Show filters
248 Total Results
Displaying 31-40 of 248
Sort by:
Attacker Value
Unknown

CVE-2024-50578

Disclosure Date: October 28, 2024 (last updated February 26, 2025)
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
Attacker Value
Unknown

CVE-2024-50577

Disclosure Date: October 28, 2024 (last updated February 26, 2025)
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
Attacker Value
Unknown

CVE-2024-50576

Disclosure Date: October 28, 2024 (last updated February 26, 2025)
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest
Attacker Value
Unknown

CVE-2024-50575

Disclosure Date: October 28, 2024 (last updated February 26, 2025)
In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
Attacker Value
Unknown

CVE-2024-50574

Disclosure Date: October 28, 2024 (last updated February 26, 2025)
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality
Attacker Value
Unknown

CVE-2023-6080

Disclosure Date: October 18, 2024 (last updated February 26, 2025)
Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnerability which allows attackers SYSTEM level access.
Attacker Value
Unknown

CVE-2024-49579

Disclosure Date: October 17, 2024 (last updated February 26, 2025)
In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated February 26, 2025)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2024-48902

Disclosure Date: October 10, 2024 (last updated February 26, 2025)
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API
Attacker Value
Unknown

CVE-2024-47162

Disclosure Date: September 19, 2024 (last updated February 26, 2025)
In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page