CVE-2024-4499

A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS policy. The vulnerability allows attackers to perform unauthorized actions ...

Continue Reading
CVE-2024-4499

A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS policy. The vulnerability allows attackers to perform unauthorized actions ...

Continue Reading
CVE-2024-28397

An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call. Notes Author| Note ---|--- rodrigo-zaiden | python-cloudscrap ...

Continue Reading
CVE-2024-28397

An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call. Notes Author| Note ---|--- rodrigo-zaiden | python-cloudscrap ...

Continue Reading
CVE-2024-38361

Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Use of an exclusion under an arrow that has multiple resources ...

Continue Reading
CVE-2024-5791 Appointment Booking and Online Scheduling <= 4.4.2 – Missing Authorization to Unauthenticated Stored Cross-Site Scripting

The Online Booking &amp; Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_id' parameter in all versions up to, and ...

Continue Reading
CVE-2024-5791

The Online Booking &amp; Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_id' parameter in all versions up to, and ...

Continue Reading
CVE-2024-5791

The Online Booking &amp; Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_id' parameter in all versions up to, and ...

Continue Reading

Back to Main

Subscribe for the latest news: