Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-31 CVE-2023-7256 Double Free vulnerability in Tcpdump Libpcap
In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() still remains to be called after the function returns.
local
low complexity
tcpdump CWE-415
4.4
2024-08-31 CVE-2024-45304 Always-Incorrect Control Flow Implementation vulnerability in Openzeppelin Contracts
Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup.
network
low complexity
openzeppelin CWE-670
6.5
2024-08-31 CVE-2024-8006 NULL Pointer Dereference vulnerability in Tcpdump Libpcap
Remote packet capture support is disabled by default in libpcap.
local
low complexity
tcpdump CWE-476
4.4
2024-08-30 CVE-2024-44682 Cross-site Scripting vulnerability in Shopxo 6.2.0
ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters.
network
low complexity
shopxo CWE-79
6.1
2024-08-30 CVE-2024-44683 Cross-site Scripting vulnerability in Seacms 13.0
Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.
network
low complexity
seacms CWE-79
6.1
2024-08-30 CVE-2024-44684 Cross-site Scripting vulnerability in Tpmecms 1.3.3.2
TpMeCMS 1.3.3.2 is vulnerable to Cross Site Scripting (XSS) in /h.php/page?ref=addtabs via the "Title," "Images," and "Content" fields.
network
low complexity
tpmecms CWE-79
6.1
2024-08-30 CVE-2024-8285 Improper Certificate Validation vulnerability in Redhat Kroxylicious
A flaw was found in Kroxylicious.
network
high complexity
redhat CWE-295
5.9
2024-08-30 CVE-2024-21658 Allocation of Resources Without Limits or Throttling vulnerability in Discourse Calendar 1.0.0/1.0.1
discourse-calendar is a discourse plugin which adds the ability to create a dynamic calendar in the first post of a topic.
network
low complexity
discourse CWE-770
4.3
2024-08-30 CVE-2024-45047 Cross-site Scripting vulnerability in Svelte
svelte performance oriented web framework.
network
low complexity
svelte CWE-79
6.1
2024-08-30 CVE-2024-8235 NULL Pointer Dereference vulnerability in Redhat Libvirt
A flaw was found in libvirt.
local
low complexity
redhat CWE-476
6.2