NA - CVE-2024-51723 - A Stored Cross-Site Scripting (XSS)...
A Stored Cross-Site Scripting (XSS) vulnerability in the Management Console of BlackBerry AtHoc version 7.15 could allow an attacker to potentially execute actions in the context of the...
NA - CVE-2024-52529 - Cilium is a networking, observability, and...
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For users with the following configuration: 1. An allow policy that selects a Layer 3 destination and a...
NA - CVE-2024-52811 - The ngtcp2 project is an effort to implement...
The ngtcp2 project is an effort to implement IETF QUIC protocol in C. In affected versions acks are not validated before being written to the qlog leading to a buffer overflow. In...
NA - CVE-2024-53255 - BoidCMS is a free and open-source flat file CMS...
BoidCMS is a free and open-source flat file CMS for building simple websites and blogs, developed using PHP and uses JSON as a database. In affected versions a reflected Cross-site Scripting (XSS)...
NA - CVE-2024-53599 - A cross-site scripting (XSS) vulnerability in...
A cross-site scripting (XSS) vulnerability in the /scroll.php endpoint of LafeLabs Chaos v0.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
NA - CVE-2024-53258 - Autolab is a course management service that...
Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as long as...
NA - CVE-2024-53261 - SvelteKit is a framework for rapidly developing...
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. "Unsanitized input from *the request URL* flows into `end`, where it is used to render an HTML page...
NA - CVE-2024-53262 - SvelteKit is a framework for rapidly developing...
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static error.html template for errors contains placeholders that are replaced without escaping...
NA - CVE-2024-53268 - Joplin is an open source, privacy-focused note...
Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In affected versions attackers are able to abuse the fact that...
NA - CVE-2024-11670 - Incorrect authorization in the permission...
Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View...