Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-04 CVE-2024-45446 Unspecified vulnerability in Huawei Emui and Harmonyos
Access permission verification vulnerability in the camera driver module Impact: Successful exploitation of this vulnerability will affect availability.
local
low complexity
huawei
5.5
2024-09-04 CVE-2024-45447 Unspecified vulnerability in Huawei Emui and Harmonyos
Access control vulnerability in the camera framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
local
low complexity
huawei
5.5
2024-09-04 CVE-2024-45448 Unspecified vulnerability in Huawei Emui and Harmonyos
Page table protection configuration vulnerability in the trusted firmware module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
local
low complexity
huawei
5.5
2024-09-04 CVE-2024-45449 Unspecified vulnerability in Huawei Emui and Harmonyos
Access permission verification vulnerability in the ringtone setting module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
local
low complexity
huawei
5.5
2024-09-04 CVE-2024-8298 Unspecified vulnerability in Huawei Emui and Harmonyos
Memory request vulnerability in the memory management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
local
low complexity
huawei
5.5
2024-09-04 CVE-2024-41927 Cleartext Transmission of Sensitive Information vulnerability in Idec products
Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs.
low complexity
idec CWE-319
4.6
2024-09-03 CVE-2024-45619 Classic Buffer Overflow vulnerability in multiple products
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK.
low complexity
redhat opensc-project CWE-120
4.3
2024-09-03 CVE-2024-45180 Cross-site Scripting vulnerability in Squaredup DS for Scom
SquaredUp DS for SCOM 6.2.1.11104 allows XSS.
network
low complexity
squaredup CWE-79
5.4
2024-09-03 CVE-2024-45389 Cross-site Scripting vulnerability in Cloudcannon Pagefinder
Pagefind, a fully static search library, initializes its dynamic JavaScript and WebAssembly files relative to the location of the first script the user loads.
network
low complexity
cloudcannon CWE-79
5.4
2024-09-03 CVE-2024-45678 Information Exposure Through Discrepancy vulnerability in Yubico products
Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the Extended Euclidean Algorithm, aka the EUCLEAK issue.
high complexity
yubico CWE-203
4.2