NA - CVE-2024-42009 - A Cross-Site Scripting vulnerability in...
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a...
NA - CVE-2024-42010 - mod_css_styles in Roundcube through 1.5.7 and...
mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote...
NA - CVE-2024-6361 - Improper Neutralization vulnerability (XSS) has...
Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all version prior to version 23.4. The vulnerability could cause remote code...
NA - CVE-2024-41816 - Cooked is a recipe plugin for WordPress. The...
Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the ‘[cooked-timer]’ shortcode in versions up to, and including,...
NA - CVE-2024-41820 - Kubean is a cluster lifecycle management...
Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has `*` verbs of `*` resources. If a malicious user can access the worker node...
NA - CVE-2024-41958 - mailcow: dockerized is an open source...
mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the two-factor authentication (2FA) mechanism. This flaw allows an authenticated...
NA - CVE-2024-41959 - mailcow: dockerized is an open source...
mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a JavaScript payload into the API logs. This payload is executed whenever the API...
NA - CVE-2024-41960 - mailcow: dockerized is an open source...
mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a JavaScript payload into the Relay Hosts configuration. The injected payload is...
NA - CVE-2024-42350 - Biscuit is an authorization token with...
Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforcement based on a logic language. Third-party blocks can be generated without...
NA - CVE-2024-6915 - JFrog Artifactory versions below 7.90.6,...
JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.