Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-06 CVE-2024-7537 Out-of-bounds Read vulnerability in Ofono Project Ofono 1.34
oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability.
local
low complexity
ofono-project CWE-125
5.5
2024-08-05 CVE-2024-34343 Cross-site Scripting vulnerability in Nuxt
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js.
network
low complexity
nuxt CWE-79
6.1
2024-08-05 CVE-2024-41959 Cross-site Scripting vulnerability in Mailcow Mailcow: Dockerized
mailcow: dockerized is an open source groupware/email suite based on docker.
network
low complexity
mailcow CWE-79
6.1
2024-08-05 CVE-2024-41960 Cross-site Scripting vulnerability in Mailcow Mailcow: Dockerized
mailcow: dockerized is an open source groupware/email suite based on docker.
network
low complexity
mailcow CWE-79
4.8
2024-08-05 CVE-2024-6361 Cross-site Scripting vulnerability in Opentext ALM Octane
Improper Neutralization vulnerability (XSS) has been discovered in OpenTextâ„¢ ALM Octane.
network
low complexity
opentext CWE-79
5.4
2024-08-05 CVE-2024-21459 Information disclosure while handling beacon or probe response frame in STA.
network
low complexity
6.5
2024-08-05 CVE-2024-21467 Information disclosure while handling beacon probe frame during scan entry generation in client side.
network
low complexity
6.5
2024-08-05 CVE-2024-23350 Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network.
low complexity
6.5
2024-08-05 CVE-2024-23357 Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus.
local
low complexity
6.2
2024-08-05 CVE-2024-6498 Cross-site Scripting vulnerability in Micro.Company Collect.Chat
The Chatbot for WordPress by Collect.chat ?? WordPress plugin before 2.4.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
network
low complexity
micro-company CWE-79
4.8