6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-46922
Software Genérico General
7.5
HIGH
EPSS
0.8%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The absence of a null check leads to a Denial of Service at amdgpu_cs_parser_bos in the Xclipse Driver.

CVE-2024-8198
Chrome General
7.5
HIGH
EPSS
0.3%
2024 CWE-122 2 PoCs

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-8233
GitLab DevOps
7.5
HIGH
EPSS
1.2%
2024 CWE-407 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could cause a denial of service with requests for diff files on a commit or merge request.

CVE-2024-0040
Android General
7.5
HIGH
EPSS
18.4%
2024 2 PoCs

In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-6707
Open WebUI General
7.5
HIGH
EPSS
0.2%
2024 CWE-22 3 PoCs

Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.

CVE-2024-10462
Firefox General
7.5
HIGH
EPSS
0.5%
2024 1 PoC

Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVE-2024-51179
Software Genérico General
7.5
HIGH
EPSS
13.5%
2024 1 PoC

An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as the User Plane Function (UPF) and the Session Management Function (SMF), The Packet Data Unit (PDU) session establishment process.

CVE-2024-6781
Calibre General ⚡ nuclei
7.5
HIGH
EPSS
93.7%
2024 CWE-22 1 PoC

Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.

CVE-2024-12157
Popup – MailChimp, GetResponse and ActiveCampaign Intergrations Web Database Windows
7.5
HIGH
EPSS
10.2%
2024 CWE-89 1 PoC

The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'upc_delete_db_record' AJAX action in all versions up to, and including, 3.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-54374
Sogrid Web
7.5
HIGH
EPSS
20.7%
2024 CWE-22 1 PoC

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sabri Sogrid sogrid allows PHP Local File Inclusion.This issue affects Sogrid: from n/a through <= 1.5.6.

CVE-2024-22851
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 2 PoCs

Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint.

CVE-2024-23722
Software Genérico Web
7.5
HIGH
EPSS
0.9%
2024 3 PoCs

In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.

CVE-2024-21522
audify General
7.5
HIGH
EPSS
0.3%
2024 CWE-129 1 PoC

All versions of the package audify are vulnerable to Improper Validation of Array Index when frameSize is provided to the new OpusDecoder().decode or new OpusDecoder().decodeFloat functions it is not checked for negative values. This can lead to a process crash.

CVE-2024-32736
CyberPower PowerPanel Enterprise Database ⚡ nuclei
7.5
HIGH
EPSS
69.1%
2024 1 PoC

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper.

CVE-2024-34667
Samsung Mobile Devices General
7.5
HIGH
EPSS
5.1%
2024 1 PoC

Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2024-11728
KiviCare – Clinic & Patient Management System (EHR) Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
65.9%
2024 CWE-89 1 PoC

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-21088
Production Scheduling Web Database
7.5
HIGH
EPSS
0.2%
2024 1 PoC

Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Import Utility). Supported versions that are affected are 12.2.4-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVE-2024-28806
Software Genérico General
7.5
HIGH
EPSS
0.5%
2024 1 PoC

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Remote unauthenticated attackers can upload files at an arbitrary path.

CVE-2024-49113
Windows 10 Version 1809 Windows
7.5
HIGH
EPSS
88.9%
2024 CWE-125 3 PoCs

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2024-13471
DesignThemes Core Features Web Windows
7.5
HIGH
EPSS
0.9%
2024 CWE-22 1 PoC

The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dt_process_imported_file function in all versions up to, and including, 4.7. This makes it possible for unauthenticated attackers to read arbitrary files on the underlying operating system.