Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-27 CVE-2024-7941 Open Redirect vulnerability in Hitachienergy Microscada X Sys600
An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
network
low complexity
hitachienergy CWE-601
6.1
2024-08-27 CVE-2024-8207 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Mongodb
In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible for a unintended actor with host-level access to cause the MongoDB Server binary to load unintended actor-controlled shared libraries when the server binary is started, potentially resulting in the unintended actor gaining full control over the MongoDB server process.
local
low complexity
mongodb CWE-610
6.7
2024-08-27 CVE-2024-7791 The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arrow’ parameter within the Post Grid widget in all versions up to, and including, 1.4.4.3 due to insufficient input sanitization and output escaping.
network
low complexity
6.4
2024-08-27 CVE-2024-8197 The Visual Sound plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.03.
network
low complexity
4.3
2024-08-27 CVE-2024-6789 Path Traversal vulnerability in M-Files Server
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files
network
low complexity
m-files CWE-22
6.5
2024-08-27 CVE-2024-41175 Allocation of Resources Without Limits or Throttling vulnerability in Beckhoff IPC Diagnostics Package and Twincat/Bsd
The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker.
local
low complexity
beckhoff CWE-770
5.5
2024-08-27 CVE-2024-6804 Cross-site Scripting vulnerability in Jegtheme JEG Elementor KIT
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.6.7 due to insufficient input sanitization and output escaping.
network
low complexity
jegtheme CWE-79
5.4
2024-08-27 CVE-2024-7304 Cross-site Scripting vulnerability in Wpmanageninja Ninja Tables
The Ninja Tables – Easiest Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping.
network
low complexity
wpmanageninja CWE-79
5.4
2024-08-27 CVE-2024-6688 The Oxygen Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the oxy_save_css_from_admin AJAX action in all versions up to, and including, 4.8.3.
network
low complexity
4.3
2024-08-26 CVE-2024-43214 Missing Authorization vulnerability in Mycred
Missing Authorization vulnerability in myCred.This issue affects myCred: from n/a through 2.7.2.
network
low complexity
mycred CWE-862
5.3