|
305561
|
5.4 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest
|
CWE-79
Cross-site Scripting
|
CVE-2024-50576
|
2024-10-30 02:18 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305562
|
6.1 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
|
CWE-79
Cross-site Scripting
|
CVE-2024-50575
|
2024-10-30 02:18 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305563
|
7.5 |
HIGH
Network
|
informatik.hu-berlin
|
flair
|
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loade…
|
CWE-94
Code Injection
|
CVE-2024-10073
|
2024-10-30 02:18 |
2024-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305564
|
5.4 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag
|
CWE-79
Cross-site Scripting
|
CVE-2024-50581
|
2024-10-30 02:17 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305565
|
5.4 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule
|
CWE-79
Cross-site Scripting
|
CVE-2024-50580
|
2024-10-30 02:17 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305566
|
6.1 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
|
CWE-79
Cross-site Scripting
|
CVE-2024-50579
|
2024-10-30 02:17 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305567
|
5.4 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
|
CWE-79
Cross-site Scripting
|
CVE-2024-50578
|
2024-10-30 02:17 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305568
|
5.4 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements
|
CWE-79
Cross-site Scripting
|
CVE-2024-50582
|
2024-10-30 02:16 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305569
|
7.5 |
HIGH
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2024-50574
|
2024-10-30 02:16 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305570
|
5.4 |
MEDIUM
Network
|
jetbrains
|
hub
|
In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services
|
CWE-862
Missing Authorization
|
CVE-2024-50573
|
2024-10-30 02:12 |
2024-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|