3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-1819
Membership Management System General
4.7
MEDIUM
EPSS
0.1%
2024 CWE-434 1 PoC

A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the component Add Members Tab. The manipulation of the argument Member Photo leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254607.

CVE-2024-0929
AC10U General
4.7
MEDIUM
EPSS
0.2%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda AC10U 15.03.06.49_multi_TDE01. It has been rated as critical. Affected by this issue is the function fromNatStaticSetting. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252134 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-25676
Software Genérico General
4.7
MEDIUM
EPSS
0.1%
2024 2 PoCs

An issue was discovered in ViewerJS 0.5.8. A script from the component loads content via URL TAGs without properly sanitizing it. This leads to both open redirection and out-of-band resource loading.

CVE-2024-9266
express General
4.7
MEDIUM
EPSS
0.1%
2024 CWE-601 1 PoC

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from 3.4.5 before 4.0.0.

CVE-2024-2201
Xen General
4.7
MEDIUM
EPSS
0.0%
2024 1 PoC

A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fine(IBT), and to leak arbitrary Linux kernel memory on Intel systems.

CVE-2024-48197
Software Genérico General
4.7
MEDIUM
EPSS
4.5%
2024 1 PoC

Cross Site Scripting vulnerability in Audiocodes MP-202b v.4.4.3 allows a remote attacker to escalate privileges via the login page of the web interface.

CVE-2024-33299
Software Genérico General
4.7
MEDIUM
EPSS
1.1%
2024 1 PoC

Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users

CVE-2024-0925
AC10U General
4.7
MEDIUM
EPSS
0.2%
2024 CWE-121 1 PoC

A vulnerability has been found in Tenda AC10U 15.03.06.49_multi_TDE01 and classified as critical. This vulnerability affects the function formSetVirtualSer. The manipulation of the argument list leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-252130 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-54910
Software Genérico General
4.7
MEDIUM
EPSS
1.2%
2024 1 PoC

Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.

CVE-2024-5691
Firefox General
4.7
MEDIUM
EPSS
0.2%
2024 1 PoC

By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

CVE-2024-8071
Mattermost General
4.7
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as system admin which allows a System Role with edit access to the permissions section of system console to update their role (e.g. member) to include the `manage_system` permission, effectively becoming a System Admin.

CVE-2024-30052
Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) General
4.7
MEDIUM
EPSS
1.8%
2024 CWE-693 1 PoC

Visual Studio Remote Code Execution Vulnerability

CVE-2024-34639
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.

CVE-2024-40813
iOS and iPadOS General
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

A lock screen issue was addressed with improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data.

CVE-2024-40818
iOS and iPadOS General
4.6
MEDIUM
EPSS
0.1%
2024 4 PoCs

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data.

CVE-2024-49402
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles.

CVE-2024-20882
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.3%
2024 1 PoC

Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.

CVE-2024-24857
Linux kernel General
4.6
MEDIUM
EPSS
0.0%
2024 CWE-362 1 PoC

A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to bluetooth connection abnormality or denial of service.

CVE-2024-24859
Linux kernel General
4.6
MEDIUM
EPSS
0.0%
2024 CWE-362 1 PoC

A race condition was found in the Linux kernel's net/bluetooth in sniff_{min,max}_interval_set() function. This can result in a bluetooth sniffing exception issue, possibly leading denial of service.

CVE-2024-24858
Linux kernel General
4.6
MEDIUM
EPSS
0.0%
2024 CWE-362 1 PoC

A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading to denial of service.