1161
|
- |
|
-
|
-
|
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account wi…
|
CWE-616 CWE-692
Incomplete Denylist to Cross-Site Scripting
|
CVE-2024-52305
|
2024-11-14 02:01 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1162
|
- |
|
-
|
-
|
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for any user who can edit a page. XSS can impact…
|
CWE-80
Basic XSS
|
CVE-2024-52300
|
2024-11-14 02:01 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1163
|
- |
|
-
|
-
|
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService can access any attachment stored in the wiki as the "key" that is passed to pr…
|
CWE-340
Generation of Predictable Numbers or Identifiers
|
CVE-2024-52299
|
2024-11-14 02:01 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1164
|
- |
|
-
|
-
|
DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and take over services. The JWT secret is hardcoded in the code, and the UID and O…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-52295
|
2024-11-14 02:01 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1165
|
- |
|
-
|
-
|
Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could lead to Remote Code Execution on the server via tw…
|
CWE-22
Path Traversal
|
CVE-2024-52293
|
2024-11-14 02:01 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1166
|
- |
|
-
|
-
|
In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-10013
|
2024-11-14 02:01 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1167
|
- |
|
-
|
-
|
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulnerability.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-10012
|
2024-11-14 02:01 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1168
|
- |
|
-
|
-
|
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The PDF Viewer macro allows an attacker to view any attachment using the "Delegate my view right" feature as long as the attacker…
|
CWE-615
|
CVE-2024-52298
|
2024-11-14 02:01 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1169
|
- |
|
-
|
-
|
Insecure creation of temporary files allows local users on systems with non-default configurations to cause denial of service or set the encryption key for a filesystem
|
CWE-377
Insecure Temporary File
|
CVE-2024-49506
|
2024-11-14 02:01 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1170
|
- |
|
-
|
-
|
grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.
|
-
|
CVE-2024-49504
|
2024-11-14 02:01 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|