3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-24455
HPE Athonet Core General
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

An invalid memory access when handling a UE Context Release message containing an invalid UE identifier in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

CVE-2024-40774
iOS and iPadOS General
5.9
MEDIUM
EPSS
0.0%
2024 3 PoCs

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.

CVE-2024-34273
Software Genérico General
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method.

CVE-2024-56087
Software Genérico General
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.

CVE-2024-35910
Linux General
5.8
MEDIUM
EPSS
0.0%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: tcp: properly terminate timers for kernel sockets We had various syzbot reports about tcp timers firing after the corresponding netns has been dismantled. Fortunately Josef Bacik could trigger the issue more often, and could test a patch I wrote two years ago. When TCP sockets are closed, we call inet_csk_clear_xmit_timers() to 'stop' the timers. inet_csk_clear_xmit_timers() can be called from any context, including when socket lock is held. This is the reason it uses sk_stop_timer(), aka del_timer(). This means that ongo

CVE-2024-8321
Endpoint Manager General
5.8
MEDIUM
EPSS
0.5%
2024 CWE-306 1 PoC

Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.

CVE-2024-23983
PingAccess General
5.8
MEDIUM
EPSS
0.1%
2024 CWE-20 1 PoC

Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.

CVE-2024-43035
Fonoster General
5.8
MEDIUM
EPSS
0.4%
2024 CWE-24 1 PoC

Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file VoiceServer endpoint. This occurs in serveFiles in mods/voice/src/utils.ts. NOTE: serveFiles exists in 0.5.5 but not in the next release, 0.6.1.

CVE-2024-52017
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-52014
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at genie_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-55415
Software Genérico General ⚡ nuclei
5.7
MEDIUM
EPSS
59.7%
2024 0 PoCs

DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.

CVE-2024-51006
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the ipv6_static_ip parameter in the ipv6_tunnel function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-51000
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component wireless.cgi via the opmode, opmode_an, and opmode_an_2 parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-52026
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at bsw_pppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-51001
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the sysDNSHost parameter at ddns.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-51019
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pppoe_localnetmask parameter at pppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-51020
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the apn parameter at usbISP_detail_edit.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-51014
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the ssid_an parameter in bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-51007
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at wireless.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-51018
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.