3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-49757
zitadel General ⚡ nuclei
7.5
HIGH
EPSS
10.8%
2024 CWE-287 0 PoCs

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way. Versions 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.

CVE-2024-33662
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.

CVE-2024-48142
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

CVE-2024-50650
Software Genérico General
7.5
HIGH
EPSS
0.5%
2024 1 PoC

python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

CVE-2024-11392
Transformers General
7.5
HIGH
EPSS
59.3%
2024 CWE-502 1 PoC

Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of configuration files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vul

CVE-2024-37728
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
13.5%
2024 0 PoCs

Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the "Pic/Indexes" interface

CVE-2024-21502
fastecdsa General
7.5
HIGH
EPSS
0.1%
2024 CWE-457 1 PoC

Versions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Variable on the stack, via the curvemath_mul function in src/curveMath.c, due to being used and interpreted as user-defined type. Depending on the variable's actual value it could be arbitrary free(), arbitrary realloc(), null pointer dereference and other. Since the stack can be controlled by the attacker, the vulnerability could be used to corrupt allocator structure, leading to possible heap exploitation. The attacker could cause denial of service by exploiting this vulnerability.

CVE-2024-55272
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function.

CVE-2024-21523
images General
7.5
HIGH
EPSS
0.2%
2024 CWE-400 1 PoC

All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. This makes it possible to reach an assert macro, leading to a process crash. **Note:** By providing some specific integer values (like 0) to the size function, it is possible to obtain a Segmentation fault error, leading to the process crash.

CVE-2024-47915
VaeMendis Ubooquity version 2.1.2 General
7.5
HIGH
EPSS
0.3%
2024 CWE-200 1 PoC

VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-21484
jsrsasign General
7.5
HIGH
EPSS
0.2%
2024 CWE-203 4 PoCs

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. Workaround The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.

CVE-2024-33437
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

An issue in CSS Exfil Protection v.1.1.0 allows a remote attacker to obtain sensitive information due to missing support for CSS Style Rules.

CVE-2024-38879
Omnivise T3000 Application Server R9.2 General
7.5
HIGH
EPSS
1.3%
2024 CWE-20 1 PoC

A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). The affected system exposes the port of an internal application on the public network interface allowing an attacker to circumvent authentication and directly access the exposed application.

CVE-2024-49196
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 2 PoCs

An issue was discovered in the GPU in Samsung Mobile Processor Exynos 1480 and 2400. Type confusion leads to a Denial of Service.

CVE-2024-33217
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter in ip/goform/addressNat.

CVE-2024-39033
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

In Newgensoft OmniDocs 11.0_SP1_03_006, Insecure Direct Object Reference (IDOR) in the getuserproperty function allows user's configuration and PII to be stolen.

CVE-2024-23660
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the device time is the only entropy source, leading to economic losses, as exploited in the wild in July 2023. An attacker can systematically generate mnemonics for each timestamp within an applicable timeframe, and link them to specific wallet addresses in order to steal funds from those wallets.

CVE-2024-34659
Group Sharing General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victim to join the group.

CVE-2024-23766
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An unauthenticated GET request to a specific URL triggers the reboot of the Anybus gateway (or at least most of its modules). An attacker can use this feature to carry out a denial of service attack by continuously sending GET requests to that URL.

CVE-2024-31846
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor.