181
|
5.3 |
MEDIUM
Network
neomutt mutt redhat
|
neomutt mutt enterprise_linux
|
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original …
Update
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-49394
|
2024-11-14 22:38 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
182
|
5.3 |
MEDIUM
Network
neomutt mutt redhat
|
neomutt mutt enterprise_linux
|
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
Update
|
NVD-CWE-noinfo
|
CVE-2024-49395
|
2024-11-14 22:33 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
183
|
5.4 |
MEDIUM
Network
|
leevio
|
happy_addons_for_elementor
|
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2024-10538
|
2024-11-14 22:27 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
184
|
- |
|
-
|
-
|
An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious Ja…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-8648
|
2024-11-14 22:15 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
185
|
- |
|
-
|
-
|
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed …
New
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2024-7404
|
2024-11-14 22:15 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
186
|
- |
|
-
|
-
|
A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirec…
New
|
CWE-601
Open Redirect
|
CVE-2024-11207
|
2024-11-14 22:15 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
187
|
- |
|
-
|
-
|
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arb…
New
|
-
|
CVE-2024-10979
|
2024-11-14 22:15 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
188
|
- |
|
-
|
-
|
Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE, SET S…
New
|
-
|
CVE-2024-10978
|
2024-11-14 22:15 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
189
|
- |
|
-
|
-
|
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-…
New
|
-
|
CVE-2024-10977
|
2024-11-14 22:15 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
190
|
- |
|
-
|
-
|
Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction betwe…
New
|
-
|
CVE-2024-10976
|
2024-11-14 22:15 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|