5.5
CVE-2023-49676 - CODESYS: Use after free vulnerability through corrupted project files
An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability.
7.8
CVE-2023-49675 - CODESYS: Out-of-bounds write through corrupted project files
An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash the system due to an out-of-bounds write vulnerability.
6.4
CVE-2023-6854 - Breakdance <= 1.7.0 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom postmeta
The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output in all versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping on user supplied post meta fields. This makes it possible for authenticated…
5.3
CVE-2024-23193 -
E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same service node could access other users E-Mails in case they were exported as PDF for a brief moment until caches were cleared. Successful exploitation req…
6.5
CVE-2024-23188 -
Maliciously crafted E-Mail attachment names could be used to temporarily execute script code in the context of the users browser session. Common user interaction is required for the vulnerability to trigger. Attackers could perform malicious API requests or extract information from the users accoun…
6.5
CVE-2024-23187 -
Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers could perform malicious API requests or extract information from the users account. Exploiting the vulnerability requires user interaction. Please deplo…
6.5
CVE-2024-23186 -
E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could perform malicious API requests or extract information from the users account. Please deploy the provided updates and patch releases. We now use safer m…
2.4
CVE-2024-4528 - SourceCodester Prison Management System user-record.php cross site scripting
A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /Admin/user-record.php. The manipulation of the argument txtfullname leads to cross site scripting. The attack can be…
3.5
CVE-2024-4527 - Campcodes Complete Web-Based School Management System student_payment_details2.php cross site scrip…
A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /view/student_payment_details2.php. The manipulation of the argument index leads to cross site scripting. It is possible to laun…
3.5
CVE-2024-4526 - Campcodes Complete Web-Based School Management System student_payment_details3.php cross site scrip…
A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /view/student_payment_details3.php. The manipulation of the argument month leads to cross site scripting. The attack may be in…