3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-39929
Software Genérico General
5.4
MEDIUM
EPSS
60.3%
2024 2 PoCs

Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filename extension-blocking protection mechanism, and potentially deliver executable attachments to the mailboxes of end users.

CVE-2024-54997
Software Genérico General
5.4
MEDIUM
EPSS
0.3%
2024 1 PoC

MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit.

CVE-2024-53976
Firefox for iOS General
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.

CVE-2024-27703
Software Genérico General
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do title parameter.

CVE-2024-29833
PhotoGallery General
5.4
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by using a Cross Site Scripting payload which does not match the regular expression; one example of this is the inclusion of whitespace within the script tag. An attacker must target an authenticated user with permissions to access this feature, however once uploaded the payload is also accessible to unauthenticated users.

CVE-2024-29506
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.

CVE-2024-24397
Software Genérico General
5.4
MEDIUM
EPSS
1.2%
2024 2 PoCs

Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the ReportName field.

CVE-2024-51463
i General
5.4
MEDIUM
EPSS
1.1%
2024 CWE-918 1 PoC

IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

CVE-2024-37672
Software Genérico General
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the idactivity parameter.

CVE-2024-11695
Firefox General
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

CVE-2024-37671
Software Genérico General
5.4
MEDIUM
EPSS
0.5%
2024 1 PoC

Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the page parameter.

CVE-2024-37856
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2024 2 PoCs

Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the first, last, middle name fields in the User Profile page.

CVE-2024-29507
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2024 2 PoCs

Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont parameters.

CVE-2024-10460
Firefox General
5.4
MEDIUM
EPSS
0.4%
2024 1 PoC

The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVE-2024-8021
gradio-app/gradio General ⚡ nuclei
5.4
MEDIUM
EPSS
2.4%
2024 CWE-601 0 PoCs

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-controlled site.

CVE-2024-9160
PEADM Forge Module General
5.4
MEDIUM
EPSS
0.0%
2024 CWE-295 1 PoC

In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.

CVE-2024-54998
Software Genérico General
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create.

CVE-2024-42406
Mattermost General
5.4
MEDIUM
EPSS
0.3%
2024 CWE-284 1 PoC

Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize requests when viewing archived channels is disabled, which allows an attacker to retrieve post and file information about archived channels. Examples are flagged or unread posts as well as files.

CVE-2024-20829
Samsung Internet General
5.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Missing proper interaction for opening deeplink in Samsung Internet prior to version v24.0.0.0 allows remote attackers to open an application without proper interaction.

CVE-2024-28435
Software Genérico General
5.4
MEDIUM
EPSS
0.2%
2024 1 PoC

The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.