Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In April 2024
Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link.
CVSS Score
3.1
EPSS Score
0.004
Published
2024-04-16
In OffloadAMRWriter, a scalar field is not initialized so will contain an arbitrary value left over from earlier computations
CVSS Score
5.8
EPSS Score
0.003
Published
2024-04-16
Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations.
CVSS Score
7.2
EPSS Score
0.003
Published
2024-04-16
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Exclusive Addons Exclusive Addons Elementor allows Stored XSS.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.2.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-04-16
Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted script during markdown file creation.
CVSS Score
6.1
EPSS Score
0.001
Published
2024-04-16
An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted payload to the src component.
CVSS Score
6.1
EPSS Score
0.001
Published
2024-04-16
Cross Site Scripting (XSS) vulnerability in Xunruicms versions 4.6.3 and before, allows remote attacker to execute arbitrary code via the Security.php file in the catalog \XunRuiCMS\dayrui\Fcms\Library.
CVSS Score
6.1
EPSS Score
0.002
Published
2024-04-16
A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval function. Attackers can bypass the intended security mechanism, which checks for the presence of underscores in code generated by LLM, to execute arbitrary code. This is achieved by crafting input that does not contain an underscore but still results in the execution of OS commands. The vulnerability allows for remote code execution (RCE) on the server hosting the application.
CVSS Score
9.8
EPSS Score
0.012
Published
2024-04-16
langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted directory ('Path Traversal') in its LocalFileStore functionality. An attacker can leverage this vulnerability to read or write files anywhere on the filesystem, potentially leading to information disclosure or remote code execution. The issue lies in the handling of file paths in the mset and mget methods, where user-supplied input is not adequately sanitized, allowing directory traversal sequences to reach unintended directories.
CVSS Score
6.5
EPSS Score
0.02
Published
2024-04-16
The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. This vulnerability allows attackers to perform denial of service attacks, access local files, generate network connections, or circumvent firewalls by submitting specially crafted XML data.
CVSS Score
7.5
EPSS Score
0.002
Published
2024-04-16


Contact Us

Shodan ® - All rights reserved