11
|
4.8 |
MEDIUM
Network
|
decidim
|
decidim
|
decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The WYSWYG editor QuillJS is subject to potential XSS attach in case the…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-39910
|
2024-09-29 09:33 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
12
|
6.1 |
MEDIUM
Network
|
rws
|
multitrans
|
Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary web scripts or HTML via a crafted payload.
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-43024
|
2024-09-29 09:27 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
13
|
5.6 |
MEDIUM
Local
|
microsoft
|
windows_11_22h2 windows_11_23h2
|
Windows Kernel Information Disclosure Vulnerability
Update
|
NVD-CWE-noinfo
|
CVE-2024-37985
|
2024-09-29 09:26 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
14
|
4.9 |
MEDIUM
Network
|
ibm
|
business_automation_workflow
|
IBM Business Automation Workflow
22.0.2, 23.0.1, 23.0.2, and 24.0.0
could allow a privileged user to perform unauthorized activities due to improper client side validation.
Update
|
NVD-CWE-Other
|
CVE-2024-43188
|
2024-09-29 09:24 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
15
|
9.0 |
CRITICAL
Network
|
acquia
|
mautic
|
Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged in user of Mautic with the appropriate permiss…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2021-27915
|
2024-09-29 09:22 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
16
|
7.8 |
HIGH
Local
|
apple
|
xcode
|
This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious application may gain access to a user's Keychain items.
Update
|
NVD-CWE-noinfo
|
CVE-2024-44162
|
2024-09-29 09:16 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
17
|
- |
|
-
|
-
|
A vulnerability has been found in SourceCodester Online Timesheet App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /endpoint/add-timesheet.php of the compone…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-9320
|
2024-09-29 09:15 |
2024-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
18
|
- |
|
-
|
-
|
A vulnerability, which was classified as critical, was found in SourceCodester Online Timesheet App 1.0. This affects an unknown part of the file /endpoint/delete-timesheet.php. The manipulation of t…
New
|
-
|
CVE-2024-9319
|
2024-09-29 09:15 |
2024-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
19
|
4.8 |
MEDIUM
Network
|
decidim
|
decidim
|
decidim is a Free Open-Source participatory democracy, citizen participation and open government for cities and organizations. The admin panel is subject to potential Cross-site scripting (XSS) attac…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-32034
|
2024-09-29 09:14 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
20
|
5.9 |
MEDIUM
Network
|
alf
|
alf
|
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, a race condition allows the user to bypass the limit on the number of…
Update
|
CWE-362
Race Condition
|
CVE-2024-45300
|
2024-09-29 09:08 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|