Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-06-26 CVE-2024-28984 Cross-site Scripting vulnerability in Hitachi Pentaho Business Analytics Server
Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.
network
low complexity
hitachi CWE-79
6.1
2024-06-26 CVE-2024-39241 Cross-site Scripting vulnerability in Skycaiji 2.8
Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 allows attackers to run arbitrary code via /admin/tool/preview.
network
low complexity
skycaiji CWE-79
6.1
2024-06-26 CVE-2024-39242 Cross-site Scripting vulnerability in Skycaiji 2.8
A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload using eval(String.fromCharCode()).
network
low complexity
skycaiji CWE-79
6.1
2024-06-26 CVE-2024-38271 Improper Resource Shutdown or Release vulnerability in Google Nearby
There exists a vulnerability in Quick Share/Nearby, where an attacker can force a victim to stay connected to a temporary hotspot created for the sharing.
high complexity
google CWE-404
4.8
2024-06-26 CVE-2024-38272 Authentication Bypass by Capture-replay vulnerability in Google Nearby
There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share Windows. Normally in Quick Share Windows app we can't send a file without the user accept from the receiving device if the visibility is set to everyone mode or contacts mode. We recommend upgrading to version 1.0.1724.0 of Quick Share or above
low complexity
google CWE-294
4.3
2024-06-26 CVE-2024-4604 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields.This issue affects SSO (Single Sign On): from 1.0 before 1.1.
network
low complexity
CWE-601
6.1
2024-06-26 CVE-2024-5215 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 2.5.5 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
6.4
2024-06-26 CVE-2024-5169 Cross-site Scripting vulnerability in Nikodev Video Widget 1.2.3
The Video Widget WordPress plugin through 1.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
nikodev CWE-79
4.8
2024-06-26 CVE-2024-5199 Cross-site Scripting vulnerability in Wolfiezero Spotify Play Button
The Spotify Play Button WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
network
low complexity
wolfiezero CWE-79
5.4
2024-06-26 CVE-2024-5332 Cross-site Scripting vulnerability in Exclusiveaddons Exclusive Addons for Elementor
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Card widget in all versions up to, and including, 2.6.9.8 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
exclusiveaddons CWE-79
5.4