6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-56426
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000. The lack of a length check leads to out-of-bounds writes via malformed USB packets to the target.

CVE-2024-24418
Software Genérico Networking
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_pdn_address function at /nas/ies/PdnAddress.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

CVE-2024-25458
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

An issue in CYCZCAM, SHIX ZHAO, SHIXCAM A9 Camera (circuit board identifier A9-48B-V1.0) firmware v.CYCAM_48B_BC01_v87_0903 allows a remote attacker to obtain sensitive information via a crafted request to a UDP port.

CVE-2024-21484
jsrsasign General
7.5
HIGH
EPSS
0.2%
2024 CWE-203 4 PoCs

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts by exploiting the Marvin security flaw. Exploiting this vulnerability requires the attacker to have access to a large number of ciphertexts encrypted with the same key. Workaround The vulnerability can be mitigated by finding and replacing RSA and RSAOAEP decryption with another crypto library.

CVE-2024-40582
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.

CVE-2024-29190
Mobile-Security-Framework-MobSF Networking
7.5
HIGH
EPSS
0.4%
2024 CWE-918 1 PoC

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In version 3.9.5 Beta and prior, MobSF does not perform any input validation when extracting the hostnames in `android:host`, so requests can also be sent to local hostnames. This can lead to server-side request forgery. An attacker can cause the server to make a connection to internal-only services within the organization's infrastructure. Commit 5a8eeee73c5f504a6c3abdf2a139a13804efdb77 has a hotfix for this issue.

CVE-2024-25728
Software Genérico Networking Windows
7.5
HIGH
EPSS
0.3%
2024 1 PoC

ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configuration (e.g., sends them to DNS servers operated by the user's ISP instead of to the ExpressVPN DNS servers), which may allow remote attackers to obtain sensitive information about websites visited by VPN users.

CVE-2024-6587
berriai/litellm Web ⚡ nuclei
7.5
HIGH
EPSS
88.4%
2024 CWE-918 0 PoCs

A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the `api_base` parameter when making requests to `POST /chat/completions`, causing the application to send the request to the domain specified by `api_base`. This request includes the OpenAI API key. A malicious user can set the `api_base` to their own domain and intercept the OpenAI API key, leading to unauthorized access and potential misuse of the API key.

CVE-2024-6893
Journyx (jtime) DevOps Web ⚡ nuclei
7.5
HIGH
EPSS
91.4%
2024 CWE-611 3 PoCs

The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.

CVE-2024-33383
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request using the filePath parameter.

CVE-2024-50609
Software Genérico General
7.5
HIGH
EPSS
0.7%
2024 1 PoC

An issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP address and port, one can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpoint) to perform a remote Denial of service attack. The crash happens because of a NULL pointer dereference when 0 (from the Content-Length) is passed to the function cfl_sds_len, which in turn tries to

CVE-2024-27686
Software Genérico Networking Windows
7.5
HIGH
EPSS
0.3%
2024 1 PoC

Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.

CVE-2024-6119
OpenSSL General
7.5
HIGH
EPSS
14.3%
2024 CWE-843 1 PoC

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that termina

CVE-2024-26477
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2024 1 PoC

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the api parameter of the oauth, amazon_sns, export endpoints.

CVE-2024-46508
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).

CVE-2024-57757
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava.

CVE-2024-26480
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the admin parameter.

CVE-2024-27158
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.0%
2024 CWE-1392 1 PoC

All the Toshiba printers share the same hardcoded root password. As for the affected products/models/versions, see the reference URL.

CVE-2024-25642
SAP Cloud Connector Cloud
7.4
HIGH
EPSS
0.4%
2024 CWE-295 1 PoC

Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC breaking the mutual authentication. Hence, the attacker can intercept the request to view/modify sensitive information. There is no impact on the availability of the system.

CVE-2024-0023
Android General
7.4
HIGH
EPSS
3.7%
2024 3 PoCs

In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.