9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-34391
Software Genérico General
8.1
HIGH
EPSS
3.2%
2024 CWE-843 1 PoC

libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both 32-bit systems and 64-bit systems), data leak, infinite loop and remote code execution (on 32-bit systems with the XML_PARSE_HUGE flag enabled).

CVE-2024-28114
peering-manager General
8.1
HIGH
EPSS
0.4%
2024 CWE-74 1 PoC

Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to Remote Code Execution in Peering Manager <=1.8.2. As a result arbitrary commands can be executed on the operating system that is running Peering Manager. This issue has been addressed in version 1.8.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-51431
Software Genérico General
8.1
HIGH
EPSS
0.2%
2024 1 PoC

LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.

CVE-2024-5565
Software Genérico General
8.1
HIGH
EPSS
5.1%
2024 CWE-94 1 PoC

The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt using prompt injection and run arbitrary Python code instead of the intended visualization code. Specifically - allowing external input to the library’s “ask” method with "visualize" set to True (default behavior) leads to remote code execution.

CVE-2024-41967
CC100 0751-9x01 General
8.1
HIGH
EPSS
1.3%
2024 CWE-306 1 PoC

A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process or a denial-of-service attack.

CVE-2024-51329
Software Genérico General
8.1
HIGH
EPSS
0.2%
2024 1 PoC

A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.

CVE-2024-27804
iOS and iPadOS General
8.1
HIGH
EPSS
4.2%
2024 1 PoC

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.3, watchOS 10.5. An app may be able to cause unexpected system termination.

CVE-2024-56883
Software Genérico General
8.1
HIGH
EPSS
3.1%
2024 2 PoCs

Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are not always enforced on the server side. Low-privileged Sage users with employee role privileges can create external courses for other employees, even though they do not have the option to do so in the user interface. To do this, a valid request to create a course simply needs to be modified, so that the current user ID in the "id" parameter is replaced with the ID of another user.

CVE-2024-36444
Software Genérico General
8.1
HIGH
EPSS
0.1%
2024 2 PoCs

cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.

CVE-2024-39890
Software Genérico General
8.1
HIGH
EPSS
0.8%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300. The baseband software does not properly check the length specified by the CC (Call Control). This can lead to an Out-of-Bounds write.

CVE-2024-11700
Firefox General
8.1
HIGH
EPSS
0.3%
2024 1 PoC

Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133 and Thunderbird < 133.

CVE-2024-3157
Chrome General
8.1
HIGH
EPSS
0.7%
2024 1 PoC

Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)

CVE-2024-34392
Software Genérico General
8.1
HIGH
EPSS
3.2%
2024 CWE-843 1 PoC

libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespaces() function (which invokes _wrap__xmlNode_nsDef_get()) on a grand-child of a node that refers to an entity. This vulnerability can lead to denial of service and remote code execution.

CVE-2024-29946
Splunk Enterprise General
8.1
HIGH
EPSS
0.4%
2024 CWE-20 1 PoC

In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerability would require the attacker to phish the victim by tricking them into initiating a request within their browser.

CVE-2024-36598
Software Genérico General
8.1
HIGH
EPSS
0.2%
2024 2 PoCs

An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file.

CVE-2024-41971
CC100 0751-9x01 General
8.1
HIGH
EPSS
1.8%
2024 CWE-22 1 PoC

A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.

CVE-2024-44068
Software Genérico General
8.1
HIGH
EPSS
0.7%
2024 2 PoCs

An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.

CVE-2024-58101
Software Genérico General
8.1
HIGH
EPSS
0.1%
2024 1 PoC

Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to stop this mode. As a consequence, audio playback takeover or even microphone recording without user consent or notification is achieved. Note: This is considered a low severity vulnerability by the vendor.

CVE-2024-27876
iOS and iPadOS General
8.1
HIGH
EPSS
0.0%
2024 1 PoC

A race condition was addressed with improved locking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, visionOS 2. Unpacking a maliciously crafted archive may allow an attacker to write arbitrary files.

CVE-2024-24794
libdicom General
8.1
HIGH
EPSS
0.5%
2024 CWE-416 2 PoCs

A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature freeing of memory that is used later. To trigger this vulnerability, an attacker would need to induce the vulnerable application to process a malicious DICOM image.The Use-After-Free happens in the `parse_meta_sequence_end()` parsing the Sequence Value Represenations.