Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2024-06-28 CVE-2022-38383 Unspecified vulnerability in IBM Cloud PAK for Security and Qradar Suite
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which can be read by another user on the system.
local
low complexity
ibm
3.3
2024-06-26 CVE-2024-37141 Unspecified vulnerability in Dell Data Domain Operating System
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an open redirect vulnerability.
network
low complexity
dell
3.5
2024-06-26 CVE-2024-29177 Unspecified vulnerability in Dell Data Domain Operating System
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary sensitive information vulnerability.
network
low complexity
dell
2.7
2024-06-25 CVE-2024-6299 Unspecified vulnerability in Conduit
Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the remote server, as well as PDUs with timestamps past the expiry date
network
high complexity
conduit
3.7
2024-06-24 CVE-2024-3121 OS Command Injection vulnerability in Lollms 5.9.0
A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version 5.9.0.
local
low complexity
lollms CWE-78
3.3
2024-06-20 CVE-2024-37349 Cross-site Scripting vulnerability in Absolute Secure Access
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06.
network
low complexity
absolute CWE-79
3.4
2024-06-20 CVE-2024-37351 Cross-site Scripting vulnerability in Absolute Secure Access
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06.
network
low complexity
absolute CWE-79
3.4
2024-06-20 CVE-2024-37352 Cross-site Scripting vulnerability in Absolute Secure Access
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06 that allows attackers with system administrator permissions to interfere with other system administrators’ use of the management UI when the second administrator accesses the vulnerable page.
network
low complexity
absolute CWE-79
3.4
2024-06-20 CVE-2024-37344 Cross-site Scripting vulnerability in Absolute Secure Access
There is a cross-site scripting vulnerability in the Policy management UI of Absolute Secure Access prior to version 13.06.
network
low complexity
absolute CWE-79
3.4
2024-06-20 CVE-2024-37347 Cross-site Scripting vulnerability in Absolute Secure Access
There is a cross-site scripting vulnerability in the pool configuration component of the management UI of Absolute Secure Access prior to 13.06.
network
low complexity
absolute CWE-79
3.4