|
250161
|
2.3 |
LOW
Local
|
apple
|
macos iphone_os ipados
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, iOS 18 and iPadOS 18. A malicious app with root privileges may be able to access keyboard inpu…
|
NVD-CWE-noinfo
|
CVE-2024-44123
|
2024-10-30 02:37 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250162
|
- |
|
-
|
-
|
Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` function. The vulnerability is due to improper sanitization of user input in the …
|
-
|
CVE-2024-41618
|
2024-10-30 02:35 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250163
|
- |
|
-
|
-
|
Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to Incorrect Access Control. The `redirect_if_not_loggedin` function in `functions_security.php` fails to terminate script execution…
|
-
|
CVE-2024-41617
|
2024-10-30 02:35 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250164
|
6.5 |
MEDIUM
Network
|
apple
|
macos watchos safari iphone_os ipados
|
A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 18, iOS 17.7.1 and iPadOS 17.7.1, macOS Sequoia 15, watchOS 11, iOS 18 and iPadOS 18. Ma…
|
NVD-CWE-noinfo
|
CVE-2024-44155
|
2024-10-30 02:34 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250165
|
5.5 |
MEDIUM
Local
|
apple
|
watchos tvos iphone_os ipados macos
|
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, macOS Sequoia 15, macOS Sonoma 14.7.1, tvOS 18, watchOS 11, visionOS 2, iOS 18 and …
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-44144
|
2024-10-30 02:34 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250166
|
5.4 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
|
CWE-79
Cross-site Scripting
|
CVE-2024-50577
|
2024-10-30 02:18 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250167
|
5.4 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest
|
CWE-79
Cross-site Scripting
|
CVE-2024-50576
|
2024-10-30 02:18 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250168
|
6.1 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
|
CWE-79
Cross-site Scripting
|
CVE-2024-50575
|
2024-10-30 02:18 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250169
|
7.5 |
HIGH
Network
|
informatik.hu-berlin
|
flair
|
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loade…
|
CWE-94
Code Injection
|
CVE-2024-10073
|
2024-10-30 02:18 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250170
|
5.4 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag
|
CWE-79
Cross-site Scripting
|
CVE-2024-50581
|
2024-10-30 02:17 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|