6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-6842
mintplex-labs/anything-llm Web ⚡ nuclei
7.5
HIGH
EPSS
70.2%
2024 CWE-306 0 PoCs

In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for search engines, which can be exploited by attackers to steal these keys and cause loss of user assets.

CVE-2024-56902
Software Genérico General
7.5
HIGH
EPSS
26.5%
2024 1 PoC

Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which discloses account information, including cleartext password.

CVE-2024-44083
Software Genérico General
7.5
HIGH
EPSS
11.7%
2024 2 PoCs

ida64.dll in Hex-Rays IDA Pro through 8.4 crashes when there is a section that has many jumps linked, and the final jump corresponds to the payload from where the actual entry point will be invoked. NOTE: in many use cases, this is an inconvenience but not a security issue.

CVE-2024-11322
PowerPanel Business General
7.5
HIGH
EPSS
0.8%
2024 CWE-287 1 PoC

A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote attacker can restart the ppbd.exe process via the PowerPanel Business Service Watchdog service listening on TCP port 2003. The attacker can repeatedly restart ppbd.exe to render it unavailable.

CVE-2024-21215
Oracle WebLogic Server Web Database
7.5
HIGH
EPSS
0.2%
2024 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2024-22641
Software Genérico General
7.5
HIGH
EPSS
9.0%
2024 1 PoC

TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.

CVE-2024-44903
IPAC20 Database
7.5
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable.

CVE-2024-32825
Simply Static General ⚡ nuclei
7.5
HIGH
EPSS
25.8%
2024 CWE-201 0 PoCs

Insertion of Sensitive Information Into Sent Data vulnerability in Simply Static Simply Static simply-static.This issue affects Simply Static: from n/a through <= 3.1.3.

CVE-2024-23837
libhtp Web
7.5
HIGH
EPSS
0.3%
2024 CWE-770 1 PoC

LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed in 0.5.46.

CVE-2024-12085
Software Genérico General
7.5
HIGH
EPSS
19.1%
2024 CWE-908 1 PoC

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVE-2024-21073
Trade Management Web Database
7.5
HIGH
EPSS
0.5%
2024 1 PoC

Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trade Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2024-55568
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The absence of a NULL check leads to a Denial of Service when an attacker sends malformed MM packets to the target.

CVE-2024-55196
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.

CVE-2024-49193
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to grant additional authorization for ticket viewing, the mechanism for detecting spoofed e-mail messages is insufficient, and the support e-mail addresses associated with individual tickets are predictable.

CVE-2024-28716
Software Genérico General
7.5
HIGH
EPSS
2.2%
2024 2 PoCs

An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.

CVE-2024-33605
Multiple MFPs (multifunction printers) General ⚡ nuclei
7.5
HIGH
EPSS
60.2%
2024 CWE-22 3 PoCs

Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-1483
mlflow/mlflow Web ⚡ nuclei
7.5
HIGH
EPSS
75.0%
2024 CWE-22 0 PoCs

A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on the server. By crafting a series of HTTP POST requests with specially crafted 'artifact_location' and 'source' parameters, using a local URI with '#' instead of '?', an attacker can traverse the server's directory structure. The issue occurs due to insufficient validation of user-supplied input in the server's handlers.

CVE-2024-41594
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2024 1 PoC

An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL.

CVE-2024-24424
Software Genérico Networking
7.5
HIGH
EPSS
0.2%
2024 1 PoC

A reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

CVE-2024-7389
Forminator Forms – Contact Form, Payment Form & Custom Form Builder Web Windows
7.5
HIGH
EPSS
2.8%
2024 CWE-522 3 PoCs

The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.29.1 via class-forminator-addon-hubspot-wp-api.php. This makes it possible for unauthenticated attackers to extract the HubSpot integration developer API key and make unauthorized changes to the plugin's HubSpot integration or expose personally identifiable information from plugin users using the HubSpot integration.