Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-06-14 CVE-2024-23442 Open Redirect vulnerability in Elastic Kibana
An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.
network
low complexity
elastic CWE-601
6.1
2024-06-14 CVE-2024-2023 The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0 in Folders and 3.0.2 in Folders Pro via the 'handle_folders_file_upload' function.
network
low complexity
4.3
2024-06-14 CVE-2023-51376 Missing Authorization vulnerability in Brainstormforce Surefeedback
Missing Authorization vulnerability in Brainstorm Force ProjectHuddle Client Site.This issue affects ProjectHuddle Client Site: from n/a through 1.0.34.
network
low complexity
brainstormforce CWE-862
4.3
2024-06-14 CVE-2024-34012 Incorrect Default Permissions vulnerability in Acronis Cloud Manager
Local privilege escalation due to insecure folder permissions.
local
low complexity
acronis CWE-276
4.4
2024-06-14 CVE-2024-37182 Unspecified vulnerability in Mattermost Desktop
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.
network
low complexity
mattermost
6.1
2024-06-14 CVE-2024-36499 Unspecified vulnerability in Huawei Emui and Harmonyos
Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
local
low complexity
huawei
5.5
2024-06-14 CVE-2024-36500 Unspecified vulnerability in Huawei Emui and Harmonyos
Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
local
low complexity
huawei
5.5
2024-06-14 CVE-2024-36501 Unspecified vulnerability in Huawei Emui and Harmonyos
Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity.
local
low complexity
huawei
5.5
2024-06-14 CVE-2024-36502 Out-of-bounds Read vulnerability in Huawei Emui and Harmonyos
Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnerability will affect availability.
local
low complexity
huawei CWE-125
5.5
2024-06-14 CVE-2024-36503 Use of Uninitialized Resource vulnerability in Huawei Emui and Harmonyos
Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability.
local
low complexity
huawei CWE-908
5.5