6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-29198
geoserver General ⚡ nuclei
7.5
HIGH
EPSS
10.1%
2024 CWE-918 0 PoCs

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. It possible to achieve Service Side Request Forgery (SSRF) via the Demo request endpoint if Proxy Base URL has not been set. Upgrading to GeoServer 2.24.4, or 2.25.2, removes the TestWfsPost servlet resolving this issue.

CVE-2024-8194
Chrome General
7.5
HIGH
EPSS
0.1%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-7409
Software Genérico General
7.5
HIGH
EPSS
1.7%
2024 CWE-662 1 PoC

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.

CVE-2024-36052
Software Genérico Windows
7.5
HIGH
EPSS
0.1%
2024 1 PoC

RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899.

CVE-2024-50600
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, W920, W930, and W1000. Lack of a boundary check in STOP_KEEP_ALIVE_OFFLOAD leads to out-of-bounds access. An attacker can send a malformed message to the target through the Wi-Fi driver.

CVE-2024-21272
MySQL Connectors Database
7.5
HIGH
EPSS
0.9%
2024 1 PoC

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVE-2024-24926
Brooklyn | Creative Multi-Purpose Responsive WordPress Theme Web Windows
7.5
HIGH
EPSS
42.1%
2024 CWE-502 1 PoC

Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme: from n/a through 4.9.7.6.

CVE-2024-26331
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
67.9%
2024 0 PoCs

ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to a session ID. Attackers can easily modify the cookie value, within a browser or by implementing client-side code outside of a browser. Attackers can bypass the authentication mechanism by modifying the cookie to contain an expected value.

CVE-2024-21907
Software Genérico General
7.5
HIGH
EPSS
2.9%
2024 CWE-755 2 PoCs

Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote attacker may be able to cause the denial of service condition.

CVE-2024-23302
Software Genérico General
7.5
HIGH
EPSS
0.6%
2024 2 PoCs

Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.

CVE-2024-24419
Software Genérico Networking
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_traffic_flow_template_packet_filter function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

CVE-2024-7985
FileOrganizer – WordPress File Manager Web Windows
7.5
HIGH
EPSS
50.5%
2024 CWE-434 1 PoC

The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the "fileorganizer_ajax_handler" function in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions granted by an administrator, to upload arbitrary files on the affected site's server which may make remote code execution possible. NOTE: The FileOrganizer Pro plugin must be installed and active to allow Subscriber+ users to upload files.

CVE-2024-30571
Software Genérico General
7.5
HIGH
EPSS
22.0%
2024 1 PoC

An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.

CVE-2024-2782
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Web Windows ⚡ nuclei
7.5
HIGH
EPSS
7.2%
2024 CWE-862 1 PoC

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wp-json/fluentform/v1/global-settings REST API endpoint in all versions up to, and including, 5.1.16. This makes it possible for unauthenticated attackers to modify all of the plugin's settings.

CVE-2024-29059
🔥 KEV Microsoft .NET Framework 4.8 General ⚡ nuclei
7.5
HIGH
EPSS
93.7%
2024 CWE-209 0 PoCs

.NET Framework Information Disclosure Vulnerability

CVE-2024-48645
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

In Minecraft mod "Command Block IDE" up to and including version 0.4.9, a missing authorization (CWE-862) allows any user to modify "function" files used by the game when installed on a dedicated server.

CVE-2024-53621
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

A buffer overflow in the formSetCfm() function of Tenda AC1206 1200M 11ac US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-46923
Software Genérico General
7.5
HIGH
EPSS
0.5%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. The absence of a null check leads to a Denial of Service at amdgpu_cs_ib_fill in the Xclipse Driver.

CVE-2024-20931
WebLogic Server Database
7.5
HIGH
EPSS
89.1%
2024 5 PoCs

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2024-53522
Software Genérico General
7.5
HIGH
EPSS
1.0%
2024 2 PoCs

Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to access sensitive information.