Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In August 2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in petesheppard84 Extensions for Elementor allows Stored XSS.This issue affects Extensions for Elementor: from n/a through 2.0.31.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-08-01
biscuit-java is the java implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, a ThirdPartyBlock request can be sent, providing only the necessary info to generate a third-party block and to sign it, which includes the public key of the previous block (used in the signature) and the public keys part of the token symbol table (for public key interning in datalog expressions). A third-part block request forged by a malicious user can trick the third-party authority into generating datalog trusting the wrong keypair. This vulnerability is fixed in 4.0.0.
CVSS Score
3.0
EPSS Score
0.002
Published
2024-08-01
biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferring the whole token to the third-party authority. Instead, a ThirdPartyBlock request can be sent, providing only the necessary info to generate a third-party block and to sign it, which includes the public key of the previous block (used in the signature) and the public keys part of the token symbol table (for public key interning in datalog expressions). A third-part block request forged by a malicious user can trick the third-party authority into generating datalog trusting the wrong keypair.
CVSS Score
3.0
EPSS Score
0.001
Published
2024-08-01
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lester ‘GaMerZ’ Chan WP-PostRatings allows Stored XSS.This issue affects WP-PostRatings: from n/a through 1.91.1.
CVSS Score
6.5
EPSS Score
0.002
Published
2024-08-01
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Modernaweb Studio Black Widgets For Elementor allows Stored XSS.This issue affects Black Widgets For Elementor: from n/a through 1.3.5.
CVSS Score
6.5
EPSS Score
0.002
Published
2024-08-01
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 4.0.5.
CVSS Score
5.9
EPSS Score
0.002
Published
2024-08-01
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor allows Stored XSS.This issue affects Essential Addons for Elementor: from n/a through 5.9.26.
CVSS Score
6.5
EPSS Score
0.002
Published
2024-08-01
Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.
CVSS Score
5.7
EPSS Score
0.004
Published
2024-08-01
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.
CVSS Score
7.5
EPSS Score
0.007
Published
2024-08-01
Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange
CVSS Score
7.5
EPSS Score
0.001
Published
2024-08-01


Contact Us

Shodan ® - All rights reserved