5.3

CVSS3.1

CVE-2024-6301 - Origin Validation Error in Conduit

Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs

πŸ“… Published: June 25, 2024, 1:02 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

8.1

CVSS3.1

CVE-2024-6302 - Improper Handling of Insufficient Permissions or Privileges in Conduit

Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to redact any message from users on the same server, given that they are able to send redaction events.

πŸ“… Published: June 25, 2024, 1:02 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

9.9

CVSS3.1

CVE-2024-6303 - Missing Authorization in Conduit

Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for privilege escalation by moving the #admins alias to a room which they control, allowing them to run commands resetting passwords, siging json with the…

πŸ“… Published: June 25, 2024, 1:02 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

3.7

CVSS3.1

CVE-2024-6300 - Incomplete Cleanup in Conduit

Incomplete cleanup when performing redactions in Conduit, allowing an attacker to check whether certain strings were present in the PDU before redaction

πŸ“… Published: June 25, 2024, 1:02 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:49 a.m.

6.5

CVSS3.1

CVE-2024-31111 - WordPress Core < 6.5.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.This issue affects WordPress: from 6.5 through 6.5.4, from 6.4 through 6.4.4, from 6.3 through 6.3.4, from 6.2 through 6.2.5, from 6.1 through 6.1.6, f…

πŸ“… Published: June 25, 2024, 12:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2024-5261 - TLS certificate are not properly verified when utilizing LibreOfficeKit

Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice functionality through C/C++. Typically this is used by third party components to reuse LibreOffice as a library to conve…

πŸ“… Published: June 25, 2024, 12:44 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 5:23 p.m.

6.3

CVSS3.1

CVE-2024-4846 -

Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for the 2FA via another browser tab.

πŸ“… Published: June 25, 2024, 12:18 p.m. πŸ”„ Last Modified: March 28, 2025, 4:22 p.m.

4.8

CVSS3.1

CVE-2024-28832 - XSS in Crash Report Page

Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings to execute arbitrary scripts by injecting HTML elements into the Crash Report URL in the Global Settings.

πŸ“… Published: June 25, 2024, 11:45 a.m. πŸ”„ Last Modified: Dec. 4, 2024, 4:15 p.m.

5.4

CVSS3.1

CVE-2024-28831 - XSS in confirmation pop-up

Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injecting HTML elements into some user input fields that are shown in a confirmation pop-up.

πŸ“… Published: June 25, 2024, 11:45 a.m. πŸ”„ Last Modified: Dec. 4, 2024, 4:26 p.m.

6.4

CVSS3.1

CVE-2024-6307 - WordPress Core < 6.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via HTML API

WordPress Core is vulnerable to Stored Cross-Site Scripting via the HTML API in various versions prior to 6.5.5 due to insufficient input sanitization and output escaping on URLs. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web sc…

πŸ“… Published: June 25, 2024, 11:09 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9335 of 34,919
Β« previous page Β» next page
Filters