Show filters
2,016 Total Results
Displaying 71-80 of 2,016
Sort by:
Attacker Value
Unknown
CVE-2023-37940
Disclosure Date: December 17, 2024 (last updated January 29, 2025)
Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87, and Liferay DXP 7.4 GA through update 87, 7.3 GA through update 29, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a service access policy's `Service Class` text field.
0
Attacker Value
Unknown
CVE-2024-11993
Disclosure Date: December 17, 2024 (last updated January 29, 2025)
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.1.0 through 7.4.3.38, and Liferay DXP 7.4 GA through update 38, 7.3 GA through update 36, 7.2 GA through fix pack 20 and 7.1 GA through fix pack 28 allows remote attackers to execute arbitrary web script or HTML via Dispatch name field
0
Attacker Value
Unknown
CVE-2024-9654
Disclosure Date: December 17, 2024 (last updated February 08, 2025)
The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within the 'verify_guest_email' function to ensure the requesting user is the intended recipient of the purchase receipt. This makes it possible for unauthenticated attackers to bypass intended security restrictions and view the receipts of other users, which contains a link to download paid content. Successful exploitation requires knowledge of another customers email address as well as the file ID of the content they purchased.
0
Attacker Value
Unknown
CVE-2024-54368
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Ruben Garza, Jr. GitSync allows Code Injection.This issue affects GitSync: from n/a through 1.1.0.
0
Attacker Value
Unknown
CVE-2024-8650
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.
0
Attacker Value
Unknown
CVE-2024-8116
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.
0
Attacker Value
Unknown
CVE-2023-40005
Disclosure Date: December 13, 2024 (last updated February 08, 2025)
Missing Authorization vulnerability in Easy Digital Downloads Easy Digital Downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.1.5.
0
Attacker Value
Unknown
CVE-2024-9387
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.
0
Attacker Value
Unknown
CVE-2024-9367
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2, that allows an attacker to cause uncontrolled CPU consumption, potentially leading to a Denial of Service (DoS) condition while parsing templates to generate changelogs.
0
Attacker Value
Unknown
CVE-2024-8647
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.
0