Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-12 CVE-2024-7705 Unrestricted Upload of File with Dangerous Type vulnerability in Mainwww Mwcms 1.0.0
A vulnerability was found in Fujian mwcms 1.0.0.
network
low complexity
mainwww CWE-434
5.3
2024-08-12 CVE-2024-43358 Cross-site Scripting vulnerability in Zoneminder
ZoneMinder is a free, open source closed-circuit television software application.
network
low complexity
zoneminder CWE-79
6.1
2024-08-12 CVE-2024-43359 Cross-site Scripting vulnerability in Zoneminder
ZoneMinder is a free, open source closed-circuit television software application.
network
low complexity
zoneminder CWE-79
6.1
2024-08-12 CVE-2023-41884 SQL Injection vulnerability in Zoneminder
ZoneMinder is a free, open source Closed-circuit television software application.
network
low complexity
zoneminder CWE-89
6.5
2024-08-12 CVE-2024-42474 Path Traversal vulnerability in Snowflake Streamlit
Streamlit is a data oriented application development framework for python.
network
low complexity
snowflake CWE-22
6.5
2024-08-12 CVE-2024-7700 Command Injection vulnerability in Theforeman Foreman
A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Host" page.
local
low complexity
theforeman CWE-77
6.5
2024-08-12 CVE-2024-41909 Improper Validation of Integrity Check Value vulnerability in Apache Mina Sshd
Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795.
network
high complexity
apache CWE-354
5.9
2024-08-12 CVE-2024-42482 Unspecified vulnerability in Fish-Shop Syntax-Check
fish-shop/syntax-check is a GitHub action for syntax checking fish shell files.
network
low complexity
fish-shop
6.5
2024-08-12 CVE-2024-21550 Cross-site Scripting vulnerability in Steve-Community Steve
SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points.
network
low complexity
steve-community CWE-79
6.1
2024-08-12 CVE-2024-27443 Cross-site Scripting vulnerability in Zimbra Collaboration
An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0.
network
low complexity
zimbra CWE-79
6.1