Vulnerabilities (CVE)

Filtered by CWE-451
Total 124 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-51749 2024-11-13 N/A 3.5 LOW
Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a file download once clicked. Fixed in element-web 1.11.85.
CVE-2024-38197 1 Microsoft 1 Teams 2024-10-22 N/A 6.5 MEDIUM
Microsoft Teams for iOS Spoofing Vulnerability
CVE-2024-47044 2024-10-17 N/A 5.3 MEDIUM
Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to insufficient access restrictions for Device Setting pages. If this vulnerability is exploited, an attacker who identified WAN-side IPv6 address may access the product's Device Setting page via WAN-side. Note that, the same products are also provided by NIPPON TELEGRAPH AND TELEPHONE WEST CORPORATION, but the vulnerability only affects products subscribed and used in NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION areas.
CVE-2024-7529 1 Mozilla 3 Firefox, Firefox Esr, Thunderbird 2024-08-12 N/A 6.5 MEDIUM
The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.