2281
|
- |
|
-
|
-
|
The Trix rich text editor, prior to versions 2.1.9 and 1.3.3, is vulnerable to cross-site scripting (XSS) + mutation XSS attacks when pasting malicious code. An attacker could trick a user to copy an…
|
CWE-79
Cross-site Scripting
|
CVE-2024-53847
|
2024-12-10 04:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2282
|
- |
|
-
|
-
|
Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 16.1.99.50 and Tuleap Enterprise Edition prior to version…
|
CWE-79
Cross-site Scripting
|
CVE-2024-52599
|
2024-12-10 04:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2283
|
- |
|
-
|
-
|
eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version 4.6.0 and prior to version 5.1.0 that allows an attacker to bypass eLabFTW's bu…
|
CWE-288 CWE-303
Authentication Bypass Using an Alternate Path or Channel Incorrect Implementation of Authentication Algorithm
|
CVE-2024-52586
|
2024-12-10 04:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2284
|
- |
|
-
|
-
|
User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end.
By exploi…
|
-
|
CVE-2024-12057
|
2024-12-10 04:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2285
|
- |
|
-
|
-
|
A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensi…
|
-
|
CVE-2024-11608
|
2024-12-10 03:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2286
|
- |
|
-
|
-
|
A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code in the context of the current process due to an untruste…
|
-
|
CVE-2024-11454
|
2024-12-10 03:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2287
|
- |
|
-
|
-
|
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash or could lead to an arbitrary m…
|
-
|
CVE-2024-11268
|
2024-12-10 03:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2288
|
- |
|
-
|
-
|
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerabi…
|
CWE-20
Improper Input Validation
|
CVE-2024-45761
|
2024-12-10 02:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2289
|
- |
|
-
|
-
|
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the…
|
CWE-862
Missing Authorization
|
CVE-2024-45760
|
2024-12-10 02:15 |
2024-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2290
|
- |
|
-
|
-
|
The Simple Side Tab WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attack…
|
-
|
CVE-2024-11183
|
2024-12-10 02:15 |
2024-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|