Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-39901 Authorization Bypass Through User-Controlled Key vulnerability in Opensearch Observability
OpenSearch Observability is collection of plugins and applications that visualize data-driven events.
network
low complexity
opensearch CWE-639
5.4
2024-07-09 CVE-2024-37865 Improper Certificate Validation vulnerability in S3Browser S3 Browser
An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive information via the S3 compatible storage component.
network
high complexity
s3browser CWE-295
5.9
2024-07-09 CVE-2024-34140 Out-of-bounds Read vulnerability in Adobe Bridge
Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory.
local
low complexity
adobe CWE-125
5.5
2024-07-09 CVE-2024-37830 Open Redirect vulnerability in Getoutline Outline
An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie.
network
low complexity
getoutline CWE-601
6.1
2024-07-09 CVE-2024-27183 Cross-site Scripting vulnerability in Dj-Extensions Dj-Helpfularticles
XSS vulnerability in DJ-HelpfulArticles component for Joomla.
network
low complexity
dj-extensions CWE-79
6.1
2024-07-09 CVE-2024-38970 Unspecified vulnerability in Vaethink 1.0.2
vaeThink 1.0.2 is vulnerable to Information Disclosure via the system backend,access management administrator function.
network
low complexity
vaethink
4.9
2024-07-09 CVE-2024-38971 Cross-site Scripting vulnerability in Vaethink 1.0.2
vaeThink 1.0.2 is vulnerable to stored Cross Site Scripting (XSS) in the system backend.
network
low complexity
vaethink CWE-79
5.4
2024-07-09 CVE-2024-38972 Cross-site Scripting vulnerability in Netbox 4.0.3
A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-ports/add/.
network
low complexity
netbox CWE-79
6.1
2024-07-09 CVE-2024-40726 Cross-site Scripting vulnerability in Netbox 4.0.3
A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-ports/{id}/edit/.
network
low complexity
netbox CWE-79
6.1
2024-07-09 CVE-2024-40727 Cross-site Scripting vulnerability in Netbox 4.0.3
A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/console-server-ports/add/.
network
low complexity
netbox CWE-79
6.1