Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-05 CVE-2024-45096 Unspecified vulnerability in IBM Aspera Faspex
IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information through a directory listing.
network
low complexity
ibm
6.5
2024-09-05 CVE-2024-45176 Cross-site Scripting vulnerability in C-Mor 5.2401
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401.
network
low complexity
c-mor CWE-79
6.1
2024-09-05 CVE-2024-45589 Improper Restriction of Excessive Authentication Attempts vulnerability in Identityautomation Rapididentity
RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters.
network
high complexity
identityautomation CWE-307
5.9
2024-09-05 CVE-2024-8461 Unspecified vulnerability in Dlink Dns-320 Firmware 2.02B01
A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01.
network
low complexity
dlink
5.3
2024-09-05 CVE-2024-8471 Cross-site Scripting vulnerability in PHPgurukul JOB Portal 1.0
Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted.
network
low complexity
phpgurukul CWE-79
6.1
2024-09-05 CVE-2024-8472 Cross-site Scripting vulnerability in PHPgurukul JOB Portal 1.0
Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted.
network
low complexity
phpgurukul CWE-79
6.1
2024-09-05 CVE-2024-8473 Cross-site Scripting vulnerability in PHPgurukul JOB Portal 1.0
Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted.
network
low complexity
phpgurukul CWE-79
6.1
2024-09-05 CVE-2024-8460 Unspecified vulnerability in Dlink Dns-320 Firmware 2.02B01
A vulnerability, which was classified as problematic, has been found in D-Link DNS-320 2.02b01.
network
high complexity
dlink
5.9
2024-09-05 CVE-2022-3556 Cross-site Scripting vulnerability in Kanev CAB Fare Calculator 1.0.3/1.0.4
The Cab fare calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vehicle title setting in versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping.
network
low complexity
kanev CWE-79
4.8
2024-09-05 CVE-2022-4529 Unspecified vulnerability in Msoftplugins Security Antivirus Firewall
The Security, Antivirus, Firewall – S.A.F plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.3.5.
network
low complexity
msoftplugins
5.3