3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-47217
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated endpoint. It can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.

CVE-2024-7138
RS9116 Bluetooth SDK General
6.5
MEDIUM
EPSS
0.1%
2024 CWE-617 1 PoC

An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed L2CAP packet. If a watchdog timer is not enabled, a hard reset is required to recover the device.

CVE-2024-54994
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature.

CVE-2024-40780
Safari General
6.5
MEDIUM
EPSS
0.1%
2024 4 PoCs

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2024-54764
Software Genérico General ⚡ nuclei
6.5
MEDIUM
EPSS
9.0%
2024 0 PoCs

An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.

CVE-2024-23525
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 2 PoCs

The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.

CVE-2024-46920
Software Genérico General
6.5
MEDIUM
EPSS
0.6%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to a stack out-of-bounds write at loadInputBuffers.

CVE-2024-24446
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

An uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialContextSetupResponse message sent to the AMF.

CVE-2024-50651
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

CVE-2024-27662
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_4110f4(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2024-46921
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, Modem 5123, Modem 5300, Modem 5400. UE does not limit the number of attempts for the RRC Setup procedure in the 5G SA, leading to a denial of service (battery-drain attack).

CVE-2024-42849
Software Genérico General
6.5
MEDIUM
EPSS
11.3%
2024 2 PoCs

An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

CVE-2024-3182
Hawk General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Install-type password disclosure vulnerability in Universal Installer including the Silent Installer in TIBCO Hawk versions 6.2.0, 6.2.1, 6.2.2 and 6.2.3 allows user's Enterprise Message Service (EMS) password to be exposed outside of the hawkagent.cfg and hawkevent.cfg config files.

CVE-2024-40767
Software Genérico General
6.5
MEDIUM
EPSS
0.8%
2024 1 PoC

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.

CVE-2024-38434
Vision PLC General
6.5
MEDIUM
EPSS
0.1%
2024 CWE-676 1 PoC

Unitronics Vision PLC – CWE-676: Use of Potentially Dangerous Function may allow security feature bypass

CVE-2024-48705
Software Genérico General
6.5
MEDIUM
EPSS
11.6%
2024 1 PoC

Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the "set_sys_adm" function of the "adm.cgi" binary, and is due to improper santization of the user provided "newpass" field

CVE-2024-42649
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.

CVE-2024-6697
Pentaho Data Integration & Analytics General
6.5
MEDIUM
EPSS
0.1%
2024 CWE-280 1 PoC

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state. (CWE-280)   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, do not handle invalid and missing permissions correctly, resulting in a denial of service.   An adversary leverages a legitimate capability of an application in such a way as to achieve a negative technical impact.

CVE-2024-35539
Software Genérico General
6.5
MEDIUM
EPSS
3.0%
2024 1 PoC

Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks if the comments are posted too frequently.

CVE-2024-56340
Cognos Analytics General
6.5
MEDIUM
EPSS
12.2%
2024 CWE-23 2 PoCs

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.