6.4
CVE-2024-5260 - Sina Extension for Elementor <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting viβ¦
The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the βread_more_textβ parameter in all versions up to, and including, 3.5.5 due to insufficieβ¦
8.2
CVE-2024-37077 - Arkcompiler Ets Runtime has an out-of-bounds write vulnerability
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.
8.2
CVE-2024-37185 - Arkcompiler Ets Runtime has an out-of-bounds write vulnerability
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.
8.2
CVE-2024-36260 - Arkcompiler Ets Runtime has an out-of-bounds write vulnerability
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.
3.3
CVE-2024-36278 - Arkcompiler Ets Runtime has a type confusion vulnerability
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.
8.2
CVE-2024-36243 - Arkcompiler Ets Runtime has an out-of-bounds read vulnerability
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds read and write.
8.2
CVE-2024-37030 - Arkcompiler Ets Runtime has a use after free vulnerability
in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.
3.3
CVE-2024-31071 - Arkcompiler Ets Runtime has a type confusion vulnerability
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.
4.3
CVE-2024-38857 - Reflected links in visuals facilitate phishing attacks
Improper neutralization of input in Checkmk before versions 2.3.0p8, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows attackers to craft malicious links that can facilitate phishing attacks.
5.3
CVE-2023-41928 - Remote server offers deprecated TLS protocol in Kiloview P1/P2 devices
The device is observed to accept deprecated TLS protocols, increasing the risk of cryptographic weaknesses.