3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-27460
Plantronics Hub General
6.7
MEDIUM
EPSS
2.5%
2024 3 PoCs

A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.

CVE-2024-38433
NPCM7xx (Poleg) BootBlock General
6.7
MEDIUM
EPSS
0.0%
2024 CWE-305 1 PoC

Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code execution.

CVE-2024-8441
Endpoint Manager General
6.7
MEDIUM
EPSS
0.7%
2024 CWE-427 1 PoC

An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.

CVE-2024-39580
PowerScale InsightIQ General
6.7
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

CVE-2024-1395
Arm 5th Gen GPU Architecture Kernel Driver General
6.7
MEDIUM
EPSS
0.1%
2024 CWE-416 1 PoC

Use After Free vulnerability in Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory. This issue affects Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.

CVE-2024-20865
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.

CVE-2024-20043
MT6739, MT6757, MT6761, MT6763, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6833, MT6853, MT6873, MT6877, MT6885, MT6893, MT8167, MT8168, MT8173, MT8175, MT8185, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8395, MT8666, MT8673, MT8678, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8796, MT8797, MT8798 General
6.6
MEDIUM
EPSS
0.0%
2024 1 PoC

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541781; Issue ID: ALPS08541781.

CVE-2024-20817
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

CVE-2024-20042
MT6739, MT6757, MT6761, MT6763, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6833, MT6853, MT6873, MT6877, MT6885, MT6893, MT8167, MT8168, MT8173, MT8175, MT8183, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8395, MT8666, MT8673, MT8678, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8796, MT8797, MT8798 General
6.6
MEDIUM
EPSS
0.0%
2024 1 PoC

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541780; Issue ID: ALPS08541780.

CVE-2024-20046
MT6761, MT6765, MT6768, MT6789, MT6833, MT6855, MT6895, MT8167, MT8168, MT8188, MT8321, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791T, MT8797, MT8798 General
6.6
MEDIUM
EPSS
0.1%
2024 1 PoC

In battery, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08485622; Issue ID: ALPS08485622.

CVE-2024-56264
ACF City Selector General
6.6
MEDIUM
EPSS
13.8%
2024 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Beee ACF City Selector acf-city-selector allows Upload a Web Shell to a Web Server.This issue affects ACF City Selector: from n/a through <= 1.14.0.

CVE-2024-20818
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

CVE-2024-34681
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper input validation in BluetoothAdapter prior to SMR Nov-2024 Release 1 allows local attackers to cause local permanent denial of service on Galaxy Watch.

CVE-2024-41629
Software Genérico General
6.6
MEDIUM
EPSS
0.0%
2024 2 PoCs

An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive information via the plaintext storage of credentials

CVE-2024-32228
Software Genérico General
6.6
MEDIUM
EPSS
0.4%
2024 1 PoC

FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.

CVE-2024-40441
Software Genérico General
6.6
MEDIUM
EPSS
0.6%
2024 1 PoC

An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via the model_attribs parameter.

CVE-2024-20044
MT6739, MT6757, MT6761, MT6763, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6833, MT6853, MT6873, MT6877, MT6885, MT6893, MT8167, MT8168, MT8173, MT8175, MT8185, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8395, MT8666, MT8673, MT8678, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8796, MT8797, MT8798 General
6.6
MEDIUM
EPSS
0.0%
2024 1 PoC

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541784; Issue ID: ALPS08541784.

CVE-2024-34646
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.

CVE-2024-48987
Software Genérico General
6.6
MEDIUM
EPSS
2.7%
2024 1 PoC

Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.

CVE-2024-22724
Software Genérico General
6.6
MEDIUM
EPSS
0.0%
2024 1 PoC

An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.