅 Published: Aug. 23, 2024, 4:53 p.m. 🔄 Last Modified: Oct. 7, 2024, 12:32 p.m.

5.4

CVSS3.1

CVE-2024-41878 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to inject and execute arbitrary JavaScript code within the context of the user's browser session. Exploitation of this issue requires…

📅 Published: Aug. 23, 2024, 4:53 p.m. 🔄 Last Modified: Oct. 7, 2024, 12:30 p.m.

6.1

CVSS3.1

CVE-2024-43794 - OpenSearch Dashboards Security Plugin improper validation of nextUrl can lead to external redirect

OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead to external redirect on login to OpenSearch-Dashboards for specially crafted parameters. A patch is available…

📅 Published: Aug. 23, 2024, 4:15 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-42364 - homepage DNS rebinding vulnerability (GHSL-2024-096)

Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. Homepage is setup without certificate and authentication by default, leaving it to vulnerable to DNS rebinding. In this attack, an attacker will a…

📅 Published: Aug. 23, 2024, 3:44 p.m. 🔄 Last Modified: Sept. 12, 2024, 6:20 p.m.

7.8

CVSS3.1

CVE-2024-43791 - RequestStore has Incorrect Default Permissions

RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows local users to execute arbitrary code. This version was published in 2017, and most production environments do not …

📅 Published: Aug. 23, 2024, 2:39 p.m. 🔄 Last Modified: Sept. 12, 2024, 6:26 p.m.

7.7

CVSS3.1

CVE-2024-43782 - openedx-translations's Atlas translations for Open edX missing validation

This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pulling translations from the openedx-translations repository via openedx-atlas, translations in the edx-platform repository were validated using edx-i18n-t…

📅 Published: Aug. 23, 2024, 2:35 p.m. 🔄 Last Modified: Sept. 12, 2024, 6:29 p.m.

6.9

CVSS4.0

CVE-2024-8112 - thinkgem JeeSite Cookie login cross site scripting

A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown processing of the file /js/a/login of the component Cookie Handler. The manipulation of the argument skinName leads to cross site scripting. The attack may be initiated remotely. The…

📅 Published: Aug. 23, 2024, 2:31 p.m. 🔄 Last Modified: Sept. 12, 2024, 6:23 p.m.

8.2

CVSS3.1

CVE-2024-37311 - Collabora Online's remote host TLS certificates are not fully verified

Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolwsd to other hosts may incompletely verify the remote host's certificate's against the full chain of trust. This vulnerability is fixed in Collabora Onl…

📅 Published: Aug. 23, 2024, 2:26 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS4.0

CVE-2024-8113 - Stored XSS in Placeholder Samples in Mail Preview

Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings page. The default Content Security Policy of pretix prevents execution of attacker-provided scripts, making exploitation unlikely. However, comb…

📅 Published: Aug. 23, 2024, 2:18 p.m. 🔄 Last Modified: Sept. 12, 2024, 6:21 p.m.
Total resulsts: 349182
Page 8748 of 34,919
« previous page » next page
Filters