3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-57679
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

An access control issue in the component form2RepeaterSetup.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G repeater service of the device via a crafted POST request.

CVE-2024-57678
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

An access control issue in the component form2WlAc.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the 2.4G and 5G mac access control list of the device via a crafted POST request.

CVE-2024-54764
Software Genérico General ⚡ nuclei
6.5
MEDIUM
EPSS
9.0%
2024 0 PoCs

An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.

CVE-2024-24449
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialUEMessage message sent to the AMF.

CVE-2024-1671
Chrome General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-41972
CC100 0751-9x01 General
6.5
MEDIUM
EPSS
0.3%
2024 CWE-35 1 PoC

A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file read with root privileges.

CVE-2024-34020
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

A stack-based buffer overflow was found in the putSDN() function of mail.c in hcode through 2.1.

CVE-2024-45188
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 CWE-22 1 PoC

Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "File Content" request

CVE-2024-51317
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function

CVE-2024-3044
LibreOffice General
6.5
MEDIUM
EPSS
2.4%
2024 CWE-356 1 PoC

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.

CVE-2024-54682
Mattermost General
6.5
MEDIUM
EPSS
0.2%
2024 CWE-409 1 PoC

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size for slack import file uploads which allows a user to cause a DoS via zip bomb by importing data in a team they are a team admin.

CVE-2024-56427
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds access via malformed RRC packets to the target.

CVE-2024-39925
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated when a member departs. Consequently, the departing member, whose access should be revoked, retains a copy of the organization key. Additionally, the application fails to adequately protect some encrypted data stored on the server. Consequently, an authenticated user could gain unauthorized access to encrypted data of any organization, even if the user is not a member of the targeted organization. Ho

CVE-2024-48121
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. This allows attackers to possibly gain access to sensitive information via a man-in-the-middle attack.

CVE-2024-50848
Software Genérico General
6.5
MEDIUM
EPSS
7.9%
2024 2 PoCs

An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.

CVE-2024-55471
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This allows unauthorized users to access sensitive information of other users by manipulating the id parameter.

CVE-2024-35539
Software Genérico General
6.5
MEDIUM
EPSS
3.0%
2024 1 PoC

Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks if the comments are posted too frequently.

CVE-2024-29197
pimcore General
6.5
MEDIUM
EPSS
0.0%
2024 CWE-200 1 PoC

Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true` allows to view unpublished sites. In previous versions of Pimcore, session information would propagate to previews, so only a logged in user could open a preview. This no longer applies. Previews are broad open to any user and with just the hint of a restricted link one could gain access to possible confident / unreleased information. This vulnerability is fixed in 11.2.2 and 11.1.6.1.

CVE-2024-45190
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 CWE-35 1 PoC

Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "Pipeline Interaction" request

CVE-2024-54083
Mattermost General
6.5
MEDIUM
EPSS
0.5%
2024 CWE-1287 1 PoC

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a specially crafted post.