|
249831
|
- |
|
-
|
-
|
symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metachar…
|
CWE-20
Improper Input Validation
|
CVE-2024-50343
|
2024-11-9 04:01 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249832
|
- |
|
-
|
-
|
symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, so…
|
CWE-200
Information Exposure
|
CVE-2024-50342
|
2024-11-9 04:01 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249833
|
- |
|
-
|
-
|
symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom `user_checker` define…
|
-
|
CVE-2024-50341
|
2024-11-9 04:01 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249834
|
- |
|
-
|
-
|
symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any…
|
CWE-74
Injection
|
CVE-2024-50340
|
2024-11-9 04:01 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249835
|
- |
|
-
|
-
|
A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.
|
-
|
CVE-2024-10941
|
2024-11-9 04:01 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249836
|
- |
|
-
|
-
|
A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unknown processing of the file /toggle_fold_panel.php of the component Tabelas Sec…
|
CWE-79 CWE-74
Cross-site Scripting Injection
|
CVE-2024-10926
|
2024-11-9 04:01 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249837
|
- |
|
-
|
-
|
RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission of the user. Users who had…
|
CWE-284
Improper Access Control
|
CVE-2024-51988
|
2024-11-9 04:01 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249838
|
- |
|
-
|
-
|
happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom prior to 15.10.2 may execute code on the host via a script tag. This would execut…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-51757
|
2024-11-9 04:01 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249839
|
- |
|
-
|
-
|
Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property polic…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2024-51755
|
2024-11-9 04:01 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249840
|
- |
|
-
|
-
|
Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of …
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2024-51754
|
2024-11-9 04:01 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|