3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-48987
Software Genérico General
6.6
MEDIUM
EPSS
2.7%
2024 1 PoC

Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values.

CVE-2024-34646
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.

CVE-2024-27282
Software Genérico General
6.6
MEDIUM
EPSS
0.6%
2024 1 PoC

An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.

CVE-2024-47893
Graphics DDK General
6.5
MEDIUM
EPSS
0.3%
2024 CWE-823 1 PoC

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or write data outside the Guest's virtualised GPU memory.

CVE-2024-33849
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.

CVE-2024-57679
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.

CVE-2024-45877
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User Management function in /Apps/TOPqw/BenutzerManagement.aspx. This allows a low privileged user to access all modules in the web portal, view and manipulate information and permissions of other users, lock other user or unlock the own account, change the password of other users, create new users or delete existing users and view, manipulate and delete reference data.

CVE-2024-40395
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.

CVE-2024-55471
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to access sensitive information of other users by manipulating the id parameter.

CVE-2024-7139
RS9116 Bluetooth SDK General
6.5
MEDIUM
EPSS
0.2%
2024 CWE-787 1 PoC

Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow triggers an assert, which results in a temporary denial of service.  If a watchdog timer is not enabled, a hard reset is required to recover the device.

CVE-2024-24443
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

An uninitialized pointer dereference in the ngap_handle_pdu_session_resource_setup_response routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDU Session Resource Setup Response.

CVE-2024-38435
Vision PLC General
6.5
MEDIUM
EPSS
0.1%
2024 CWE-703 1 PoC

Unitronics Vision PLC – CWE-703: Improper Check or Handling of Exceptional Conditions may allow denial of service

CVE-2024-6512
Devolutions Server General
6.5
MEDIUM
EPSS
0.1%
2024 CWE-863 1 PoC

Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism.

CVE-2024-24449
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialUEMessage message sent to the AMF.

CVE-2024-0879
vector-admin General
6.5
MEDIUM
EPSS
0.0%
2024 CWE-287 1 PoC

Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email address.

CVE-2024-40617
FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS) General
6.5
MEDIUM
EPSS
17.0%
2024 1 PoC

Path traversal vulnerability exists in FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS). If a remote authenticated attacker with User Class privilege sends a specially crafted request to the affected product, access restricted files containing sensitive information may be accessed. As a result, Administrator Class privileges of the product may be hijacked.

CVE-2024-38359
lnd General
6.5
MEDIUM
EPSS
0.2%
2024 CWE-20 1 PoC

The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability in lnd's onion processing logic and lead to a DoS vector due to excessive memory allocation. The issue was patched in lnd v0.17.0. Users should update to a version > v0.17.0 to be protected. Users unable to upgrade may set the `--rejecthtlc` CLI flag and also disable forwarding on channels via the `UpdateChanPolicyCommand`, or disable listening on a public network interface via the `--nolisten` flag as a mitigation.

CVE-2024-27660
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_41C488(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2024-42903
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.

CVE-2024-20892
Samsung Mobile Devices General
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for triggering this vulnerability.