3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-22871
Software Genérico General
7.5
HIGH
EPSS
0.7%
2024 2 PoCs

An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function.

CVE-2024-21539
@eslint/plugin-kit General
7.5
HIGH
EPSS
0.2%
2024 CWE-1333 1 PoC

Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by exploiting this vulnerability.

CVE-2024-56067
WP SuperBackup General
7.5
HIGH
EPSS
62.3%
2024 CWE-862 1 PoC

Missing Authorization vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

CVE-2024-8751
SICK MSC800 General
7.5
HIGH
EPSS
0.1%
2024 CWE-306 1 PoC

A vulnerability in the MSC800 allows an unauthenticated attacker to modify the product’s IP address over Sopas ET. This can lead to Denial of Service. Users are recommended to upgrade both MSC800 and MSC800 LFT to version V4.26 and S2.93.20 respectively which fixes this issue.

CVE-2024-33655
Software Genérico General
7.5
HIGH
EPSS
3.6%
2024 2 PoCs

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.

CVE-2024-52884
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.

CVE-2024-21907
Software Genérico General
7.5
HIGH
EPSS
2.9%
2024 CWE-755 2 PoCs

Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.

CVE-2024-52883
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication.

CVE-2024-21522
audify General
7.5
HIGH
EPSS
0.3%
2024 CWE-129 1 PoC

All versions of the package audify are vulnerable to Improper Validation of Array Index when frameSize is provided to the new OpusDecoder().decode or new OpusDecoder().decodeFloat functions it is not checked for negative values. This can lead to a process crash.

CVE-2024-33217
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter in ip/goform/addressNat.

CVE-2024-45248
Multi-DNC General
7.5
HIGH
EPSS
0.3%
2024 CWE-35 1 PoC

Multi-DNC – CWE-35: Path Traversal: '.../...//'

CVE-2024-23302
Software Genérico General
7.5
HIGH
EPSS
0.6%
2024 2 PoCs

Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.

CVE-2024-0760
BIND 9 General
7.5
HIGH
EPSS
16.7%
2024 1 PoC

A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.

CVE-2024-5803
Antivirus General
7.5
HIGH
EPSS
0.1%
2024 CWE-367 1 PoC

The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to time-of-use (TOCTOU) when self protection is disabled.

CVE-2024-46471
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information.

CVE-2024-22851
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 2 PoCs

Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint.

CVE-2024-51739
iTop General ⚡ nuclei
7.5
HIGH
EPSS
31.6%
2024 CWE-200 0 PoCs

Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to bruteforce a valid account. As a fix the sentence displayed after resetting password no longer shows if the user exists or not. This fix is included in versions 2.7.11, 3.0.5, 3.1.2, and 3.2.0. Users are advised to upgrade. Users unable to upgrade may overload the dictionary entry `"UI:ResetPwd-Error-WrongLogin"` through an extension and replace it with a generic message.

CVE-2024-47916
Boa web server 0.94.14rc21 General
7.5
HIGH
EPSS
0.4%
2024 CWE-22 1 PoC

Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2024-40803
macOS General
7.5
HIGH
EPSS
0.3%
2024 2 PoCs

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An attacker may be able to cause unexpected app termination.