Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-28 CVE-2024-45054 Unspecified vulnerability in Hwameistor
Hwameistor is an HA local storage system for cloud-native stateful workloads.
local
low complexity
hwameistor
6.7
2024-08-28 CVE-2024-44913 Unspecified vulnerability in Irfanview 4.67.1.0
An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file.
local
low complexity
irfanview
5.5
2024-08-28 CVE-2024-44914 Unspecified vulnerability in Irfanview 4.67.1.0
An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file.
local
low complexity
irfanview
5.5
2024-08-28 CVE-2024-44915 Unspecified vulnerability in Irfanview 4.67.1.0
An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file.
local
low complexity
irfanview
5.5
2024-08-28 CVE-2024-41564 Improper Validation of Array Index vulnerability in Emilyploszaj EMI
EMI v.1.1.10 and before, fixed in v.1.1.11, contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability.
network
low complexity
emilyploszaj CWE-129
5.3
2024-08-28 CVE-2024-41565 Improper Validation of Array Index vulnerability in Mezz Justenoughitems
JustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability.
network
low complexity
mezz CWE-129
5.3
2024-08-28 CVE-2024-6053 Unspecified vulnerability in Teamviewer Meeting and Teamviewer
Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamViewer Meeting prior version 15.55.3 can lead to unintentional sharing of the clipboard with the current presenter of a meeting.
network
low complexity
teamviewer
4.3
2024-08-28 CVE-2024-7744 Path Traversal vulnerability in Progress WS FTP Server
In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Probe System Files, User-Controlled Filename, Path Traversal.   An authenticated file download flaw has been identified where a user can craft an API call that allows them to download a file from an arbitrary folder on the drive where that user host's root folder is located (by default this is C:)
network
low complexity
progress CWE-22
6.5
2024-08-28 CVE-2024-42698 Improper Validation of Array Index vulnerability in Shedaniel Roughlyenoughitems
Roughly Enough Items (REI) v.16.0.729 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability.
network
low complexity
shedaniel CWE-129
5.3
2024-08-28 CVE-2024-8195 Missing Authorization vulnerability in Permalink Manager Lite Project Permalink Manager Lite
The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'debug_data', 'debug_query', and 'debug_redirect' functions in all versions up to, and including, 2.4.4.
network
low complexity
permalink-manager-lite-project CWE-862
5.3