NA - CVE-2024-31842 - An issue was discovered in Italtel Embrace...
An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string for the URL could be saved in the...
NA - CVE-2024-41659 - memos is a privacy-first, lightweight...
memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials...
NA - CVE-2024-6337 - An Incorrect Authorization vulnerability was...
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: read and pull_request_write: write permissions to read issue content...
NA - CVE-2024-6800 - An XML signature wrapping vulnerability was...
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when utilizing SAML authentication with specific identity providers. This vulnerability allowed an attacker...
NA - CVE-2024-7711 - An Incorrect Authorization vulnerability was...
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, assignees, and labels of any issue inside a public repository. This...
NA - CVE-2024-41657 - Casdoor is a UI-first Identity and Access...
Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows...
NA - CVE-2024-41658 - Casdoor is a UI-first Identity and Access...
Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, he purchase URL that is created to generate a WechatPay QR code is...
NA - CVE-2024-42361 - Hertzbeat is an open source, real-time...
Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoint to download job metrics. In the process, it...
NA - CVE-2024-42362 - Hertzbeat is an open source, real-time...
Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0.