NA - CVE-2024-47779 - Element is a Matrix web client built using the...
Element is a Matrix web client built using the Matrix React SDK .Element Web versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the...
NA - CVE-2024-47824 - matrix-react-sdk is react-based software...
matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious...
NA - CVE-2024-47874 - Starlette is an Asynchronous Server Gateway...
Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treats `multipart/form-data` parts without a `filename` as text form fields and...
NA - CVE-2024-47876 - Sakai is a Collaboration and Learning...
Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in as a normal user. This can result in...
NA - CVE-2024-48622 - A cross-site scripting (XSS) issue in DomainMOD...
A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter.
NA - CVE-2024-48623 - In queue\index.php of DomainMOD below v4.12.0,...
In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS).
NA - CVE-2024-48624 - In segments\edit.php of DomainMOD below...
In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS) vulnerability.
NA - CVE-2024-48913 - Hono, a web framework, prior to version 4.6.5...
Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although the CSRF middleware verifies...
NA - CVE-2024-48914 - Vendure is an open-source headless commerce...
Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an attacker to craft a request which is able to...