Vulnerabilities > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-12-12 | CVE-2024-54111 | Unspecified vulnerability in Huawei Harmonyos 5.0.0 Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability. | 7.5 |
2024-12-12 | CVE-2024-54112 | Unspecified vulnerability in Huawei Harmonyos 5.0.0 Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | 7.5 |
2024-12-12 | CVE-2024-54113 | Unspecified vulnerability in Huawei Harmonyos 5.0.0 Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect power consumption. | 7.5 |
2024-12-12 | CVE-2024-54114 | Out-of-bounds Read vulnerability in Huawei Harmonyos 5.0.0 Out-of-bounds access vulnerability in playback in the DASH module Impact: Successful exploitation of this vulnerability will affect availability. | 7.5 |
2024-12-12 | CVE-2024-54115 | Out-of-bounds Read vulnerability in Huawei Harmonyos 5.0.0 Out-of-bounds read vulnerability in the DASH module Impact: Successful exploitation of this vulnerability will affect availability. | 7.5 |
2024-12-12 | CVE-2024-54116 | Out-of-bounds Read vulnerability in Huawei Harmonyos 5.0.0 Out-of-bounds read vulnerability in the M3U8 module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally. | 7.5 |
2024-12-12 | CVE-2024-54117 | Unspecified vulnerability in Huawei Harmonyos 5.0.0 Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | 7.5 |
2024-12-12 | CVE-2024-12397 | A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. | 7.4 |
2024-12-12 | CVE-2024-12312 | The Print Science Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.152 via deserialization of untrusted input through the 'designer-saved-projects' cookie. | 8.1 |
2024-12-12 | CVE-2024-11052 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. | 7.2 |