Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-29 CVE-2024-45232 Authorization Bypass Through User-Controlled Key vulnerability in In2Code Powermail
An issue was discovered in powermail extension through 12.3.5 for TYPO3.
network
low complexity
in2code CWE-639
5.3
2024-08-29 CVE-2024-8250 Out-of-bounds Write vulnerability in Wireshark
NTLMSSP dissector crash in Wireshark 4.2.0 to 4.0.6 and 4.0.0 to 4.0.16 allows denial of service via packet injection or crafted capture file
local
low complexity
wireshark CWE-787
5.5
2024-08-28 CVE-2024-45046 Cross-site Scripting vulnerability in PHPoffice PHPspreadsheet
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files.
network
low complexity
phpoffice CWE-79
5.4
2024-08-28 CVE-2024-45048 XXE vulnerability in PHPoffice PHPspreadsheet
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files.
network
low complexity
phpoffice CWE-611
6.5
2024-08-28 CVE-2024-45057 Cross-site Scripting vulnerability in Portabilis I-Educar
i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers.
network
low complexity
portabilis CWE-79
6.1
2024-08-28 CVE-2024-43805 Cross-site Scripting vulnerability in Jupyter Jupyterlab and Notebook
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture.
network
low complexity
jupyter CWE-79
6.1
2024-08-28 CVE-2024-45054 Unspecified vulnerability in Hwameistor
Hwameistor is an HA local storage system for cloud-native stateful workloads.
local
low complexity
hwameistor
6.7
2024-08-28 CVE-2024-44913 Unspecified vulnerability in Irfanview 4.67.1.0
An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file.
local
low complexity
irfanview
5.5
2024-08-28 CVE-2024-44914 Unspecified vulnerability in Irfanview 4.67.1.0
An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file.
local
low complexity
irfanview
5.5
2024-08-28 CVE-2024-44915 Unspecified vulnerability in Irfanview 4.67.1.0
An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file.
local
low complexity
irfanview
5.5