3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-57699
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, containing a large number of ’{’, a stack exhaustion can be trigger, which could allow an attacker to cause a Denial of Service (DoS). This issue exists because of an incomplete fix for CVE-2023-1370.

CVE-2024-52924
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in NRMM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. Lack of boundary check during the decoding of Registration Accept messages can lead to out-of-bounds writes on the stack

CVE-2024-41696
PRI WEB Portal Add-On for Priority ERP on prem General
7.5
HIGH
EPSS
0.4%
2024 CWE-200 1 PoC

Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-40815
iOS and iPadOS General
7.5
HIGH
EPSS
7.2%
2024 4 PoCs

A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

CVE-2024-42010
Software Genérico General
7.5
HIGH
EPSS
15.1%
2024 2 PoCs

mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker to obtain sensitive information.

CVE-2024-40829
iOS and iPadOS General
7.5
HIGH
EPSS
0.4%
2024 3 PoCs

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Ventura 13.6.8, watchOS 10.6. An attacker may be able to view restricted content from the lock screen.

CVE-2024-21644
pyload General ⚡ nuclei
7.5
HIGH
EPSS
86.5%
2024 CWE-284 1 PoC

pyLoad is the free and open-source Download Manager written in pure Python. Any unauthenticated user can browse to a specific URL to expose the Flask config, including the `SECRET_KEY` variable. This issue has been patched in version 0.5.0b3.dev77.

CVE-2024-49420
GamingHub General
7.5
HIGH
EPSS
1.4%
2024 1 PoC

Improper handling of responses in GamingHub prior to version 6.1.04.6 in Korea, 7.1.03.7 in Global allows remote attackers to launch arbitrary activity.

CVE-2024-38881
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Rainbow Table Password cracking attack due to the use of one-way hashes without salts when storing user passwords.

CVE-2024-54767
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
7.0%
2024 0 PoCs

An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sensitive information without authentication. NOTE: this is disputed by the Supplier because it cannot be reproduced, and the issue report focuses on an unintended configuration with direct Internet exposure.

CVE-2024-45272
mbCONNECT24 General
7.5
HIGH
EPSS
1.0%
2024 CWE-1391 1 PoC

An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.

CVE-2024-25736
Software Genérico General
7.5
HIGH
EPSS
9.1%
2024 1 PoC

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request.

CVE-2024-57716
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

An issue in trenoncourt AutoQueryable v.1.7.0 allows a remote attacker to obtain sensitive information via the Unselectable function.

CVE-2024-36496
WINSelect (Standard + Enterprise) General
7.5
HIGH
EPSS
0.3%
2024 CWE-798 2 PoCs

The configuration file is encrypted with a static key derived from a static five-character password which allows an attacker to decrypt this file. The application hashes this five-character password with the outdated and broken MD5 algorithm (no salt) and uses the first five bytes as the key for RC4. The configuration file is then encrypted with these parameters.

CVE-2024-55196
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.

CVE-2024-46292
Software Genérico General
7.5
HIGH
EPSS
0.8%
2024 1 PoC

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit (which are required by the claimed issue).

CVE-2024-40675
Android General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

In parseUriInternal of Intent.java, there is a possible infinite loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-0762
SecureCore™ for Intel Kaby Lake General
7.5
HIGH
EPSS
0.4%
2024 2 PoCs

Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCore™ for select Intel platforms This issue affects: Phoenix SecureCore™ for Intel Kaby Lake: from 4.0.1.1 before 4.0.1.998; Phoenix SecureCore™ for Intel Coffee Lake: from 4.1.0.1 before 4.1.0.562; Phoenix SecureCore™ for Intel Ice Lake: from 4.2.0.1 before 4.2.0.323; Phoenix SecureCore™ for Intel Comet Lake: from 4.2.1.1 before 4.2.1.287; Phoenix SecureCore™ for Intel Tiger Lake: from 4.3.0.1 before 4.3.0.236; Phoenix SecureCore™ for Intel Jasper Lake: from 4.3.1.1 before 4.3.1.184; Pho

CVE-2024-29384
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 2 PoCs

An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information via the content.js and parseCSSRules functions.

CVE-2024-46307
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.