Show filters
896 Total Results
Displaying 151-160 of 896
Sort by:
Attacker Value
Unknown

CVE-2024-34704

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
era-compiler-solidity is the ZKsync compiler for Solidity. The problem occurred during instruction selection in the `DAGCombine` phase while visiting the XOR operation. The issue arises when attempting to fold the expression `!(x cc y)` into `(x !cc y)`. To perform this transformation, the second operand of XOR should be a constant representing the true value. However, it was incorrectly assumed that -1 represents the true value, when in fact, 1 is the correct representation, so this transformation for this case should be skipped. This vulnerability is fixed in 1.4.1.
0
Attacker Value
Unknown

CVE-2024-34549

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic WP Job Manager.This issue affects WP Job Manager: from n/a through 2.2.2.
0
Attacker Value
Unknown

CVE-2024-33953

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt van Andel Adventure Journal allows Stored XSS.This issue affects Adventure Journal: from n/a through 1.7.2.
0
Attacker Value
Unknown

CVE-2024-34078

Disclosure Date: May 06, 2024 (last updated May 07, 2024)
html-sanitizer is an allowlist-based HTML cleaner. If using `keep_typographic_whitespace=False` (which is the default), the sanitizer normalizes unicode to the NFKC form at the end. Some unicode characters normalize to chevrons; this allows specially crafted HTML to escape sanitization. The problem has been fixed in 2.4.2.
0
Attacker Value
Unknown

CVE-2024-1688

Disclosure Date: May 02, 2024 (last updated January 05, 2025)
The Woo Total Sales plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_orders_archive() function in all versions up to, and including, 3.1.4. This makes it possible for unauthenticated attackers to retrieve sales reports for the store.
0
Attacker Value
Unknown

CVE-2024-4198

Disclosure Date: April 26, 2024 (last updated April 26, 2024)
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.
0
Attacker Value
Unknown

CVE-2024-4195

Disclosure Date: April 26, 2024 (last updated April 26, 2024)
Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authenticated as a team admin to promote guests to team admins via crafted HTTP requests.
0
Attacker Value
Unknown

CVE-2024-4183

Disclosure Date: April 26, 2024 (last updated April 26, 2024)
Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the number of active sessions, which allows an authenticated attacker to crash the server via repeated requests to the getSessions API after flooding the sessions table.
0
Attacker Value
Unknown

CVE-2024-4182

Disclosure Date: April 26, 2024 (last updated April 26, 2024)
Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.
0
Attacker Value
Unknown

CVE-2024-32046

Disclosure Date: April 26, 2024 (last updated April 26, 2024)
Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored
0