3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-55568
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The absence of a NULL check leads to a Denial of Service when an attacker sends malformed MM packets to the target.

CVE-2024-4558
Chrome General
7.5
HIGH
EPSS
2.4%
2024 4 PoCs

Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-34619
Samsung Mobile Devices General
7.5
HIGH
EPSS
1.5%
2024 1 PoC

Improper input validation in librtp.so prior to SMR Aug-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2024-8859
mlflow/mlflow General ⚡ nuclei
7.5
HIGH
EPSS
25.7%
2024 CWE-29 0 PoCs

A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary file read vulnerability. This issue occurs because only the path part of the URL is checked, while parts such as query and parameters are not handled. The vulnerability is triggered if the user has configured the dbfs service, and during usage, the service is mounted to a local directory.

CVE-2024-37568
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.)

CVE-2024-28340
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.

CVE-2024-11067
DSL6740C General
7.5
HIGH
EPSS
0.3%
2024 CWE-23 1 PoC

The D-Link DSL6740C modem has a Path Traversal Vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files. Additionally, since the device's default password is a combination of the MAC address, attackers can obtain the MAC address through this vulnerability and attempt to log in to the device using the default password.

CVE-2024-24451
Software Genérico General
7.5
HIGH
EPSS
1.9%
2024 2 PoCs

A stack overflow in the sctp_server::sctp_receiver_thread component of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface.

CVE-2024-32406
Software Genérico General
7.5
HIGH
EPSS
2.8%
2024 1 PoC

Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue Exam Tickets function.

CVE-2024-48024
Keep Backup Daily General
7.5
HIGH
EPSS
0.8%
2024 CWE-497 1 PoC

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Fahad Mahmood Keep Backup Daily keep-backup-daily allows Retrieve Embedded Sensitive Data.This issue affects Keep Backup Daily: from n/a through <= 2.1.3.

CVE-2024-8751
SICK MSC800 General
7.5
HIGH
EPSS
0.1%
2024 CWE-306 1 PoC

A vulnerability in the MSC800 allows an unauthenticated attacker to modify the product’s IP address over Sopas ET. This can lead to Denial of Service. Users are recommended to upgrade both MSC800 and MSC800 LFT to version V4.26 and S2.93.20 respectively which fixes this issue.

CVE-2024-21521
@discordjs/opus General
7.5
HIGH
EPSS
0.2%
2024 CWE-400 1 PoC

All versions of the package @discordjs/opus are vulnerable to Denial of Service (DoS) due to providing an input object with a property toString to several different functions. Exploiting this vulnerability could lead to a system crash.

CVE-2024-39033
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII to be stolen.

CVE-2024-6291
Chrome General
7.5
HIGH
EPSS
0.3%
2024 CWE-416 1 PoC

Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-44083
Software Genérico General
7.5
HIGH
EPSS
11.7%
2024 2 PoCs

ida64.dll in Hex-Rays IDA Pro through 8.4 crashes when there is a section that has many jumps linked, and the final jump corresponds to the payload from where the actual entry point will be invoked. NOTE: in many use cases, this is an inconvenience but not a security issue.

CVE-2024-45276
mbNET.mini General
7.5
HIGH
EPSS
0.5%
2024 CWE-306 1 PoC

An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.

CVE-2024-41695
PineApp Mail Relay General
7.5
HIGH
EPSS
0.7%
2024 CWE-22 1 PoC

Cybonet - CWE-22: Improper Limitation of a Pathname to a Restricted Directory

CVE-2024-34950
Software Genérico General
7.5
HIGH
EPSS
14.5%
2024 1 PoC

D-Link DIR-822+ v1.0.5 was discovered to contain a stack-based buffer overflow vulnerability in the SetNetworkTomographySettings module.

CVE-2024-49420
GamingHub General
7.5
HIGH
EPSS
1.4%
2024 1 PoC

Improper handling of responses in GamingHub prior to version 6.1.04.6 in Korea, 7.1.03.7 in Global allows remote attackers to launch arbitrary activity.

CVE-2024-38881
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Rainbow Table Password cracking attack due to the use of one-way hashes without salts when storing user passwords.