3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-0310
Trellix Endpoint Security (ENS) Web Control General
6.1
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

A content-security-policy vulnerability in ENS Control browser extension prior to 10.7.0 Update 15 allows a remote attacker to alter the response header parameter setting to switch the content security policy into report-only mode, allowing an attacker to bypass the content-security-policy configuration.

CVE-2024-46452
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A Host Header injection vulnerability in the password reset function of VigyBag Open Source Online Shop commit 3f0e21b allows attackers to redirect victim users to a malicious site via a crafted URL.

CVE-2024-31061
Software Genérico General
6.1
MEDIUM
EPSS
0.4%
2024 2 PoCs

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Last Name input field.

CVE-2024-2307
Software Genérico General
6.1
MEDIUM
EPSS
0.0%
2024 CWE-347 1 PoC

A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle attack, allowing untrusted code to be installed into an image being built.

CVE-2024-20876
Samsung Mobile Devices General
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to memory corruption.

CVE-2024-57372
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive information via the title, time and msg parameters

CVE-2024-57370
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain sensitive information via the w parameter.

CVE-2024-31065
Software Genérico General
6.1
MEDIUM
EPSS
0.4%
2024 2 PoCs

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the City input field.

CVE-2024-42341
QueueMetrics General
6.1
MEDIUM
EPSS
0.1%
2024 CWE-601 1 PoC

Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CVE-2024-24511
Software Genérico General
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title component.

CVE-2024-11044
automatic1111/stable-diffusion-webui General ⚡ nuclei
6.1
MEDIUM
EPSS
1.1%
2024 CWE-601 0 PoCs

An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials.

CVE-2024-55040
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross Site Scripting vulnerability in Sensaphone WEB600 Monitoring System v.1.6.5.H and before allows a remote attacker to execute arbitrary code via a crafted GET requests to /@.xml, placing payloads in the g7200, g7300, g4601, and g1F02 parameters.

CVE-2024-4768
Firefox General
6.1
MEDIUM
EPSS
0.7%
2024 1 PoC

A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

CVE-2024-1549
Firefox General
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVE-2024-38959
Software Genérico General
6.1
MEDIUM
EPSS
0.9%
2024 1 PoC

Cross Site Scripting vulnerability in Creativeitem Academy LMS Learning Management System v.6.8.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the string parameter.

CVE-2024-40817
Safari General
6.1
MEDIUM
EPSS
0.4%
2024 3 PoCs

The issue was addressed with improved UI handling. This issue is fixed in Safari 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Visiting a website that frames malicious content may lead to UI spoofing.

CVE-2024-31064
Software Genérico General
6.1
MEDIUM
EPSS
0.6%
2024 1 PoC

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the First Name input field.

CVE-2024-29216
cg6kwin2k.sys General
6.1
MEDIUM
EPSS
0.0%
2024 1 PoC

Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOCTL request, a user without the administrator privilege may perform I/O to arbitrary hardware port or physical address, resulting in erasing or altering the firmware.

CVE-2024-1932
freescout-helpdesk/freescout General
6.1
MEDIUM
EPSS
0.1%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in freescout-helpdesk/freescout

CVE-2024-27706
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross Site Scripting vulnerability in Huly Platform v.0.6.202 allows attackers to execute arbitrary code via upload of crafted SVG file to issues.