Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-25 CVE-2024-41801 Open Redirect vulnerability in Openproject
OpenProject is open source project management software.
network
low complexity
openproject CWE-601
6.1
2024-07-25 CVE-2023-7271 Unspecified vulnerability in Huawei Emui and Harmonyos
Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability.
local
low complexity
huawei
5.5
2024-07-25 CVE-2024-39670 Unspecified vulnerability in Huawei Emui and Harmonyos
Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability.
local
low complexity
huawei
5.5
2024-07-25 CVE-2024-39671 Unspecified vulnerability in Huawei Emui and Harmonyos
Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
local
low complexity
huawei
5.5
2024-07-25 CVE-2024-39674 Unspecified vulnerability in Huawei Emui and Harmonyos
Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.
local
low complexity
huawei
5.5
2024-07-25 CVE-2024-41705 Cross-site Scripting vulnerability in Archerirm Archer
A stored XSS issue was discovered in Archer Platform 6.8 before 2024.06.
network
low complexity
archerirm CWE-79
5.4
2024-07-25 CVE-2024-41706 Cross-site Scripting vulnerability in Archerirm Archer
A stored XSS issue was discovered in Archer Platform 6 before version 2024.06.
network
low complexity
archerirm CWE-79
5.4
2024-07-25 CVE-2024-41707 Cross-site Scripting vulnerability in Archerirm Archer
An issue was discovered in Archer Platform 6 before 2024.06.
network
low complexity
archerirm CWE-79
5.4
2024-07-25 CVE-2024-7047 Cross-site Scripting vulnerability in Gitlab
A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user.
network
low complexity
gitlab CWE-79
5.4
2024-07-25 CVE-2024-7057 Unspecified vulnerability in Gitlab
An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacking the proper authorization level.
network
low complexity
gitlab
4.3