9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-40511
Software Genérico General
7.3
HIGH
EPSS
13.9%
2024 1 PoC

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMServerAdmin.asmx function.

CVE-2024-36438
Software Genérico General
7.3
HIGH
EPSS
0.0%
2024 2 PoCs

eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card duplication and other attacks.

CVE-2024-34614
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.2%
2024 1 PoC

Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

CVE-2024-0242
IQ Panel 4 General
7.3
HIGH
EPSS
0.1%
2024 CWE-200 1 PoC

Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.

CVE-2024-40508
Software Genérico General
7.3
HIGH
EPSS
7.8%
2024 1 PoC

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMConference.asmx function.

CVE-2024-45246
Vynamic View prior to v5.9.5 General
7.3
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

Diebold Nixdorf – CWE-427: Uncontrolled Search Path Element

CVE-2024-49601
Unity General
7.3
HIGH
EPSS
1.2%
2024 CWE-78 1 PoC

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

CVE-2024-39581
PowerScale InsightIQ General
7.3
HIGH
EPSS
0.4%
2024 CWE-552 1 PoC

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to read, modify, and delete arbitrary files.

CVE-2024-44623
Software Genérico General
7.3
HIGH
EPSS
38.9%
2024 1 PoC

An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.js function.

CVE-2024-21488
network General
7.3
HIGH
EPSS
2.2%
2024 CWE-77 1 PoC

Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for the attacker to execute arbitrary commands on the operating system that this package is being run on.

CVE-2024-40512
Software Genérico General
7.3
HIGH
EPSS
17.1%
2024 1 PoC

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMReporting.asmx function.

CVE-2024-27199
🔥 KEV TeamCity General ⚡ nuclei
7.3
HIGH
EPSS
91.4%
2024 CWE-23 1 PoC

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

CVE-2024-50450
MDTF General
7.3
HIGH
EPSS
52.5%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Code Injection.This issue affects MDTF: from n/a through <= 1.3.3.4.

CVE-2024-3203
c-blosc2 General
7.3
HIGH
EPSS
0.6%
2024 CWE-122 1 PoC

A vulnerability, which was classified as critical, was found in c-blosc2 up to 2.13.2. Affected is the function ndlz8_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz8x8.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.14.3 is able to address this issue. It is recommended to upgrade the affected component. VDB-259050 is the identifier assigned to this vulnerability.

CVE-2024-21409
Microsoft Visual Studio 2022 version 17.9 General
7.3
HIGH
EPSS
51.3%
2024 CWE-416 1 PoC

.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability

CVE-2024-34581
Software Genérico General
7.3
HIGH
EPSS
0.1%
2024 1 PoC

The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a "RetrievalMethod is a URI ... that may be used to obtain key and/or certificate information" statement and no accompanying information about SSRF risks, and this may have contributed to vulnerable implementations such as those discussed in CVE-2023-36661 and CVE-2024-21893. NOTE: this was mitigated in 1.1 and 2.0 via a directly referenced Best Practices document that calls on implementers to be wary of SSRF.

CVE-2024-34660
Samsung Notes General
7.3
HIGH
EPSS
0.1%
2024 1 PoC

Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

CVE-2024-12577
Graphics DDK General
7.3
HIGH
EPSS
0.0%
2024 CWE-823 1 PoC

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

CVE-2024-40506
Software Genérico General
7.3
HIGH
EPSS
6.2%
2024 1 PoC

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMHospitality.asmx function.

CVE-2024-2961
glibc General
7.3
HIGH
EPSS
91.9%
2024 CWE-787 12 PoCs

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.