9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-12905
Software Genérico General
7.5
HIGH
EPSS
0.8%
2024 CWE-59 2 PoCs

An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package. This issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8.

CVE-2024-24444
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

Improper file descriptor handling for closed connections in OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface.

CVE-2024-31392
Firefox for iOS General
7.5
HIGH
EPSS
0.5%
2024 1 PoC

If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.

CVE-2024-45253
VideoIQ iCVR HD camera General
7.5
HIGH
EPSS
0.4%
2024 CWE-22 1 PoC

Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2024-52924
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in NRMM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. Lack of boundary check during the decoding of Registration Accept messages can lead to out-of-bounds writes on the stack

CVE-2024-36254
Multiple MFPs (multifunction printers) General
7.5
HIGH
EPSS
0.2%
2024 CWE-125 1 PoC

Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition.

CVE-2024-47522
suricata General
7.5
HIGH
EPSS
0.3%
2024 CWE-617 2 PoCs

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, invalid ALPN in TLS/QUIC traffic when JA4 matching/logging is enabled can lead to Suricata aborting with a panic. This issue has been addressed in 7.0.7. One may disable ja4 as a workaround.

CVE-2024-36390
DeviceHub General
7.5
HIGH
EPSS
0.1%
2024 CWE-20 1 PoC

MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service

CVE-2024-52940
Software Genérico General
7.5
HIGH
EPSS
20.0%
2024 1 PoC

AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The attacker must know the victim's AnyDesk ID.

CVE-2024-21644
pyload General ⚡ nuclei
7.5
HIGH
EPSS
86.5%
2024 CWE-284 1 PoC

pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. This issue has been patched in version 0.5.0b3.dev77.

CVE-2024-30569
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
28.6%
2024 1 PoC

An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.

CVE-2024-45241
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
90.8%
2024 2 PoCs

A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information.

CVE-2024-47215
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an invalid GTM SS preview header to events, causing them to be retried indefinitely. As a result, the performance of forwarding events to GTM SS overall can be affected (latency, throughput).

CVE-2024-25736
Software Genérico General
7.5
HIGH
EPSS
9.1%
2024 1 PoC

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request.

CVE-2024-39025
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.

CVE-2024-48142
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

CVE-2024-31964
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication control. A successful exploit could allow an attacker to modify system configuration settings and potentially cause a denial of service.

CVE-2024-52883
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication.

CVE-2024-24442
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

A NULL pointer dereference in the ngap_app::handle_receive routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP message.

CVE-2024-56113
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 2 PoCs

Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file through verbose error page.