Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-06 CVE-2024-38166 Cross-site Scripting vulnerability in Microsoft Dynamics CRM Service Portal web Resource
An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link.
network
low complexity
microsoft CWE-79
6.1
2024-08-06 CVE-2024-38206 Server-Side Request Forgery (SSRF) vulnerability in Microsoft Copilot Studio
An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network.
network
low complexity
microsoft CWE-918
6.5
2024-08-06 CVE-2024-42218 Unspecified vulnerability in 1Password
1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.
local
high complexity
1password
4.7
2024-08-06 CVE-2024-42398 Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol.
network
low complexity
arubanetworks hp
5.3
2024-08-06 CVE-2024-42399 Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol.
network
low complexity
arubanetworks hp
5.3
2024-08-06 CVE-2024-42400 Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol.
network
low complexity
arubanetworks hp
5.3
2024-08-06 CVE-2024-42396 Unspecified vulnerability in HP Instantos
Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol.
network
low complexity
hp
5.3
2024-08-06 CVE-2024-42397 Unspecified vulnerability in HP Instantos
Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol.
network
low complexity
hp
5.3
2024-08-06 CVE-2024-41677 Cross-site Scripting vulnerability in Qwik
Qwik is a performance focused javascript framework.
network
low complexity
qwik CWE-79
6.1
2024-08-06 CVE-2024-42347 Unspecified vulnerability in Matrix Matrix-React-Sdk
matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page.
network
low complexity
matrix
6.5