3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-10930
Block Load General
7.1
HIGH
EPSS
1.5%
2024 CWE-427 1 PoC

An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking and execute arbitrary code with escalated privileges.

CVE-2024-28736
Software Genérico General
7.1
HIGH
EPSS
1.3%
2024 1 PoC

An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page function.

CVE-2024-44258
iOS and iPadOS General
7.1
HIGH
EPSS
1.7%
2024 2 PoCs

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.

CVE-2024-52506
graylog2-server General
7.1
HIGH
EPSS
0.4%
2024 CWE-200 2 PoCs

Graylog is a free and open log management platform. The reporting functionality in Graylog allows the creation and scheduling of reports which contain dashboard widgets displaying individual log messages or metrics aggregated from fields of multiple log messages. This functionality, as included in Graylog 6.1.0 & 6.1.1, is vulnerable to information leakage triggered by multiple concurrent report rendering requests from authorized users. When multiple report renderings are requested at the same start time, the headless browser instance used to render the PDF will be reused. Depending on the tim

CVE-2024-56084
Software Genérico General
7.1
HIGH
EPSS
2.6%
2024 CWE-77 1 PoC

An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.

CVE-2024-9284
TL-WR841ND General
7.1
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability was found in TP-LINK TL-WR841ND up to 20240920. It has been rated as critical. Affected by this issue is some unknown functionality of the file /userRpm/popupSiteSurveyRpm.htm. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-56086
Software Genérico General
7.1
HIGH
EPSS
2.6%
2024 1 PoC

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution.

CVE-2024-40492
Software Genérico General
7.1
HIGH
EPSS
7.7%
2024 1 PoC

Cross Site Scripting vulnerability in Heartbeat Chat v.15.2.1 allows a remote attacker to execute arbitrary code via the setname function.

CVE-2024-42004
Teams (work or school) General
7.1
HIGH
EPSS
0.1%
2024 CWE-347 1 PoC

A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.

CVE-2024-27164
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.1
HIGH
EPSS
0.1%
2024 CWE-259 1 PoC

Toshiba printers contain hardcoded credentials. As for the affected products/models/versions, see the reference URL.

CVE-2024-7396
JetPort 5601v3 General
7.1
HIGH
EPSS
0.1%
2024 CWE-311 2 PoCs

Missing encryption of sensitive data in Korenix JetPort 5601v3 allows Eavesdropping.This issue affects JetPort 5601v3: through 1.2.

CVE-2024-47191
Software Genérico General
7.1
HIGH
EPSS
0.1%
2024 1 PoC

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink.

CVE-2024-50301
Linux General
7.1
HIGH
EPSS
0.0%
2024 2 PoCs

In the Linux kernel, the following vulnerability has been resolved: security/keys: fix slab-out-of-bounds in key_task_permission KASAN reports an out of bounds read: BUG: KASAN: slab-out-of-bounds in __kuid_val include/linux/uidgid.h:36 BUG: KASAN: slab-out-of-bounds in uid_eq include/linux/uidgid.h:63 [inline] BUG: KASAN: slab-out-of-bounds in key_task_permission+0x394/0x410 security/keys/permission.c:54 Read of size 4 at addr ffff88813c3ab618 by task stress-ng/4362 CPU: 2 PID: 4362 Comm: stress-ng Not tainted 5.10.0-14930-gafbffd6c3ede #15 Call Trace: __dump_stack lib/dump_stack.c:82 [in

CVE-2024-11650
i9 General
7.1
HIGH
EPSS
0.1%
2024 CWE-476 1 PoC

A vulnerability was found in Tenda i9 1.0.0.8(3828) and classified as critical. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation leads to null pointer dereference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-9875
Okta Privileged Access Server Agent (SFTD) General
7.1
HIGH
EPSS
0.1%
2024 CWE-20 1 PoC

Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. To remediate this vulnerability, upgrade the Okta Privileged Access server agent (SFTD) to version 1.87.1 or greater.

CVE-2024-45178
Software Genérico General
7.1
HIGH
EPSS
1.7%
2024 3 PoCs

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary files from the C-MOR system via a path traversal attack. It was found out that different functionalities are vulnerable to path traversal attacks, due to insufficient user input validation. For instance, the download functionality for backups provided by the script download-bkf.pml is vulnerable to a path traversal attack via the parameter bkf. This enables an authenticated user to download arbitrary files as Linux user www-data from the C-MOR syst

CVE-2024-40787
iOS and iPadOS General
7.1
HIGH
EPSS
0.0%
2024 3 PoCs

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. A shortcut may be able to bypass Internet permission requirements.

CVE-2024-28982
Pentaho Business Analytics Server General
7.1
HIGH
EPSS
0.2%
2024 CWE-776 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.

CVE-2024-47895
Graphics DDK General
7.1
HIGH
EPSS
0.0%
2024 CWE-823 1 PoC

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory.

CVE-2024-40799
iOS and iPadOS General
7.1
HIGH
EPSS
0.0%
2024 4 PoCs

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.