4.9
CVE-2024-50378 - Apache Airflow: Secrets not masked in UI when sensitive variables are set via Airflow cli
Airflow versions before 2.10.3 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see.ย When sensitive variables were set via airflow CLI, values of those variables appeared in the audit log and were stored unencryptโฆ
7
CVE-2024-50592 - Local Privilege Escalation via Race Condition
An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a race condition in the Elefant Update Service during the repair or update process.ย When using the repair function, the service queries the server for a lโฆ
7.8
CVE-2024-50593 - Hardcoded Service Password
An attacker with local access to the medical office computer can access restricted functions of the Elefant Service tool by using a hard-coded "Hotline" password in the Elefant service binary, which is shipped with the software.
7.8
CVE-2024-50591 - Local Privilege Escalation via Command Injection
An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a command injection vulnerability in the Elefant Update Service. The command injection can be exploited by communicating with the Elefant Update Service wโฆ
7.8
CVE-2024-50590 - Local Privilege Escalation via Weak Service Binary Permissions
Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one of two Elefant service binaries with weak permissions.ย The default installation directory of Elefant is "C:\Elefant1" which is writable for all users.โฆ
7.5
CVE-2024-50589 - Unprotected FHIR API
An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Healthcare Interoperability Resources (FHIR) API to get access to sensitive electronic health records (EHR).
6.4
CVE-2024-10325 - Elementor Header & Footer Builder <= 1.6.45 - Authenticated (Author+) Stored Cross-Site Scripting vโฆ
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.6.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Autโฆ
8.5
CVE-2024-10839 - XML External Entity
Zohocorp ManageEngine SharePoint Manager Plus versionsย 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.
6.4
CVE-2024-10187 - myCred <= 2.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via mycred_link Shortcode
The myCred โ Loyalty Points and Rewards plugin for WordPress and WooCommerce โ Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mycred_link shortcode in all versionsโฆ
9.8
CVE-2024-50588 - Unprotected Exposed Firebird Database with default credentials
An unauthenticated attacker with access to the local network of the medical office can use known default credentials to gain remote DBA access to the Elefant Firebird database. The data in the database includes patient data and login credentials among other sensitive data. In addition, this enaโฆ