NA - CVE-2024-42915 - A host header injection vulnerability in Staff...
A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This will allow...
NA - CVE-2024-43782 - This openedx-translations repository contains...
This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pulling translations from the openedx-translations...
NA - CVE-2024-43791 - RequestStore provides per-request global...
RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows local users...
NA - CVE-2024-8112 - A vulnerability was found in thinkgem JeeSite...
A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown processing of the file /js/a/login of the component Cookie Handler. The...
NA - CVE-2024-8113 - Stored XSS in organizer and event settings of...
Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings page. The default Content Security Policy...
NA - CVE-2024-42364 - Homepage is a highly customizable homepage with...
Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. Homepage is setup without certificate and...