Show filters
890 Total Results
Displaying 51-60 of 890
Sort by:
Attacker Value
Unknown

CVE-2024-21541

Disclosure Date: November 13, 2024 (last updated January 14, 2025)
Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function generates a new function body and thus care must be given to ensure that the inputs to Function are not attacker-controlled. The risks involved are similar to that of allowing attacker-controlled input to reach eval.
Attacker Value
Unknown

CVE-2024-51573

Disclosure Date: November 11, 2024 (last updated November 11, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Matthew Lillistone ML Responsive Audio player with playlist Shortcode allows Stored XSS.This issue affects ML Responsive Audio player with playlist Shortcode: from n/a through 0.2.
0
Attacker Value
Unknown

CVE-2024-52032

Disclosure Date: November 09, 2024 (last updated November 15, 2024)
Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch when searching for the channel name in channel switcher which allows an attacker to get private channels names of channels that they are not a member of, when Elasticsearch v8 was enabled.
Attacker Value
Unknown

CVE-2024-42000

Disclosure Date: November 09, 2024 (last updated November 15, 2024)
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/channels  which allows a User or System Manager, with "Read Groups" permission but with no access for channels to retrieve details about private channels that they were not a member of by sending a request to /api/v4/channels.
Attacker Value
Unknown

CVE-2024-36250

Disclosure Date: November 09, 2024 (last updated November 15, 2024)
Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds
Attacker Value
Unknown

CVE-2024-43208

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Miller Media ( Matt Miller ) Send Emails with Mandrill allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Send Emails with Mandrill: from n/a through 1.4.1.
0
Attacker Value
Unknown

CVE-2024-37477

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Automattic Newspack Content Converter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack Content Converter: from n/a through 0.1.5.
0
Attacker Value
Unknown

CVE-2024-37475

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Automattic Newspack Newsletters allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Newspack Newsletters: from n/a through 2.13.2.
0
Attacker Value
Unknown

CVE-2024-37443

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Automattic WP Job Manager - Resume Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Manager - Resume Manager: from n/a through 2.1.0.
0
Attacker Value
Unknown

CVE-2024-37425

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Automattic Newspack Blocks newspack-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newspack Blocks: from n/a through 3.0.8.
0