3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-12970
Pardus OS My Computer General
3.9
LOW
EPSS
2.0%
2024 CWE-78 1 PoC

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection.This issue affects Pardus OS My Computer: before 0.7.2.

CVE-2024-1898
Server General
3.9
LOW
EPSS
0.1%
2024 1 PoC

Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privileged user to change notifications settings configured by an administrator.

CVE-2024-2317
Hospital AutoManager General
3.8
LOW
EPSS
0.1%
2024 CWE-285 1 PoC

A vulnerability was found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This issue affects some unknown processing of the file /prescription/prescription/delete/ of the component Prescription Page. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256271. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-39837
Mattermost General
3.8
LOW
EPSS
0.3%
2024 CWE-284 1 PoC

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled.

CVE-2024-36287
Mattermost General
3.8
LOW
EPSS
0.0%
2024 CWE-693 1 PoC

Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.

CVE-2024-2606
Firefox General
3.7
LOW
EPSS
0.2%
2024 1 PoC

Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values. This vulnerability affects Firefox < 124.

CVE-2024-9506
vue General
3.7
LOW
EPSS
0.0%
2024 CWE-1333 1 PoC

Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability.

CVE-2024-0944
T8 General
3.7
LOW
EPSS
1.6%
2024 CWE-613 3 PoCs

A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252188. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2918
Server General
3.6
LOW
EPSS
0.1%
2024 1 PoC

Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to forge the displayed group in the PAM JIT elevation checkout request via a specially crafted request.

CVE-2024-4853
editcap General
3.6
LOW
EPSS
0.1%
2024 CWE-762 1 PoC

Memory handling issue in editcap could cause denial of service via crafted capture file

CVE-2024-56433
shadow-utils General
3.6
LOW
EPSS
4.5%
2024 CWE-1188 1 PoC

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subui

CVE-2024-4855
editcap General
3.6
LOW
EPSS
0.0%
2024 CWE-416 3 PoCs

Use after free issue in editcap could cause denial of service via crafted capture file

CVE-2024-58248
nopCommerce General
3.5
LOW
EPSS
0.1%
2024 CWE-362 1 PoC

nopCommerce through 4.90.1 does not offer locking for order placement. Thus there is a race condition with duplicate redeeming of gift cards.

CVE-2024-1028
Facebook News Feed Like General
3.5
LOW
EPSS
0.0%
2024 CWE-79 1 PoC

A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Post Handler. The manipulation of the argument Description with the input <marquee>HACKED</marquee> leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252301 was assigned to this vulnerability.

CVE-2024-23790
OTRS General
3.5
LOW
EPSS
0.2%
2024 CWE-20 1 PoC

Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from 7.0.X through 7.0.48, from 8.0.X through 8.0.37, from 2023 through 2023.1.1.

CVE-2024-1024
Facebook News Feed Like General
3.5
LOW
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. This vulnerability affects unknown code of the component New Account Handler. The manipulation of the argument First Name/Last Name with the input <script>alert(1)</script> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252292.

CVE-2024-24975
Mattermost Mobile General
3.5
LOW
EPSS
0.1%
2024 CWE-400 1 PoC

Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the size of the code block that will be processed by the syntax highlighter, allowing an attacker to send a very large code block and crash the mobile app.

CVE-2024-1020
Rebuild General
3.5
LOW
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability classified as problematic was found in Rebuild up to 3.5.5. Affected by this vulnerability is the function getStorageFile of the file /filex/proxy-download. The manipulation of the argument url leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252289 was assigned to this vulnerability.

CVE-2024-0720
FactoInvestigate General
3.5
LOW
EPSS
0.1%
2024 CWE-79 2 PoCs

A vulnerability, which was classified as problematic, was found in FactoMineR FactoInvestigate up to 1.9. Affected is an unknown function of the component HTML Report Generator. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-251544. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-52757
Software Genérico General
3.5
LOW
EPSS
0.1%
2024 1 PoC

D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the notify parameter in the arp_sys_asp function.