3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-34661
Samsung Assistant General
4.3
MEDIUM
EPSS
0.4%
2024 1 PoC

Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering this vulnerability.

CVE-2024-45250
iClock v3.1-168 General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-200 1 PoC

ZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-37147
glpi General
4.3
MEDIUM
EPSS
13.0%
2024 CWE-284 1 PoC

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can attach a document to any item, even if the user has no write access on it. Upgrade to 10.0.16.

CVE-2024-6534
Directus General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-639 1 PoC

Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to another user. This is possible because the application only validates the user parameter in the 'POST /presets' request but not in the PATCH request. When chained with CVE-2024-6533, it could result in account takeover.

CVE-2024-42339
CyberArk Identity Management General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-200 1 PoC

CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-9155
Mattermost General
4.3
MEDIUM
EPSS
0.3%
2024 CWE-863 1 PoC

Mattermost versions 9.10.x <= 9.10.1, 9.9.x <= 9.9.2, 9.5.x <= 9.5.8 fail to limit access to channels files that have not been linked to a post which allows an attacker to view them in channels that they are a member of.

CVE-2024-43780
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-284 1 PoC

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.

CVE-2024-8909
Chrome General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-4182
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-754 1 PoC

Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing errors in custom status values, which allows an authenticated attacker to crash other users' web clients via a malformed custom status.

CVE-2024-1887
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is not a member of the public channel to fetch the posts, which will not be audited in the compliance export. 

CVE-2024-2446
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-400 1 PoC

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to limit the number of @-mentions processed per message, allowing an authenticated attacker to crash the client applications of other users via large, crafted messages.

CVE-2024-7981
Chrome General
4.3
MEDIUM
EPSS
0.5%
2024 1 PoC

Inappropriate implementation in Views in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-5936
imartinez/privategpt General ⚡ nuclei
4.3
MEDIUM
EPSS
2.1%
2024 CWE-601 0 PoCs

An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allows attackers to redirect users to a URL specified by user-controlled input without proper validation or sanitization. The impact of this vulnerability includes potential phishing attacks, malware distribution, and credential theft.

CVE-2024-5270
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-284 1 PoC

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to check if the email signup configuration option is enabled when a user requests to switch from SAML to Email. This allows the user to switch their authentication mail from SAML to email and possibly edit personal details that were otherwise non-editable and provided by the SAML provider.

CVE-2024-41698
Priority General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-200 1 PoC

Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-1942
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-284 1 PoC

Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing permalinks under specific conditions, which allows an authenticated attacker to access the contents of individual posts in channels they are not a member of.

CVE-2024-26312
Software Genérico General
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

Archer Platform 6 before 2024.03 contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning message.

CVE-2024-56378
Software Genérico General
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.

CVE-2024-7003
Chrome General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-38394
Software Genérico General
4.3
MEDIUM
EPSS
0.0%
2024 3 PoCs

Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kernel's underlying device matching logic allow a physically proximate attacker to access some unintended Linux kernel USB functionality, such as USB device-specific kernel modules and filesystem implementations. NOTE: the GSD supplier indicates that consideration of a mitigation for this within GSD would be in the context of "a new feature, not a CVE."