Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-06-14 CVE-2024-37182 Unspecified vulnerability in Mattermost Desktop
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.
network
low complexity
mattermost
6.1
2024-06-14 CVE-2024-36499 Unspecified vulnerability in Huawei Emui and Harmonyos
Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
local
low complexity
huawei
5.5
2024-06-14 CVE-2024-36500 Unspecified vulnerability in Huawei Emui and Harmonyos
Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
local
low complexity
huawei
5.5
2024-06-14 CVE-2024-36501 Unspecified vulnerability in Huawei Emui and Harmonyos
Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity.
local
low complexity
huawei
5.5
2024-06-14 CVE-2024-36502 Out-of-bounds Read vulnerability in Huawei Emui and Harmonyos
Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnerability will affect availability.
local
low complexity
huawei CWE-125
5.5
2024-06-14 CVE-2024-36503 Use of Uninitialized Resource vulnerability in Huawei Emui and Harmonyos
Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability.
local
low complexity
huawei CWE-908
5.5
2024-06-14 CVE-2024-5465 Unspecified vulnerability in Huawei Emui and Harmonyos
Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availability.
local
low complexity
huawei
5.5
2024-06-14 CVE-2024-5994 The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, and including, 9.0.38.
network
low complexity
6.4
2024-06-14 CVE-2023-51377 Missing Authorization vulnerability in Wpeverest Everest Forms
Missing Authorization vulnerability in WPEverest Everest Forms.This issue affects Everest Forms: from n/a through 2.0.3.
network
low complexity
wpeverest CWE-862
5.3
2024-06-14 CVE-2023-51495 Missing Authorization vulnerability in Woocommerce Returns and Warranty Requests
Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.
network
low complexity
woocommerce CWE-862
6.5