3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-11111
Chrome General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-10941
Firefox General
4.3
MEDIUM
EPSS
0.3%
2024 1 PoC

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

CVE-2024-7976
Chrome General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-51464
i General
4.3
MEDIUM
EPSS
0.4%
2024 CWE-288 2 PoCs

IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to remotely perform operations that the user is not allowed to perform when using Navigator for i.

CVE-2024-55417
Software Genérico General ⚡ nuclei
4.3
MEDIUM
EPSS
23.0%
2024 0 PoCs

DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.

CVE-2024-29215
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-284 1 PoC

Mattermost versions 9.5.x <= 9.5.3, 9.7.x <= 9.7.1, 9.6.x <= 9.6.1, 8.1.x <= 8.1.12 fail to enforce proper access control which allows a user to run a slash command in a channel they are not a member of via linking a playbook run to that channel and running a slash command as a playbook task command.

CVE-2024-8908
Chrome General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-0356
ssm_shiro_blog General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

A vulnerability has been found in Mandelo ssm_shiro_blog 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file updateRoles of the component Backend. The manipulation leads to improper access controls. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250123.

CVE-2024-39839
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-284 1 PoC

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their own remote username, when shared channels were enabled, which allows a user on a remote to set their remote username prop to an arbitrary string, which would be then synced to the local server as long as the user hadn't been synced before.

CVE-2024-47401
Mattermost General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-770 1 PoC

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in turn could cause the application to crash by sending a specially crafted request to Playbooks.

CVE-2024-20856
Samsung Mobile Devices General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario.

CVE-2024-11920
Chrome General
4.3
MEDIUM
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Dawn in Google Chrome on Mac prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2024-42338
CyberArk Identity Management General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-200 1 PoC

CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-8322
Endpoint Manager General
4.3
MEDIUM
EPSS
1.6%
2024 CWE-1390 1 PoC

Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.

CVE-2024-43105
Mattermost General
4.3
MEDIUM
EPSS
0.4%
2024 CWE-400 1 PoC

Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a user to consume excessive resource by running the /export command multiple times at once.

CVE-2024-50052
Mattermost General
4.3
MEDIUM
EPSS
0.3%
2024 CWE-862 1 PoC

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to check that the origin of the message in an integration action matches with the original post metadata which allows an authenticated user to delete an arbitrary post.

CVE-2024-6398
Secure Web Gateway General
4.3
MEDIUM
EPSS
0.1%
2024 CWE-200 1 PoC

An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows information stored in a customizable block page to be disclosed to third-party websites due to Same Origin Policy Bypass of browsers in certain scenarios. The risk is low, because other recommended default security policies such as URL categorization and GTI are in place in most policies to block access to uncategorized/high risk websites. Any information disclosed depends on how the

CVE-2024-1901
Server General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

Denial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authenticated user with specific PAM permissions to make PAM credentials unavailable.

CVE-2024-5689
Firefox General
4.3
MEDIUM
EPSS
0.7%
2024 1 PoC

In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.

CVE-2024-12148
Server General
4.3
MEDIUM
EPSS
0.2%
2024 CWE-863 1 PoC

Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.