3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-36079
Software Genérico General
6.5
MEDIUM
EPSS
0.5%
2024 1 PoC

An issue was discovered in Vaultize 21.07.27. When uploading files, there is no check that the filename parameter is correct. As a result, a temporary file will be created outside the specified directory when the file is downloaded. To exploit this, an authenticated user would upload a file with an incorrect file name, and then download it.

CVE-2024-55457
Software Genérico General ⚡ nuclei
6.5
MEDIUM
EPSS
80.4%
2024 1 PoC

MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by manipulating the file parameter to access arbitrary files on the server, potentially exposing sensitive information.

CVE-2024-40432
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IOCTL_SFFDISK_DEVICE_COMMAND control of the SD card reader driver allows a privileged attacker to crash the OS.

CVE-2024-25742
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and can trigger its handler. This affects AMD SEV-SNP and AMD SEV-ES.

CVE-2024-25506
Software Genérico General
6.5
MEDIUM
EPSS
0.6%
2024 1 PoC

Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control of the pm_sys_sys cookie.

CVE-2024-48293
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily modify antivirus settings.

CVE-2024-42648
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.

CVE-2024-54763
Software Genérico General ⚡ nuclei
6.5
MEDIUM
EPSS
5.5%
2024 0 PoCs

An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.

CVE-2024-0741
Firefox General
6.5
MEDIUM
EPSS
47.3%
2024 2 PoCs

An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

CVE-2024-1669
Chrome General
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2024-45188
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 CWE-22 1 PoC

Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "File Content" request

CVE-2024-45433
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of proper return control flow after detecting an unusual condition. An attacker can leverage this to bypass a security validation and make the incoming data be processed.

CVE-2024-48450
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into chat group.

CVE-2024-27659
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_42AF30(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2024-54999
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module.

CVE-2024-37363
Pentaho Data Integration & Analytics General
6.5
MEDIUM
EPSS
0.2%
2024 CWE-862 1 PoC

The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (CWE-862)  Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, do not correctly perform an authorization check in the data source management service. When access control checks are incorrectly applied, users can access data or perform actions that they should not be allowed to perform. This can lead to a wide range of problems, including information exposures and denial of service.

CVE-2024-57678
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G mac access control list of the device via a crafted POST request.

CVE-2024-33860
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is used within the File System Collector. The content of the file specified can be viewed in the incoming logs.

CVE-2024-27658
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2024-1671
Chrome General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)