Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-10 CVE-2024-6650 Cross-site Scripting vulnerability in Oretnom23 Employee and Visitor Gate Pass Logging System 1.0
A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic.
network
low complexity
oretnom23 CWE-79
4.8
2024-07-10 CVE-2024-38354 Cross-site Scripting vulnerability in Hackmd Codimd
CodiMD allows realtime collaborative markdown notes on all platforms.
network
low complexity
hackmd CWE-79
6.1
2024-07-10 CVE-2024-27095 Cross-site Scripting vulnerability in Decidim
Decidim is a participatory democracy framework.
network
low complexity
decidim CWE-79
4.8
2024-07-10 CVE-2023-33859 Response Discrepancy Information Exposure vulnerability in IBM Security Qradar EDR 3.12
IBM Security QRadar EDR 3.12 could disclose sensitive information due to an observable login response discrepancy.
network
low complexity
ibm CWE-204
5.3
2024-07-10 CVE-2023-33860 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in IBM Security Qradar EDR 3.12
IBM Security QRadar EDR 3.12 does not set the secure attribute on authorization tokens or session cookies.
network
low complexity
ibm CWE-614
5.3
2024-07-10 CVE-2023-35006 Cross-site Scripting vulnerability in IBM Security Qradar EDR 3.12
IBM Security QRadar EDR 3.12 is vulnerable to HTML injection.
network
low complexity
ibm CWE-79
5.4
2024-07-10 CVE-2024-6556 The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.10.8.
network
low complexity
5.3
2024-07-10 CVE-2023-6813 The Login by Auth0 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wle’ parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping.
network
low complexity
6.1
2024-07-10 CVE-2024-39489 Memory Leak vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix memleak in seg6_hmac_init_algo seg6_hmac_init_algo returns without cleaning up the previous allocations if one fails, so it's going to leak all that memory and the crypto tfms. Update seg6_hmac_exit to only free the memory when allocated, so we can reuse the code directly.
local
low complexity
linux CWE-401
5.5
2024-07-10 CVE-2024-39493 Memory Leak vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak Using completion_done to determine whether the caller has gone away only works after a complete call.
local
low complexity
linux CWE-401
5.5