NA - CVE-2024-43789 - Discourse is an open source platform for...
Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all at once. This can potentially reduce the availability...
NA - CVE-2024-45051 - Discourse is an open source platform for...
Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access to private sites,...
NA - CVE-2024-45060 - PHPSpreadsheet is a pure PHP library for...
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. One of the sample scripts in PhpSpreadsheet is susceptible to a cross-site scripting (XSS) vulnerability due to...
NA - CVE-2024-45290 - PHPSpreadsheet is a pure PHP library for...
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file which links media from external URLs. When opening the...
NA - CVE-2024-45291 - PHPSpreadsheet is a pure PHP library for...
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links images from arbitrary paths. When embedding...
NA - CVE-2024-45297 - Discourse is an open source platform for...
Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. This issue has been patched in the latest stable, beta...
NA - CVE-2024-45919 - A security flaw has been discovered in Solvait...
A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the Request ID and Action Type parameters in...
NA - CVE-2024-47610 - InvenTree is an Open Source Inventory...
InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for a registered user to store javascript in markdown notes fields, which are then...
NA - CVE-2024-47772 - Discourse is an open source platform for...
Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by sending a maliciously crafted chat message and replying to it....