9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-25164
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionality.

CVE-2024-34666
Samsung Mobile Devices General
7.5
HIGH
EPSS
5.1%
2024 1 PoC

Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2024-46938
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
93.4%
2024 0 PoCs

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated attacker can read arbitrary files.

CVE-2024-53473
Software Genérico General
7.5
HIGH
EPSS
0.9%
2024 2 PoCs

WeGIA 3.2.0 before 3998672 does not verify permission to change a password.

CVE-2024-56527
tcpdf General
7.5
HIGH
EPSS
0.5%
2024 CWE-79 1 PoC

An issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.

CVE-2024-33530
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.

CVE-2024-47187
suricata General
7.5
HIGH
EPSS
0.1%
2024 CWE-330 1 PoC

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed for "thash" leads to datasets having predictable hash table behavior. This can lead to dataset file loading to use excessive time to load, as well as runtime performance issues during traffic handling. This issue has been addressed in 7.0.7. As a workaround, avoid loading datasets from untrusted sources. Avoid dataset rules that track traffic in rules.

CVE-2024-23261
macOS General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.8. An attacker may be able to read information belonging to another user.

CVE-2024-48141
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

CVE-2024-35057
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

An issue in NASA AIT-Core v2.5.2 allows attackers to execute arbitrary code via a crafted packet.

CVE-2024-55628
suricata General
7.5
HIGH
EPSS
0.5%
2024 CWE-405 1 PoC

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.8, DNS resource name compression can lead to small DNS messages containing very large hostnames which can be costly to decode, and lead to very large DNS log records. While there are limits in place, they were too generous. The issue has been addressed in Suricata 7.0.8.

CVE-2024-56067
WP SuperBackup General
7.5
HIGH
EPSS
62.3%
2024 CWE-862 1 PoC

Missing Authorization vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

CVE-2024-52884
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.

CVE-2024-0760
BIND 9 General
7.5
HIGH
EPSS
16.7%
2024 1 PoC

A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.

CVE-2024-46471
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information.

CVE-2024-55272
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function.

CVE-2024-23660
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the device time is the only entropy source, leading to economic losses, as exploited in the wild in July 2023. An attacker can systematically generate mnemonics for each timestamp within an applicable timeframe, and link them to specific wallet addresses in order to steal funds from those wallets.

CVE-2024-31846
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2024-41336
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 were discovered to store passwords in plaintext.

CVE-2024-28069
Software Genérico General
7.5
HIGH
EPSS
0.8%
2024 1 PoC

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to access sensitive information and potentially conduct unauthorized actions within the vulnerable component.