NA - CVE-2023-0109 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a JavaScript file containing a malicious script and...
NA - CVE-2023-0737 - wallabag version 2.5.2 contains a Cross-Site...
wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This issue is fixed in...
NA - CVE-2023-2332 - A stored Cross-site Scripting (XSS)...
A stored Cross-site Scripting (XSS) vulnerability exists in the Conditions tab of Pricing Rules in pimcore/pimcore versions 10.5.19. The vulnerability is present in the From and To fields of the...
NA - CVE-2023-4679 - A use after free vulnerability exists in GPAC...
A use after free vulnerability exists in GPAC version 2.3-DEV-revrelease, specifically in the gf_filterpacket_del function in filter_core/filter.c at line 38. This vulnerability can lead to a...
NA - CVE-2024-0787 - phpIPAM version 1.5.1 contains a vulnerability...
phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X-Forwarded-For' header. The issue lies...
NA - CVE-2024-0875 - A stored cross-site scripting (XSS)...
A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messaging...
NA - CVE-2024-10443 - Improper neutralization of special elements...
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and...
NA - CVE-2024-10534 - Origin Validation Error vulnerability in...
Origin Validation Error vulnerability in Dataprom Informatics Personnel Attendance Control Systems (PACS) / Access Control Security Systems (ACSS) allows Traffic Injection.This issue affects...
NA - CVE-2024-11182 - An XSS issue was discovered in
MDaemon Email...
An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to...