|
250171
|
5.4 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule
|
CWE-79
Cross-site Scripting
|
CVE-2024-50580
|
2024-10-30 02:17 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250172
|
6.1 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
|
CWE-79
Cross-site Scripting
|
CVE-2024-50579
|
2024-10-30 02:17 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250173
|
5.4 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
|
CWE-79
Cross-site Scripting
|
CVE-2024-50578
|
2024-10-30 02:17 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250174
|
5.4 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements
|
CWE-79
Cross-site Scripting
|
CVE-2024-50582
|
2024-10-30 02:16 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250175
|
7.5 |
HIGH
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2024-50574
|
2024-10-30 02:16 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250176
|
5.4 |
MEDIUM
Network
|
jetbrains
|
hub
|
In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services
|
CWE-862
Missing Authorization
|
CVE-2024-50573
|
2024-10-30 02:12 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250177
|
4.8 |
MEDIUM
Network
|
villatheme
|
woocommerce_email_template_customizer
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VillaTheme Email Template Customizer for WooCommerce allows Stored XSS.This issue affects …
|
CWE-79
Cross-site Scripting
|
CVE-2024-49288
|
2024-10-30 01:59 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250178
|
5.4 |
MEDIUM
Network
|
tiandiyoyo
|
flat_ui_button
|
The Flat UI Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's flatbtn shortcode in version 1.0 due to insufficient input sanitization and output escaping on us…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10014
|
2024-10-30 01:58 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250179
|
- |
|
-
|
-
|
QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a spoofed IP address. This can bypass the IP allow/block list functionality.
|
-
|
CVE-2024-49214
|
2024-10-30 01:35 |
2024-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250180
|
- |
|
-
|
-
|
Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injectio…
|
-
|
CVE-2024-44667
|
2024-10-30 01:35 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|