9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-41695
PineApp Mail Relay General
7.5
HIGH
EPSS
0.7%
2024 CWE-22 1 PoC

Cybonet - CWE-22: Improper Limitation of a Pathname to a Restricted Directory

CVE-2024-57762
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.

CVE-2024-5633
LBH30FE200W General
7.5
HIGH
EPSS
3.0%
2024 CWE-912 1 PoC

Longse model LBH30FE200W cameras, as well as products based on this device, provide an unrestricted access for an attacker located in the same local network to an undocumented binary service CoolView on one of the ports.  An attacker with a knowledge of the available commands is able to perform read/write operations on the device's memory, which might result in e.g. bypassing telnet login and obtaining full access to the device.

CVE-2024-45272
mbCONNECT24 General
7.5
HIGH
EPSS
1.0%
2024 CWE-1391 1 PoC

An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.

CVE-2024-4388
cas General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

This does not validate a path generated with user input when downloading files, allowing unauthenticated user to download arbitrary files from the server

CVE-2024-1931
Unbound General
7.5
HIGH
EPSS
6.8%
2024 CWE-835 1 PoC

NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path that can lead to an infinite loop. Unbound 1.18.0 introduced a feature that removes EDE records from responses with size higher than the client's advertised buffer size. Before removing all the EDE records however, it would try to see if trimming the extra text fields on those records would result in an acceptable size while still retaining the EDE codes. Due to an unchecked condition, the code that trims the text of the EDE records could loop ind

CVE-2024-41700
Barix SIP Client Web Management Interface UI General
7.5
HIGH
EPSS
0.3%
2024 CWE-200 1 PoC

Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-52923
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in NRMM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. Lack of a boundary check during the decoding of DL NAS Transport messages leads to a Denial of Service.

CVE-2024-8859
mlflow/mlflow General ⚡ nuclei
7.5
HIGH
EPSS
25.7%
2024 CWE-29 0 PoCs

A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary file read vulnerability. This issue occurs because only the path part of the URL is checked, while parts such as query and parameters are not handled. The vulnerability is triggered if the user has configured the dbfs service, and during usage, the service is mounted to a local directory.

CVE-2024-42010
Software Genérico General
7.5
HIGH
EPSS
15.1%
2024 2 PoCs

mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.

CVE-2024-21526
speaker General
7.5
HIGH
EPSS
0.1%
2024 CWE-400 1 PoC

All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to the channels property of the Speaker object makes it possible to reach an assert macro. Exploiting this vulnerability can lead to a process crash.

CVE-2024-48953
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 2 PoCs

An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in unauthorized access.

CVE-2024-27292
docassemble General ⚡ nuclei
7.5
HIGH
EPSS
93.8%
2024 CWE-706 1 PoC

Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through URL manipulation. It affects versions 1.4.53 to 1.4.96. The vulnerability has been patched in version 1.4.97 of the master branch.

CVE-2024-50650
Software Genérico General
7.5
HIGH
EPSS
0.5%
2024 1 PoC

python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

CVE-2024-53605
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS v10.9.9.7 allows attackers to access sensitive data.

CVE-2024-0801
Unified Data Protection General ⚡ nuclei
7.5
HIGH
EPSS
49.2%
2024 1 PoC

A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.

CVE-2024-40554
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information.

CVE-2024-29384
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 2 PoCs

An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information via the content.js and parseCSSRules functions.

CVE-2024-40675
Android General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.