Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In October 2024
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=delAdmin&id=17
CVSS Score
6.3
EPSS Score
0.0
Published
2024-10-28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Post Grid Team by WPXPO PostX allows Stored XSS.This issue affects PostX: from n/a through 4.1.12.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-10-28
A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in expressions for encrypted fields to be sent to the server as plaintext instead of ciphertext. Should this occur, no documents would be returned or written. This issue affects mongocryptd binary (v5.0 versions prior to 5.0.29, v6.0 versions prior to 6.0.17, v7.0 versions prior to 7.0.12 and v7.3 versions prior to 7.3.4) and mongo_crypt_v1.so shared libraries (v6.0 versions prior to 6.0.17, v7.0 versions prior to 7.0.12 and v7.3 versions prior to 7.3.4) released alongside MongoDB Enterprise Server versions.
CVSS Score
2.2
EPSS Score
0.0
Published
2024-10-28
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via sprint value on agile boards page
CVSS Score
4.6
EPSS Score
0.177
Published
2024-10-28
In JetBrains YouTrack before 2024.3.47707 reflected XSS due to insecure link sanitization was possible
CVSS Score
4.6
EPSS Score
0.067
Published
2024-10-28
In JetBrains YouTrack before 2024.3.47707 multiple XSS were possible due to insecure markdown parsing and custom rendering rule
CVSS Score
4.6
EPSS Score
0.177
Published
2024-10-28
In JetBrains YouTrack before 2024.3.47707 improper HTML sanitization could lead to XSS attack via comment tag
CVSS Score
4.6
EPSS Score
0.177
Published
2024-10-28
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible due to improper HTML sanitization in markdown elements
CVSS Score
4.6
EPSS Score
0.177
Published
2024-10-28
In JetBrains Hub before 2024.3.47707 improper access control allowed users to generate permanent tokens for unauthorized services
CVSS Score
4.3
EPSS Score
0.0
Published
2024-10-28
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality
CVSS Score
5.3
EPSS Score
0.0
Published
2024-10-28


Contact Us

Shodan ® - All rights reserved