9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-13966
BioTime General
7.3
HIGH
EPSS
0.6%
2024 CWE-1393 1 PoC

ZKTeco BioTime allows unauthenticated attackers to enumerate usernames and log in as any user with a password unchanged from the default value '123456'. Users should change their passwords (located under the Attendance Settings tab as "Self-Password").

CVE-2024-43093
🔥 KEV Android General
7.3
HIGH
EPSS
0.2%
2024 2 PoCs

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2024-28287
Software Genérico General
7.3
HIGH
EPSS
0.1%
2024 1 PoC

A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted URL.

CVE-2024-20878
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.2%
2024 1 PoC

Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows local attackers to execute arbitrary code.

CVE-2024-34656
Samsung Notes General
7.3
HIGH
EPSS
0.1%
2024 1 PoC

Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

CVE-2024-38355
socket.io General
7.3
HIGH
EPSS
0.1%
2024 CWE-20 1 PoC

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. This issue is fixed by commit `15af22fc22` which has been included in `socket.io@4.6.2` (released in May 2023). The fix was backported in the 2.x branch as well with commit `d30630ba10`. Users are advised to upgrade. Users unable to upgrade may attach a listener for the "error" event to catch these errors.

CVE-2024-43688
Software Genérico General
7.3
HIGH
EPSS
0.1%
2024 2 PoCs

cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was introduced during a May 2023 refactoring.

CVE-2024-34612
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.2%
2024 1 PoC

Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

CVE-2024-3204
c-blosc2 General
7.3
HIGH
EPSS
0.6%
2024 CWE-122 2 PoCs

A vulnerability has been found in c-blosc2 up to 2.13.2 and classified as critical. Affected by this vulnerability is the function ndlz4_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz4x4.c. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.14.3 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-259051.

CVE-2024-45492
Software Genérico General
7.3
HIGH
EPSS
2.3%
2024 2 PoCs

An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

CVE-2024-4582
GM8181 General
7.3
HIGH
EPSS
0.7%
2024 CWE-78 1 PoC

A vulnerability classified as critical has been found in Faraday GM8181 and GM828x up to 20240429. Affected is an unknown function of the component NTP Service. The manipulation of the argument ntp_srv leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-263304.

CVE-2024-40507
Software Genérico General
7.3
HIGH
EPSS
7.8%
2024 1 PoC

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMPersonnel.asmx function.

CVE-2024-0294
LR1200GB General
7.3
HIGH
EPSS
2.1%
2024 CWE-78 1 PoC

A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this issue is the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249860. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-1302
Monitool General
7.3
HIGH
EPSS
0.3%
2024 CWE-200 1 PoC

Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a log file obtaining all sensitive information such as database credentials.

CVE-2024-21541
dom-iterator General
7.3
HIGH
EPSS
0.3%
2024 CWE-94 2 PoCs

Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function generates a new function body and thus care must be given to ensure that the inputs to Function are not attacker-controlled. The risks involved are similar to that of allowing attacker-controlled input to reach eval.

CVE-2024-38499
CA Client Automation (ITCM) General
7.3
HIGH
EPSS
0.1%
2024 CWE-269 1 PoC

CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a non-admin/non-root user to execute "caf encrypt"/"sd_acmd encrypt" commands.

CVE-2024-42471
toolkit General
7.3
HIGH
EPSS
7.7%
2024 CWE-22 1 PoC

actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or higher. There are no known workarounds for this issue.

CVE-2024-20877
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.2%
2024 1 PoC

Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to execute arbitrary code.

CVE-2024-33211
Software Genérico General
7.3
HIGH
EPSS
0.1%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter in ip/goform/QuickIndex.

CVE-2024-50986
Software Genérico General
7.3
HIGH
EPSS
10.9%
2024 2 PoCs

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.