3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-57386
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function.

CVE-2024-0953
Firefox for iOS General
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content. This vulnerability affects Firefox for iOS < 129.

CVE-2024-28140
Scan2Net General
6.1
MEDIUM
EPSS
0.1%
2024 CWE-250 2 PoCs

The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user. There are also several other applications running as root user. This can be confirmed by running "ps aux" as the root user and observing the output.

CVE-2024-24396
Software Genérico General
6.1
MEDIUM
EPSS
1.8%
2024 2 PoCs

Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component.

CVE-2024-57601
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter.

CVE-2024-24510
Software Genérico General
6.1
MEDIUM
EPSS
1.0%
2024 1 PoC

Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.

CVE-2024-33298
Software Genérico General
6.1
MEDIUM
EPSS
1.3%
2024 1 PoC

Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup

CVE-2024-1550
Firefox General
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVE-2024-34645
Samsung Mobile Devices General
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.

CVE-2024-44776
Software Genérico General
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.

CVE-2024-10812
binary-husky/gpt_academic General ⚡ nuclei
6.1
MEDIUM
EPSS
0.7%
2024 CWE-601 0 PoCs

An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is redirected to a URL specified by user-controlled input in the 'file' parameter without proper validation or sanitization. This can be exploited by attackers to conduct phishing attacks, distribute malware, and steal user credentials.

CVE-2024-2610
Firefox General
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVE-2024-2609
Firefox General
6.1
MEDIUM
EPSS
1.0%
2024 1 PoC

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

CVE-2024-20893
Samsung Mobile Devices General
6.1
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption.

CVE-2024-26542
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross Site Scripting vulnerability in Bonitasoft, S.A v.7.14. and fixed in v.9.0.2, 8.0.3, 7.15.7, 7.14.8 allows attackers to execute arbitrary code via a crafted payload to the Groups Display name field.

CVE-2024-42697
Software Genérico General
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to execute arbitrary code via the q parameter of the product search function.

CVE-2024-51423
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Cross Site Scripting vulnerability in Infor Global HR GHR v.11.23.03.00.21 and before allows a remote attacker to execute arbitrary code via the class parameter.

CVE-2024-28734
Software Genérico General ⚡ nuclei
6.1
MEDIUM
EPSS
11.3%
2024 1 PoC

Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted GET request using the cols parameter.

CVE-2024-0310
Trellix Endpoint Security (ENS) Web Control General
6.1
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration.

CVE-2024-5693
Firefox General
6.1
MEDIUM
EPSS
1.8%
2024 1 PoC

Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.