Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In October 2024
In JetBrains YouTrack before 2024.3.47707 potential ReDoS exploit was possible via email header parsing in Helpdesk functionality
CVSS Score
5.3
EPSS Score
0.0
Published
2024-10-28
In JetBrains YouTrack before 2024.3.47707 reflected XSS was possible in Widget API
CVSS Score
5.4
EPSS Score
0.06
Published
2024-10-28
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via vendor URL in App manifest
CVSS Score
4.6
EPSS Score
0.172
Published
2024-10-28
In JetBrains YouTrack before 2024.3.47707 stored XSS was possible via Angular template injection in Hub settings
CVSS Score
4.6
EPSS Score
0.129
Published
2024-10-28
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BuyNowDepot Advanced Online Ordering and Delivery Platform allows PHP Local File Inclusion.This issue affects Advanced Online Ordering and Delivery Platform: from n/a through 2.0.0.
CVSS Score
8.1
EPSS Score
0.015
Published
2024-10-28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Climax Themes Kata Plus allows Stored XSS.This issue affects Kata Plus: from n/a through 1.4.7.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-10-28
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CozyThemes Cozy Blocks allows Stored XSS.This issue affects Cozy Blocks: from n/a through 2.0.18.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-10-28
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mansur Ahamed Woocommerce Quote Calculator allows Blind SQL Injection.This issue affects Woocommerce Quote Calculator: from n/a through 1.1.
CVSS Score
9.3
EPSS Score
0.003
Published
2024-10-28
Authorization Bypass Through User-Controlled Key vulnerability in Meetup allows Privilege Escalation.This issue affects Meetup: from n/a through 0.1.
CVSS Score
9.8
EPSS Score
0.582
Published
2024-10-28
Authentication Bypass Using an Alternate Path or Channel vulnerability in Priyabrata Sarkar Token Login allows Authentication Bypass.This issue affects Token Login: from n/a through 1.0.3.
CVSS Score
8.8
EPSS Score
0.323
Published
2024-10-28


Contact Us

Shodan ® - All rights reserved