3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-35429
Software Genérico General
6.5
MEDIUM
EPSS
0.5%
2024 1 PoC

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.

CVE-2024-33901
Software Genérico General
6.5
MEDIUM
EPSS
19.5%
2024 1 PoC

Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disputes this because memory-management constraints make this unavoidable in the current design and other realistic designs.

CVE-2024-0879
vector-admin General
6.5
MEDIUM
EPSS
0.0%
2024 CWE-287 1 PoC

Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email address.

CVE-2024-38435
Vision PLC General
6.5
MEDIUM
EPSS
0.1%
2024 CWE-703 1 PoC

Unitronics Vision PLC – CWE-703: Improper Check or Handling of Exceptional Conditions may allow denial of service

CVE-2024-2447
Mattermost General
6.5
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing an authenticated attacker to create posts as other users via a crafted post action.

CVE-2024-0507
Enterprise Server General
6.5
MEDIUM
EPSS
72.9%
2024 CWE-20 1 PoC

An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.11.3, 3.10.5, 3.9.8, and 3.8.13 This vulnerability was reported via the GitHub Bug Bounty program.

CVE-2024-9391
Firefox General
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.

CVE-2024-24787
cmd/go General
6.4
MEDIUM
EPSS
2.7%
2024 2 PoCs

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.

CVE-2024-20880
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.3%
2024 1 PoC

Stack-based buffer overflow vulnerability in bootloader prior to SMR Jun-2024 Release 1 allows physical attackers to overwrite memory.

CVE-2024-49409
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.

CVE-2024-49408
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.

CVE-2024-48954
Software Genérico General
6.4
MEDIUM
EPSS
2.5%
2024 2 PoCs

An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.

CVE-2024-8105
vz2694g General
6.4
MEDIUM
EPSS
0.0%
2024 1 PoC

A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.

CVE-2024-31063
Software Genérico General
6.4
MEDIUM
EPSS
0.7%
2024 2 PoCs

Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute arbitrary code via the Email input field.

CVE-2024-20832
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

CVE-2024-31798
Software Genérico General
6.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrieve the root password for all similar devices

CVE-2024-45062
ippusbxd General
6.4
MEDIUM
EPSS
0.0%
2024 CWE-121 2 PoCs

A stack based buffer overflow vulnerability is present in OpenPrinting ippusbxd 1.34. A specially configured printer that supports IPP-over-USB can cause a buffer overflow which can lead to a arbitrary code execution in a privileged service. To trigger the vulnerability, a malicious device would need to be connected to the vulnerable system over USB.

CVE-2024-2248
Artifactory General
6.4
MEDIUM
EPSS
0.7%
2024 CWE-20 1 PoC

A Header Injection vulnerability in the JFrog platform in versions below 7.85.0 (SaaS) and 7.84.7 (Self-Hosted) may allow threat actors to take over the end user's account when clicking on a specially crafted URL sent to the victim’s user email.

CVE-2024-26875
Linux General
6.4
MEDIUM
EPSS
0.0%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: media: pvrusb2: fix uaf in pvr2_context_set_notify [Syzbot reported] BUG: KASAN: slab-use-after-free in pvr2_context_set_notify+0x2c4/0x310 drivers/media/usb/pvrusb2/pvrusb2-context.c:35 Read of size 4 at addr ffff888113aeb0d8 by task kworker/1:1/26 CPU: 1 PID: 26 Comm: kworker/1:1 Not tainted 6.8.0-rc1-syzkaller-00046-gf1a27f081c1f #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/25/2024 Workqueue: usb_hub_wq hub_event Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_

CVE-2024-8159
DeepFreeze General
6.4
MEDIUM
EPSS
0.1%
2024 CWE-125 1 PoC

Deep Freeze 9.00.020.5760 is vulnerable to an out-of-bounds read vulnerability by triggering the 0x70014 IOCTL code of the FarDisk.sys driver.