3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-26329
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2024 1 PoC

Chilkat before v9.5.0.98, allows attackers to obtain sensitive information via predictable PRNG in ChilkatRand::randomBytes function.

CVE-2024-34606
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

CVE-2024-1014
E-DDC3.3 General
6.2
MEDIUM
EPSS
0.1%
2024 CWE-400 1 PoC

Uncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could interrupt the availability of the administration panel by sending multiple ICMP packets.

CVE-2024-45184
Software Genérico General
6.2
MEDIUM
EPSS
0.1%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with chipset Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, and Modem 5300. A USAT out-of-bounds write due to a heap buffer overflow can lead to a Denial of Service.

CVE-2024-27154
Toshiba Tec e-Studio multi-function peripheral (MFP) General
6.2
MEDIUM
EPSS
0.1%
2024 CWE-532 1 PoC

Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/versions, see the reference URL.

CVE-2024-20887
GalaxyBudsManager PC General
6.2
MEDIUM
EPSS
0.6%
2024 1 PoC

Arbitrary directory creation in GalaxyBudsManager PC prior to version 2.1.240315.51 allows attacker to create arbitrary directory.

CVE-2024-34609
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

CVE-2024-20048
MT2713, MT6781, MT6789, MT6835, MT6855, MT6879, MT6886, MT6895, MT6983, MT6985, MT6989, MT8167, MT8168, MT8173, MT8175, MT8188, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8390, MT8395, MT8666, MT8667, MT8673, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8796, MT8797, MT8798 General
6.2
MEDIUM
EPSS
0.0%
2024 1 PoC

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541769; Issue ID: ALPS08541769.

CVE-2024-0406
Software Genérico General
6.1
MEDIUM
EPSS
21.5%
2024 CWE-22 1 PoC

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

CVE-2024-42341
QueueMetrics General
6.1
MEDIUM
EPSS
0.1%
2024 CWE-601 1 PoC

Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CVE-2024-26317
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

In illumos illumos-gate 2024-02-15, an error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates, causing the algorithm to yield a result of POINT_AT_INFINITY when it should not. A man-in-the-middle attacker could use this to interfere with a connection, resulting in an attacked party computing an incorrect shared secret.

CVE-2024-10908
lm-sys/fastchat General ⚡ nuclei
6.1
MEDIUM
EPSS
1.0%
2024 CWE-601 0 PoCs

An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.

CVE-2024-57601
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter.

CVE-2024-46326
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function.

CVE-2024-24512
Software Genérico General
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component.

CVE-2024-48448
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into the tracker comments page.

CVE-2024-57529
Software Genérico General
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Cross Site Scripting vulnerability in Jeppesen JetPlanner Pro v.1.6.2.20 allows a remote attacker to execute arbitrary code.

CVE-2024-24034
Software Genérico General
6.1
MEDIUM
EPSS
0.3%
2024 3 PoCs

Setor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers to execute arbitrary code.

CVE-2024-40785
Safari General
6.1
MEDIUM
EPSS
0.6%
2024 4 PoCs

This issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to a cross site scripting attack.

CVE-2024-9397
Firefox General
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.