3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-9399
Firefox General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

CVE-2024-7017
Chrome General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2024-34668
Samsung Mobile Devices General
7.5
HIGH
EPSS
5.1%
2024 1 PoC

Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2024-41696
PRI WEB Portal Add-On for Priority ERP on prem General
7.5
HIGH
EPSS
0.4%
2024 CWE-200 1 PoC

Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-28854
tls-listener General
7.5
HIGH
EPSS
0.2%
2024 CWE-400 1 PoC

tls-listener is a rust lang wrapper around a connection listener to support TLS. With the default configuration of tls-listener, a malicious user can open 6.4 `TcpStream`s a second, sending 0 bytes, and can trigger a DoS. The default configuration options make any public service using `TlsListener::new()` vulnerable to a slow-loris DoS attack. This impacts any publicly accessible service using the default configuration of tls-listener in versions prior to 0.10.0. Users are advised to upgrade. Users unable to upgrade may mitigate this by passing a large value, such as `usize::MAX` as the parame

CVE-2024-11322
PowerPanel Business General
7.5
HIGH
EPSS
0.8%
2024 CWE-287 1 PoC

A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote attacker can restart the ppbd.exe process via the PowerPanel Business Service Watchdog service listening on TCP port 2003. The attacker can repeatedly restart ppbd.exe to render it unavailable.

CVE-2024-38429
Tafnit v8 General
7.5
HIGH
EPSS
0.2%
2024 CWE-552 1 PoC

Matrix Tafnit v8 -  CWE-552: Files or Directories Accessible to External Parties

CVE-2024-42861
Software Genérico General
7.5
HIGH
EPSS
31.9%
2024 1 PoC

An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function

CVE-2024-23747
Software Genérico General
7.5
HIGH
EPSS
1.0%
2024 1 PoC

The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vulnerability resides in the system's handling of user data access through a /Modernanet/LAUDO/LAU0000100/Laudo?id= URI. By manipulating this id parameter, an attacker can gain access to sensitive medical information.

CVE-2024-27630
Software Genérico General
7.5
HIGH
EPSS
1.1%
2024 3 PoCs

Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file function.

CVE-2024-50650
Software Genérico General
7.5
HIGH
EPSS
0.5%
2024 1 PoC

python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

CVE-2024-57698
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, even after initial configuration and password change. This happens due to excessive exposure of information and the lack of adequate access control on the /user/list?culture=en-us endpoint.

CVE-2024-33818
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.

CVE-2024-40554
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information.

CVE-2024-28757
Software Genérico General
7.5
HIGH
EPSS
1.2%
2024 3 PoCs

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

CVE-2024-48125
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

An issue in the AsDB service of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to enumerate user credentials via crafted GIOP protocol requests.

CVE-2024-34669
Samsung Mobile Devices General
7.5
HIGH
EPSS
5.1%
2024 1 PoC

Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2024-23733
Software Genérico General
7.5
HIGH
EPSS
18.1%
2024 1 PoC

The /WmAdmin/,/invoke/vm.server/login login page in the Integration Server in Software AG webMethods 10.15.0 before Core_Fix7 allows remote attackers to reach the administration panel and discover hostname and version information by sending an arbitrary username and a blank password to the /WmAdmin/#/login/ URI.

CVE-2024-8198
Chrome General
7.5
HIGH
EPSS
0.3%
2024 CWE-122 2 PoCs

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-5803
Antivirus General
7.5
HIGH
EPSS
0.1%
2024 CWE-367 1 PoC

The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.