Show filters
961 Total Results
Displaying 81-90 of 961
Sort by:
Attacker Value
Unknown

CVE-2024-50575

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
Attacker Value
Unknown

CVE-2024-50574

Disclosure Date: October 28, 2024 (last updated October 30, 2024)
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality
Attacker Value
Unknown

CVE-2024-49617

Disclosure Date: October 20, 2024 (last updated October 23, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Bhaskar Dhote Back Link Tracker allows Blind SQL Injection.This issue affects Back Link Tracker: from n/a through 1.0.0.
Attacker Value
Unknown

CVE-2023-6080

Disclosure Date: October 18, 2024 (last updated October 31, 2024)
Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnerability which allows attackers SYSTEM level access.
Attacker Value
Unknown

CVE-2024-49224

Disclosure Date: October 18, 2024 (last updated October 22, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mahesh Patel Mitm Bug Tracker allows Reflected XSS.This issue affects Mitm Bug Tracker: from n/a through 1.0.
Attacker Value
Unknown

CVE-2024-49579

Disclosure Date: October 17, 2024 (last updated November 15, 2024)
In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2024-21280

Disclosure Date: October 15, 2024 (last updated October 22, 2024)
Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Authoring). Supported versions that are affected are 12.2.5-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Contracts. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Service Contracts accessible data as well as unauthorized access to critical data or complete access to all Oracle Service Contracts accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Attacker Value
Unknown

CVE-2024-47877

Disclosure Date: October 11, 2024 (last updated January 05, 2025)
Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symlink outside the extraction target directory. This vulnerability is fixed in 4.0.0. If you're using the Extractor.FS interface, then upgrading to /v4 will require to implement the new methods that have been added.
Attacker Value
Unknown

CVE-2024-48902

Disclosure Date: October 10, 2024 (last updated October 17, 2024)
In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via API