3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-9962
Chrome General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-7975
Chrome General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

Inappropriate implementation in Permissions in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-57683
Software Genérico General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the filter settings of the device via a crafted POST request.

CVE-2024-4886
buddyboss-platform General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in the request

CVE-2024-5272
Mattermost General
4.3
MEDIUM
EPSS
0.3%
2024 CWE-284 1 PoC

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to restrict the audience of the "custom_playbooks_playbook_run_updated" webhook event, which allows a guest on a channel with a playbook run linked to see all the details of the playbook run when the run is marked by finished.

CVE-2024-31859
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper authorization checks which allows a member running a playbook in an existing channel to be promoted to a channel admin

CVE-2024-43780
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-284 1 PoC

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to upload files to a channel.

CVE-2024-55075
Grocy General
4.3
MEDIUM
EPSS
0.0%
2024 CWE-425 1 PoC

Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.

CVE-2024-1137
TIBCO ActiveSpaces - Enterprise Edition General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

The Proxy and Client components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Enterprise Edition contain a vulnerability that theoretically allows an Active Spaces client to passively observe data traffic to other clients. Affected releases are TIBCO Software Inc.'s TIBCO ActiveSpaces - Enterprise Edition: versions 4.4.0 through 4.9.0.

CVE-2024-32939
Mattermost General
4.3
MEDIUM
EPSS
0.3%
2024 CWE-284 1 PoC

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server."

CVE-2024-39908
rexml General
4.3
MEDIUM
EPSS
8.3%
2024 CWE-400 1 PoC

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific characters such as `<`, `0` and `%>`. If you need to parse untrusted XMLs, you many be impacted to these vulnerabilities. The REXML gem 3.3.2 or later include the patches to fix these vulnerabilities. Users are advised to upgrade. Users unable to upgrade should avoid parsing untrusted XML strings.

CVE-2024-25653
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unlimited Admin Mode is enabled, to view system reports and modify custom reports via the Report functionality in the Web UI.

CVE-2024-1887
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is not a member of the public channel to fetch the posts, which will not be audited in the compliance export. 

CVE-2024-11116
Chrome General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-7004
Chrome General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-20 1 PoC

Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low)

CVE-2024-49419
GamingHub General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to load an arbitrary URL in its webview.

CVE-2024-1888
Mattermost General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member with permissions to add other members but not to add guests to add a guest to a team as long as the guest was already a guest in another team of the server

CVE-2024-27707
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Server Side Request Forgery (SSRF) vulnerability in hcengineering Huly Platform v.0.6.202 allows attackers to run arbitrary code via upload of crafted SVG file.

CVE-2024-27592
Software Genérico General
4.3
MEDIUM
EPSS
0.1%
2024 2 PoCs

Open Redirect vulnerability in Corezoid Process Engine v6.5.0 allows attackers to redirect to arbitrary websites via appending a crafted link to /login/ in the login page URL.

CVE-2024-11111
Chrome General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)