NA - CVE-2024-42363 - Prior to 3385, the user-controlled role...
Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController. The role parameter flows into the RoleConfigFile initializer and then into...
NA - CVE-2024-43396 - Khoj is an application that creates personal AI...
Khoj is an application that creates personal AI agents. The Automation feature allows a user to insert arbitrary HTML inside the task instructions, resulting in a Stored XSS. The q parameter for...
NA - CVE-2024-33872 - Keyfactor Command 10.5.x before 10.5.1 and...
Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of privileges.
NA - CVE-2024-6377 - A reflected Cross-site Scripting (XSS)...
A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in...
NA - CVE-2024-6378 - A reflected Cross-site Scripting (XSS)...
A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to...
NA - CVE-2024-6379 - An URL redirection to untrusted site (open...
An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to...