Show filters
961 Total Results
Displaying 71-80 of 961
Sort by:
Attacker Value
Unknown

CVE-2024-51607

Disclosure Date: November 09, 2024 (last updated November 09, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Buddy Lindsey Golf Tracker allows SQL Injection.This issue affects Golf Tracker: from n/a through 0.7.
0
Attacker Value
Unknown

CVE-2024-43343

Disclosure Date: November 01, 2024 (last updated November 13, 2024)
Missing Authorization vulnerability in Etoile Web Design Order Tracking allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Order Tracking: from n/a through 3.3.12.
Attacker Value
Unknown

CVE-2024-50411

Disclosure Date: October 29, 2024 (last updated November 08, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kevon Adonis WP Abstracts allows Stored XSS.This issue affects WP Abstracts: from n/a through 2.7.1.
Attacker Value
Unknown

CVE-2024-50582

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements
Attacker Value
Unknown

CVE-2024-50581

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag
Attacker Value
Unknown

CVE-2024-50580

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule
Attacker Value
Unknown

CVE-2024-50579

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
Attacker Value
Unknown

CVE-2024-50578

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
Attacker Value
Unknown

CVE-2024-50577

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
Attacker Value
Unknown

CVE-2024-50576

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest