|
cve-2024-28133
|
7.8 (v3.1)
|
PHOENIX CONTACT: Privilege escalation in CHARX Series
|
PHOENIX CONTACT
|
CHARX SEC-3000
|
2024-05-14T08:09:11.136Z |
2024-08-02T00:48:49.201Z |
|
cve-2024-28113
|
|
Open redirection using the return_url parameter in Pee…
|
peering-manager
|
peering-manager
|
2024-03-12T19:56:01.358Z |
2024-08-02T00:48:49.208Z |
|
cve-2024-28116
|
|
Server-Side Template Injection (SSTI) with Grav CMS se…
|
getgrav
|
grav
|
2024-03-21T21:44:29.489Z |
2024-08-02T00:48:49.256Z |
|
cve-2024-28173
|
4.3 (v3.1)
|
In JetBrains TeamCity between 2023.11 and 2023.11…
|
JetBrains
|
TeamCity
|
2024-03-06T16:52:10.211Z |
2024-08-02T00:48:49.258Z |
|
cve-2024-28134
|
7 (v3.1)
|
PHOENIX CONTACT: MitM attack gains privileges of the c…
|
PHOENIX CONTACT
|
CHARX SEC-3000
|
2024-05-14T08:09:24.900Z |
2024-08-02T00:48:49.289Z |
|
cve-2024-28111
|
|
CSV Injection in exported history CSV files
|
thinkst
|
canarytokens
|
2024-03-06T21:15:02.404Z |
2024-08-02T00:48:49.290Z |
|
cve-2024-28167
|
6.5 (v3.1)
|
Missing Authorization check in SAP Group Reporting Dat…
|
SAP_SE
|
SAP Group Reporting Data Collection (Enter Package Data)
|
2024-04-09T00:55:46.326Z |
2024-08-02T00:48:49.373Z |
|
cve-2024-28179
|
|
Jupyter Server Proxy's Websocket Proxying does not req…
|
jupyterhub
|
jupyter-server-proxy
|
2024-03-20T19:54:38.247Z |
2024-08-02T00:48:49.393Z |
|
cve-2024-28174
|
5.8 (v3.1)
|
In JetBrains TeamCity before 2023.11.4 presigned …
|
JetBrains
|
TeamCity
|
2024-03-06T16:52:10.853Z |
2024-08-02T00:48:49.417Z |
|
cve-2024-28186
|
|
SMTP Mail Credentials Disclosed in Error Log in freescout
|
freescout-helpdesk
|
freescout
|
2024-03-12T19:36:05.964Z |
2024-08-02T00:48:49.423Z |
|
cve-2024-28200
|
9.1 (v3.1)
|
N-central Authentication Bypass
|
N-able
|
N-central
|
2024-07-01T20:49:38.092Z |
2024-08-02T00:48:49.431Z |
|
cve-2024-28230
|
6.5 (v3.1)
|
In JetBrains YouTrack before 2024.1.25893 attachi…
|
JetBrains
|
YouTrack
|
2024-03-07T11:40:00.296Z |
2024-08-02T00:48:49.436Z |
|
cve-2024-28198
|
|
XML external entity (XXE) injection in OpenOLAT
|
OpenOLAT
|
OpenOLAT
|
2024-03-11T19:38:26.088Z |
2024-08-02T00:48:49.441Z |
|
cve-2024-28199
|
|
Cross-site Scripting (XSS) possible with maliciously f…
|
phlex-ruby
|
phlex
|
2024-03-11T22:50:38.789Z |
2024-08-02T00:48:49.443Z |
|
cve-2024-28246
|
|
KaTeX is missing normalization of the protocol in URLs…
|
KaTeX
|
KaTeX
|
2024-03-25T20:00:17.211Z |
2024-08-02T00:48:49.457Z |
|
cve-2024-28106
|
|
phpMyFAQ Stored XSS at FAQ News Content
|
thorsten
|
phpMyFAQ
|
2024-03-25T18:41:58.260Z |
2024-08-02T00:48:49.468Z |
|
cve-2024-28188
|
|
jupyter-scheduler's endpoint is missing authentication
|
jupyter-server
|
jupyter-scheduler
|
2024-05-23T11:54:53.672Z |
2024-08-02T00:48:49.472Z |
|
cve-2024-28191
|
|
Contao may have unencoded insert tags in the frontend
|
contao
|
contao
|
2024-04-09T13:54:22.129Z |
2024-08-02T00:48:49.484Z |
|
cve-2024-28240
|
|
GLPI-Agent's MSI package installation permits local us…
|
glpi-project
|
glpi-agent
|
2024-04-25T16:37:32.215Z |
2024-08-02T00:48:49.487Z |
|
cve-2024-28236
|
|
Insecure Variable Substitution in Vela
|
go-vela
|
worker
|
2024-03-12T20:41:09.271Z |
2024-08-02T00:48:49.488Z |
|
cve-2024-28190
|
|
Contao core bundle vulnerable to cross site scripting …
|
contao
|
contao
|
2024-04-09T13:48:46.324Z |
2024-08-02T00:48:49.506Z |
|
cve-2024-28189
|
|
Judge0 vulnerable to Sandbox Escape Patch Bypass via c…
|
judge0
|
judge0
|
2024-04-18T14:40:29.320Z |
2024-08-02T00:48:49.514Z |
|
cve-2024-28244
|
|
KaTeX's maxExpand bypassed by Unicode sub/superscripts
|
KaTeX
|
KaTeX
|
2024-03-25T19:45:50.907Z |
2024-08-02T00:48:49.553Z |
|
cve-2024-28181
|
|
Arbitrary method invocation turbo_boost-commands
|
hopsoft
|
turbo_boost-commands
|
2024-03-14T17:24:25.460Z |
2024-08-02T00:48:49.558Z |
|
cve-2024-28251
|
|
Cross-site websocket hijacking in Querybook
|
pinterest
|
querybook
|
2024-03-13T23:21:28.115Z |
2024-08-02T00:48:49.563Z |
|
cve-2024-28234
|
|
Contao has insufficient BBCode sanitizer
|
contao
|
contao
|
2024-04-09T13:59:41.300Z |
2024-08-02T00:48:49.568Z |
|
cve-2024-28245
|
|
KaTeX's \includegraphics does not escape filename
|
KaTeX
|
KaTeX
|
2024-03-25T19:53:01.320Z |
2024-08-02T00:48:49.569Z |
|
cve-2024-28235
|
|
Contao possible cookie sharing with external domains w…
|
contao
|
contao
|
2024-04-09T15:50:56.531Z |
2024-08-02T00:48:49.584Z |
|
cve-2024-28248
|
|
Cilium intermittent HTTP policy bypass
|
cilium
|
cilium
|
2024-03-18T21:31:51.318Z |
2024-08-02T00:48:49.593Z |
|
cve-2024-28185
|
|
Judge0 vulnerable to Sandbox Escape via Symbolic Link
|
judge0
|
judge0
|
2024-04-18T14:31:16.326Z |
2024-08-02T00:48:49.601Z |