2571
|
- |
|
-
|
-
|
Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService.insertNote`, `ApPersonService.createPerson`, and `ApPersonService.updatePerson…
|
CWE-20
Improper Input Validation
|
CVE-2024-52593
|
2024-12-19 05:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2572
|
- |
|
-
|
-
|
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.update` allows an attacker to modify the result of polls belonging to another us…
|
CWE-20
Improper Input Validation
|
CVE-2024-52592
|
2024-12-19 05:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2573
|
- |
|
-
|
-
|
Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check the target host. This vulnerability allows an attacker to send POST or GET reque…
|
CWE-20 CWE-918
Improper Input Validation Server-Side Request Forgery (SSRF)
|
CVE-2024-52579
|
2024-12-19 05:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2574
|
- |
|
-
|
-
|
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` and `HttpRequestService.getActivityJson` allows an attacker to crea…
|
CWE-20
Improper Input Validation
|
CVE-2024-52591
|
2024-12-19 05:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2575
|
- |
|
-
|
-
|
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` allows an attacker to create fake user profiles that appear to be f…
|
CWE-20
Improper Input Validation
|
CVE-2024-52590
|
2024-12-19 05:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2576
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE NonStop 8.1.0 through 8.1.0.25 could allow an authenticated user to cause a de…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2024-51470
|
2024-12-19 05:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2577
|
- |
|
-
|
-
|
Misskey is an open source, federated social media platform. In affected versions FileServerService (media proxy) in github.com/misskey-dev/misskey 2024.10.1 or earlier did not detect proxy loops, whi…
|
CWE-405 CWE-674
Asymmetric Resource Consumption (Amplification) Uncontrolled Recursion
|
CVE-2024-49363
|
2024-12-19 05:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2578
|
- |
|
-
|
-
|
OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.
|
-
|
CVE-2024-36694
|
2024-12-19 05:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2579
|
- |
|
-
|
-
|
A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially craf…
|
-
|
CVE-2024-12741
|
2024-12-19 05:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2580
|
9.8 |
CRITICAL
Network
gstreamer_project
|
gstreamer
|
GStreamer is a library for constructing graphs of media-handling components. An OOB-Write has been detected in the function gst_parse_vorbis_setup_packet within vorbis_parse.c. The integer size is re…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-47615
|
2024-12-19 04:57 |
2024-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|