Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-06-14 CVE-2024-37888 Cross-site Scripting vulnerability in Mlewand Open Link
The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab.
network
low complexity
mlewand CWE-79
6.1
2024-06-14 CVE-2024-37315 Unspecified vulnerability in Nextcloud Server
Nextcloud Server is a self hosted personal cloud system.
network
low complexity
nextcloud
4.3
2024-06-14 CVE-2024-37316 Unspecified vulnerability in Nextcloud Calendar
Nextcloud Calendar is a calendar app for Nextcloud.
network
low complexity
nextcloud
4.6
2024-06-14 CVE-2024-37317 Missing Authorization vulnerability in Nextcloud Notes
The Nextcloud Notes app is a distraction free notes taking app for Nextcloud.
network
low complexity
nextcloud CWE-862
4.6
2024-06-14 CVE-2024-37883 Unspecified vulnerability in Nextcloud Deck
Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud.
network
low complexity
nextcloud
4.3
2024-06-14 CVE-2024-37884 Unspecified vulnerability in Nextcloud Server
Nextcloud Server is a self hosted personal cloud system.
network
low complexity
nextcloud
5.4
2024-06-14 CVE-2024-23442 Open Redirect vulnerability in Elastic Kibana
An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.
network
low complexity
elastic CWE-601
6.1
2024-06-14 CVE-2024-2023 The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0 in Folders and 3.0.2 in Folders Pro via the 'handle_folders_file_upload' function.
network
low complexity
4.3
2024-06-14 CVE-2023-51376 Missing Authorization vulnerability in Brainstormforce Surefeedback
Missing Authorization vulnerability in Brainstorm Force ProjectHuddle Client Site.This issue affects ProjectHuddle Client Site: from n/a through 1.0.34.
network
low complexity
brainstormforce CWE-862
4.3
2024-06-14 CVE-2024-34012 Incorrect Default Permissions vulnerability in Acronis Cloud Manager
Local privilege escalation due to insecure folder permissions.
local
low complexity
acronis CWE-276
4.4