3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-33664
Software Genérico General
5.3
MEDIUM
EPSS
0.2%
2024 1 PoC

python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a crafted JSON Web Encryption (JWE) token with a high compression ratio, aka a "JWT bomb." This is similar to CVE-2024-21319.

CVE-2024-0546
EasyFTP General
5.3
MEDIUM
EPSS
36.6%
2024 CWE-404 1 PoC

A vulnerability, which was classified as problematic, has been found in EasyFTP 1.7.0. This issue affects some unknown processing of the component LIST Command Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250715.

CVE-2024-4106
FAST/TOOLS General
5.3
MEDIUM
EPSS
0.1%
2024 CWE-258 1 PoC

A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwords set. Therefore, if the product is operated without a password set by default, an attacker can break into the affected product. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04 CI Server R1.01.00 to R1.03.00

CVE-2024-31486
OPUPI0 AMQP/MQTT General
5.3
MEDIUM
EPSS
0.1%
2024 CWE-312 2 PoCs

A vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected devices stores MQTT client passwords without sufficient protection on the devices. An attacker with remote shell access or physical access could retrieve the credentials leading to confidentiality loss.

CVE-2024-7920
Jieshun JieLink+ JSOTC2016 General
5.3
MEDIUM
EPSS
1.2%
2024 CWE-284 1 PoC

A vulnerability, which was classified as problematic, was found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805. Affected is an unknown function of the file /Report/ParkCommon/GetParkInThroughDeivces. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-0737
Xlight FTP Server General
5.3
MEDIUM
EPSS
1.9%
2024 CWE-404 1 PoC

A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1. This vulnerability affects unknown code of the component Login. The manipulation of the argument user leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251560.

CVE-2024-0579
X2000R General
5.3
MEDIUM
EPSS
0.8%
2024 CWE-77 1 PoC

A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDevice of the file /boafrm/formMapDelDevice. The manipulation of the argument macstr leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-21493
github.com/greenpau/caddy-security General
5.3
MEDIUM
EPSS
0.1%
2024 CWE-129 2 PoCs

All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when parsing a Caddyfile. Multiple parsing functions in the affected library do not validate whether their input values are nil before attempting to access elements, which can lead to a panic (index out of range). Panics during the parsing of a configuration file may introduce ambiguity and vulnerabilities, hindering the correct interpretation and configuration of the web server.

CVE-2024-7833
DI-8100 General
5.3
MEDIUM
EPSS
0.7%
2024 CWE-77 1 PoC

A vulnerability was found in D-Link DI-8100 16.07. It has been classified as critical. This affects the function upgrade_filter_asp of the file upgrade_filter.asp. The manipulation of the argument path leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-40094
Software Genérico General
5.3
MEDIUM
EPSS
17.5%
2024 3 PoCs

GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.

CVE-2024-41694
PineApp Mail Relay General
5.3
MEDIUM
EPSS
0.3%
2024 CWE-200 1 PoC

Cybonet - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-12346
Talentera General
5.3
MEDIUM
EPSS
0.1%
2024 CWE-79 2 PoCs

A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unknown code of the file /app/control/byt_cv_manager. The manipulation of the argument redirect_url leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The provided PoC only works in Mozilla Firefox. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-34589
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
1.1%
2024 1 PoC

Improper input validation in parsing RTCP RR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

CVE-2024-46979
xwiki-platform General
5.3
MEDIUM
EPSS
0.4%
2024 CWE-200 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification filters of any user by using a URL such as `<hostname>xwiki/bin/get/XWiki/Notifications/Code/NotificationFilterPreferenceLivetableResults?outputSyntax=plain&type=custom&user=<username>`. This vulnerability impacts all versions of XWiki since 13.2-rc-1. The filters do not provide much information (they mainly contain references which are public data in XWiki), though some info could be used in combination with other vulnerabilities. This vulnerabil

CVE-2024-34663
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.0%
2024 1 PoC

Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory.

CVE-2024-9906
Online Eyewear Shop General
5.3
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /admin/?page=inventory/view_inventory&id=2. The manipulation of the argument Code leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13042
Electronic Archives Management System General
5.3
MEDIUM
EPSS
0.0%
2024 CWE-200 1 PoC

A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802(62532). It has been classified as problematic. Affected is the function download of the file /Searchnew/Subject/download.html. The manipulation of the argument path leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-34473
Software Genérico General
5.3
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message type during xApp registration to disrupt other service components.

CVE-2024-43919
YARPP General ⚡ nuclei
5.3
MEDIUM
EPSS
84.5%
2024 CWE-862 1 PoC

Access Control vulnerability in YARPP YARPP allows . This issue affects YARPP: from n/a through 5.30.10.

CVE-2024-5121
Event Registration System General
5.3
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability was found in SourceCodester Event Registration System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /registrar/?page=registration. The manipulation of the argument e leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-265201 was assigned to this vulnerability.