3387 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2024-0470
Human Resource Integrated System Web Database
6.3
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been classified as critical. This affects an unknown part of the file /admin_route/inc_service_credits.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250575.

CVE-2024-34655
Samsung Mobile Devices Web
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.

CVE-2024-20884
Samsung Mobile Devices Web
6.2
MEDIUM
EPSS
0.2%
2024 1 PoC

Incorrect use of privileged API vulnerability in getSemBatteryUsageStats in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.

CVE-2024-27161
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
6.2
MEDIUM
EPSS
0.1%
2024 CWE-798 2 PoCs

all the Toshiba printers have programs containing a hardcoded key used to encrypt files. An attacker can decrypt the encrypted files using the hardcoded key. Insecure algorithm is used for the encryption. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/mo

CVE-2024-40540
Software Genérico Web Database
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/dept.

CVE-2024-40541
Software Genérico Web Database
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/dept/build.

CVE-2024-27160
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
6.2
MEDIUM
EPSS
0.1%
2024 CWE-798 2 PoCs

All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the hardcoded key. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.

CVE-2024-40539
Software Genérico Web Database
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/user.

CVE-2024-20883
Samsung Mobile Devices Web
6.2
MEDIUM
EPSS
0.2%
2024 1 PoC

Incorrect use of privileged API vulnerability in registerBatteryStatsCallback in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.

CVE-2024-27159
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
6.2
MEDIUM
EPSS
0.0%
2024 CWE-798 2 PoCs

All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the hardcoded key. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.

CVE-2024-31586
Software Genérico Web
6.1
MEDIUM
EPSS
0.3%
2024 1 PoC

A Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerability allows a remote attacker to execute arbitrary code via the Borrower Name, Department, and Remarks parameters.

CVE-2024-1664
Responsive Gallery Grid Web Windows
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

The Responsive Gallery Grid WordPress plugin before 2.3.11 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-31648
Software Genérico Web
6.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter at /core/new_category2.

CVE-2024-24506
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2024 2 PoCs

Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter in the General Setting function.

CVE-2024-33669
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 2 PoCs

An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user.

CVE-2024-21036
Complex Maintenance, Repair, and Overhaul Web Database
6.1
MEDIUM
EPSS
0.6%
2024 1 PoC

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair, and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of th

CVE-2024-12302
Icegram Engage Web Windows
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks

CVE-2024-48591
Software Genérico Web
6.1
MEDIUM
EPSS
0.4%
2024 1 PoC

Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded that will render and execute JavaScript upon direct viewing.

CVE-2024-48396
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

AIML Chatbot 1.0 (fixed in 2.0) is vulnerable to Cross Site Scripting (XSS). The vulnerability is exploited through the message input field, where attackers can inject malicious HTML or JavaScript code. The chatbot fails to sanitize these inputs, leading to the execution of malicious scripts.

CVE-2024-25712
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2024 1 PoC

http-swagger before 1.2.6 allows XSS via PUT requests, because a file that has been uploaded (via httpSwagger.WrapHandler and *webdav.memFile) can subsequently be accessed via a GET request. NOTE: this is independently fixable with respect to CVE-2022-24863, because (if a solution continued to allow PUT requests) large files could have been blocked without blocking JavaScript, or JavaScript could have been blocked without blocking large files.