Show filters
896 Total Results
Displaying 131-140 of 896
Sort by:
Attacker Value
Unknown
CVE-2023-52199
Disclosure Date: June 11, 2024 (last updated June 12, 2024)
Missing Authorization vulnerability in Matthias Pfefferle & Automattic ActivityPub.This issue affects ActivityPub: from n/a through 1.0.5.
0
Attacker Value
Unknown
CVE-2024-4088
Disclosure Date: June 05, 2024 (last updated June 12, 2024)
The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disable_fe_assets function in all versions up to, and including, 1.9.2. This makes it possible for authenticated attackers, with subscriber access or above, to change the plugin's settings. Additionally, no nonce check is performed resulting in a CSRF vulnerability.
0
Attacker Value
Unknown
CVE-2024-34766
Disclosure Date: June 03, 2024 (last updated June 04, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic ChaosTheory allows Stored XSS.This issue affects ChaosTheory: from n/a through 1.3.
0
Attacker Value
Unknown
CVE-2024-35229
Disclosure Date: May 27, 2024 (last updated May 28, 2024)
ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. Prior to version 1.3.10, there is a very specific pattern `f(a(),b()); check_if_a_executed_last()` in Yul that exposes a bug in evaluation order of Yul function arguments. This vulnerability has been fixed in version 1.3.10. As a workaround, update and redeploy affected contracts.
0
Attacker Value
Unknown
CVE-2024-5272
Disclosure Date: May 26, 2024 (last updated May 27, 2024)
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by finished.
0
Attacker Value
Unknown
CVE-2024-5270
Disclosure Date: May 26, 2024 (last updated May 27, 2024)
Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check if the email signup configuration option is enabled when a user requests to switch from SAML to Email. This allows the user to switch their authentication mail from SAML to email and possibly edit personal details that were otherwise non-editable and provided by the SAML provider.
0
Attacker Value
Unknown
CVE-2024-36255
Disclosure Date: May 26, 2024 (last updated May 27, 2024)
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist task command as another user via creating and sharing a deceptive post action that unexpectedly runs a slash command in some arbitrary channel.
0
Attacker Value
Unknown
CVE-2024-36241
Disclosure Date: May 26, 2024 (last updated May 27, 2024)
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post contents via the /playbook add slash command
0
Attacker Value
Unknown
CVE-2024-34152
Disclosure Date: May 26, 2024 (last updated May 27, 2024)
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper access control which allows a guest to get the metadata of a public playbook run that linked to the channel they are guest via sending an RHSRuns GraphQL query request to the server
0
Attacker Value
Unknown
CVE-2024-34029
Disclosure Date: May 26, 2024 (last updated May 27, 2024)
Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1 and 8.1.x <= 8.1.12 fail to perform a proper authorization check in the /api/v4/groups/<group-id>/channels/<channel-id>/link endpoint which allows a user to learn the members of an AD/LDAP group that is linked to a team by adding the group to a channel, even if the user has no access to the team.
0