Show filters
248 Total Results
Displaying 51-60 of 248
Sort by:
Attacker Value
Unknown

CVE-2024-28229

Disclosure Date: March 07, 2024 (last updated February 26, 2025)
In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles
Attacker Value
Unknown

CVE-2024-28228

Disclosure Date: March 07, 2024 (last updated February 26, 2025)
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible
Attacker Value
Unknown

CVE-2023-5041

Disclosure Date: January 17, 2024 (last updated February 26, 2025)
The Track The Click WordPress plugin before 0.3.12 does not properly sanitize query parameters to the stats REST endpoint before using them in a database query, allowing a logged in user with an author role or higher to perform time based blind SQLi attacks on the database.
Attacker Value
Unknown

CVE-2024-22370

Disclosure Date: January 09, 2024 (last updated February 25, 2025)
In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible
Attacker Value
Unknown

CVE-2023-49188

Disclosure Date: December 15, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZealousWeb Track Geolocation Of Users Using Contact Form 7 allows Stored XSS.This issue affects Track Geolocation Of Users Using Contact Form 7: from n/a through 2.0.
Attacker Value
Unknown

CVE-2023-50871

Disclosure Date: December 15, 2023 (last updated February 25, 2025)
In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed
Attacker Value
Unknown

CVE-2023-38068

Disclosure Date: July 12, 2023 (last updated February 25, 2025)
In JetBrains YouTrack before 2023.1.16597 captcha was not properly validated for Helpdesk forms
Attacker Value
Unknown

CVE-2023-35054

Disclosure Date: June 12, 2023 (last updated February 25, 2025)
In JetBrains YouTrack before 2023.1.10518 stored XSS in a Markdown-rendering engine was possible
Attacker Value
Unknown

CVE-2023-35053

Disclosure Date: June 12, 2023 (last updated February 25, 2025)
In JetBrains YouTrack before 2023.1.10518 a DoS attack was possible via Helpdesk forms
Attacker Value
Unknown

CVE-2022-39351

Disclosure Date: October 25, 2022 (last updated February 24, 2025)
Dependency-Track is a Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Prior to version 4.6.0, performing an API request using a valid API key with insufficient permissions causes the API key to be written to Dependency-Track's audit log in clear text. Actors with access to the audit log can exploit this flaw to gain access to valid API keys. The issue has been fixed in Dependency-Track 4.6.0. Instead of logging the entire API key, only the last 4 characters of the key will be logged. It is strongly recommended to check historic logs for occurrences of this behavior, and re-generating API keys in case of leakage.