|
312601
|
- |
|
-
|
-
|
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep elements that have same local name attributes. If you need to parse untru…
|
-
|
CVE-2024-43398
|
2024-08-24 01:18 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312602
|
3.7 |
LOW
Network
|
mattermost
|
mattermost
|
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2024-32939
|
2024-08-24 01:17 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312603
|
6.5 |
MEDIUM
Network
|
mattermost
|
mattermost
|
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or reset passwords, which allows the munged …
|
NVD-CWE-noinfo
|
CVE-2024-39836
|
2024-08-24 01:16 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312604
|
4.9 |
MEDIUM
Network
|
mattermost
|
mattermost
|
Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which allows a System Role with access to the Elasticsear…
|
NVD-CWE-noinfo
|
CVE-2024-39810
|
2024-08-24 01:16 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312605
|
9.8 |
CRITICAL
Network
|
lopalopa
|
music_management_system
|
A SQL injection vulnerability in "/music/ajax.php?action=find_music" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "search" parameter.
|
CWE-89
SQL Injection
|
CVE-2024-42782
|
2024-08-24 01:16 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312606
|
9.8 |
CRITICAL
Network
|
lopalopa
|
music_management_system
|
A SQL injection vulnerability in "/music/ajax.php?action=login" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email para…
|
CWE-89
SQL Injection
|
CVE-2024-42781
|
2024-08-24 01:15 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312607
|
6.3 |
MEDIUM
Network
|
youdiancms
|
youdiancms
|
A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the function curl_exec of the file /App/Core/Extend/Function/ydLib.php. The manipulation o…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-7330
|
2024-08-24 01:12 |
2024-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312608
|
8.8 |
HIGH
Network
|
lopalopa
|
music_management_system
|
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a c…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-42780
|
2024-08-24 01:10 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312609
|
8.8 |
HIGH
Network
|
mattermost
|
mattermost
|
Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-sid…
|
CWE-352
Origin Validation Error
|
CVE-2024-40886
|
2024-08-24 01:09 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312610
|
8.8 |
HIGH
Network
|
lopalopa
|
music_management_system
|
An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a c…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-42779
|
2024-08-24 01:09 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|