9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-35428
Software Genérico General
7.1
HIGH
EPSS
0.7%
2024 1 PoC

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server which can lead to DoS.

CVE-2024-26292
Avid NEXIS E-series General
7.1
HIGH
EPSS
0.2%
2024 CWE-22 1 PoC

An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1.

CVE-2024-47191
Software Genérico General
7.1
HIGH
EPSS
0.1%
2024 1 PoC

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.

CVE-2024-5082
Nexus Repository General ⚡ nuclei
7.1
HIGH
EPSS
6.4%
2024 CWE-94 1 PoC

A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.  This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.

CVE-2024-10930
Block Load General
7.1
HIGH
EPSS
1.5%
2024 CWE-427 1 PoC

An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges.

CVE-2024-40814
macOS General
7.1
HIGH
EPSS
0.0%
2024 1 PoC

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.6, macOS Ventura 13.7. An app may be able to bypass Privacy preferences.

CVE-2024-49413
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.1%
2024 1 PoC

Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applications.

CVE-2024-53150
🔥 KEV Linux General
7.1
HIGH
EPSS
1.1%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That is, when a device provides a bogus descriptor with a shorter bLength, the driver might hit out-of-bounds reads. For addressing it, this patch adds sanity checks to the validator functions for the clock descriptor traversal. When the descriptor length is shorter than expected, it's skipped in the loop. For the clock source and clock multipl

CVE-2024-45187
Software Genérico General
7.1
HIGH
EPSS
0.1%
2024 CWE-613 1 PoC

Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute arbitrary code through the Mage AI terminal server

CVE-2024-1938
Chrome General
7.1
HIGH
EPSS
0.4%
2024 1 PoC

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-33899
Software Genérico General
7.1
HIGH
EPSS
1.0%
2024 1 PoC

RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape sequences.

CVE-2024-9284
TL-WR841ND General
7.1
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability was found in TP-LINK TL-WR841ND up to 20240920. It has been rated as critical. Affected by this issue is some unknown functionality of the file /userRpm/popupSiteSurveyRpm.htm. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-27164
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.1
HIGH
EPSS
0.1%
2024 CWE-259 1 PoC

Toshiba printers contain hardcoded credentials. As for the affected products/models/versions, see the reference URL.

CVE-2024-50301
Linux General
7.1
HIGH
EPSS
0.0%
2024 2 PoCs

In the Linux kernel, the following vulnerability has been resolved: security/keys: fix slab-out-of-bounds in key_task_permission KASAN reports an out of bounds read: BUG: KASAN: slab-out-of-bounds in __kuid_val include/linux/uidgid.h:36 BUG: KASAN: slab-out-of-bounds in uid_eq include/linux/uidgid.h:63 [inline] BUG: KASAN: slab-out-of-bounds in key_task_permission+0x394/0x410 security/keys/permission.c:54 Read of size 4 at addr ffff88813c3ab618 by task stress-ng/4362 CPU: 2 PID: 4362 Comm: stress-ng Not tainted 5.10.0-14930-gafbffd6c3ede #15 Call Trace: __dump_stack lib/dump_stack.c:82 [in

CVE-2024-11650
i9 General
7.1
HIGH
EPSS
0.1%
2024 CWE-476 1 PoC

A vulnerability was found in Tenda i9 1.0.0.8(3828) and classified as critical. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-40787
iOS and iPadOS General
7.1
HIGH
EPSS
0.0%
2024 3 PoCs

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. A shortcut may be able to bypass Internet permission requirements.

CVE-2024-28982
Pentaho Business Analytics Server General
7.1
HIGH
EPSS
0.2%
2024 CWE-776 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.

CVE-2024-47895
Graphics DDK General
7.1
HIGH
EPSS
0.0%
2024 CWE-823 1 PoC

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory.

CVE-2024-0206
Anti-Malware Engine General
7.1
HIGH
EPSS
0.1%
2024 CWE-59 1 PoC

A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an authenticated local user to potentially gain an escalation of privileges. This was achieved by adding an entry to the registry under the Trellix ENS registry folder with a symbolic link to files that the user wouldn't normally have permission to. After a scan, the Engine would follow the links and remove the files

CVE-2024-9875
Okta Privileged Access Server Agent (SFTD) General
7.1
HIGH
EPSS
0.1%
2024 CWE-20 1 PoC

Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. To remediate this vulnerability, upgrade the Okta Privileged Access server agent (SFTD) to version 1.87.1 or greater.