6.1
CVE-2024-27184 - [20240801] - Core - Inadequate validation of internal URLs
Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
6.1
CVE-2024-40743 - [20240805] - Core - XSS vectors in Outputfilter::strip* methods
The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
7.5
CVE-2024-27187 - [20240804] - Core - Improper ACL for backend profile view
Improper Access Controls allows backend users to overwrite their username when disallowed.
6.5
CVE-2024-43409 - Ghost's improper authentication allows access to member information and actions
Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information. This security vulnerability is present in Ghost v4.46.0-v5.89.4. v5.89.5 contains a fix for this issue.
8.8
CVE-2024-43406 - LF Edge eKuiper has a SQL Injection in sqlKvStore
LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.
9.8
CVE-2024-43404 - Remote Code Execution Vulnerability in MEGABOT
MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT versions < 1.5.0 contains a remote code execution vulnerability due to a Python `eval()`. The vulnerability allows an attacker to inject Python code into the `expression` parameter when โฆ
4.3
CVE-2024-43397 - Potential unauthorized access issue in apollo-portal
Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that allows users to craft specific requests to bypass permission checks. This exploit enables them to modify a namespace without the necessary permissions. The issue was addressed with โฆ
5.4
CVE-2024-43377 - Umbraco CMS Improper Access Control vulnerability
Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.2.
4.3
CVE-2024-43376 - Umbraco CMS vulnerable to Generation of Error Message Containing Sensitive Information
Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode. This vulnerability is fixed in 14.1.2.
4.1
CVE-2024-42369 - A room with itself as a its predecessor will freeze matrix-js-sdk
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. The matrix-js-sdk's getRoomUpgradeHistory function will infinitely recurse in this case, causing the code to hang. This mโฆ