5.4

CVSS3.1

CVE-2024-1097 - Stored XSS in craigk5n/webcalendar

A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs in the 'Report Name' input field while creating a new report. An attacker can inject malicious scripts, which are then executed in the context of other users who view the report,…

πŸ“… Published: Nov. 15, 2024, 10:57 a.m. πŸ”„ Last Modified: Nov. 19, 2024, 7:05 p.m.

6.8

CVSS3.1

CVE-2021-3740 - Session Fixation in chatwoot/chatwoot

A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes their password, allowing old sessions to persist. This can lead to unauthorized access if an attacker has obtained a sessi…

πŸ“… Published: Nov. 15, 2024, 10:57 a.m. πŸ”„ Last Modified: July 10, 2025, 4:31 p.m.

4.6

CVSS3.1

CVE-2024-1240 - Open Redirection in pyload/pyload

An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling of the 'next' parameter in the login functionality. An attacker can exploit this vulnerability to redirect users to malicious sites, which can be used for phishing or other malicio…

πŸ“… Published: Nov. 15, 2024, 10:57 a.m. πŸ”„ Last Modified: Nov. 19, 2024, 7:04 p.m.

5.3

CVSS3.1

CVE-2024-0787 - Improper Restriction of Excessive Authentication Attempts in phpipam/phpipam

phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X-Forwarded-For' header. The issue lies in the 'get_user_ip()' function in 'class.Common.php' at lines 1044 and 1045, where the presence of the 'X-Forw…

πŸ“… Published: Nov. 15, 2024, 10:57 a.m. πŸ”„ Last Modified: Nov. 19, 2024, 3:53 p.m.

5.9

CVSS3.1

CVE-2023-4679 - Use After Free in gpac/gpac

A use after free vulnerability exists in GPAC version 2.3-DEV-revrelease, specifically in the gf_filterpacket_del function in filter_core/filter.c at line 38. This vulnerability can lead to a double-free condition, which may cause the application to crash.

πŸ“… Published: Nov. 15, 2024, 10:53 a.m. πŸ”„ Last Modified: Nov. 19, 2024, 3:54 p.m.

6.5

CVSS3.1

CVE-2023-0737 - CSRF in wallabag/wallabag

wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This issue is fixed in version 2.5.4.

πŸ“… Published: Nov. 15, 2024, 10:53 a.m. πŸ”„ Last Modified: Nov. 20, 2024, 10:30 p.m.

10

CVSS3.1

CVE-2022-1884 - Remote Command Execution in gogs/gogs

A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the `tree_path` parameter during file uploads. An attacker can set `tree_path=.git.` to upload a file into the .git directory, all…

πŸ“… Published: Nov. 15, 2024, 10:53 a.m. πŸ”„ Last Modified: Nov. 19, 2024, 2:47 p.m.

4.3

CVSS3.1

CVE-2021-3991 - Improper Authorization in dolibarr/dolibarr

An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.

πŸ“… Published: Nov. 15, 2024, 10:52 a.m. πŸ”„ Last Modified: Nov. 19, 2024, 3:31 p.m.

6.1

CVSS3.1

CVE-2021-3988 - Cross-site Scripting (XSS) in janeczku/calibre-web

A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file `edit_books.js`. The vulnerability occurs when editing book properties, such as uploading a cover or a format. The affected code directly inserts user input into the DOM without proper sanitization, …

πŸ“… Published: Nov. 15, 2024, 10:52 a.m. πŸ”„ Last Modified: Nov. 20, 2024, 10:35 p.m.

4.3

CVSS3.1

CVE-2021-3987 - Improper Access Control in janeczku/calibre-web

An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not verifying if the user has the necessary permissions to create…

πŸ“… Published: Nov. 15, 2024, 10:52 a.m. πŸ”„ Last Modified: Nov. 19, 2024, 3:44 p.m.
Total resulsts: 349182
Page 7863 of 34,919
Β« previous page Β» next page
Filters