6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-28287
Software Genérico General
7.3
HIGH
EPSS
0.1%
2024 1 PoC

A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted URL.

CVE-2024-30983
Software Genérico Web Database
7.3
HIGH
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the compname parameter in /edit-computer-detail.php file.

CVE-2024-2577
Employee Task Management System Web
7.3
HIGH
EPSS
0.0%
2024 CWE-639 1 PoC

A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /update-employee.php. The manipulation of the argument admin_id leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257080.

CVE-2024-20878
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.2%
2024 1 PoC

Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows local attackers to execute arbitrary code.

CVE-2024-40560
Software Genérico Database
7.3
HIGH
EPSS
0.1%
2024 1 PoC

Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.

CVE-2024-34656
Samsung Notes General
7.3
HIGH
EPSS
0.1%
2024 1 PoC

Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

CVE-2024-38355
socket.io General
7.3
HIGH
EPSS
0.1%
2024 CWE-20 1 PoC

Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process. This issue is fixed by commit `15af22fc22` which has been included in `socket.io@4.6.2` (released in May 2023). The fix was backported in the 2.x branch as well with commit `d30630ba10`. Users are advised to upgrade. Users unable to upgrade may attach a listener for the "error" event to catch these errors.

CVE-2024-43688
Software Genérico General
7.3
HIGH
EPSS
0.1%
2024 2 PoCs

cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was introduced during a May 2023 refactoring.

CVE-2024-34612
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.2%
2024 1 PoC

Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

CVE-2024-9772
Uix Shortcodes Web Windows ⚡ nuclei
7.3
HIGH
EPSS
9.0%
2024 CWE-94 0 PoCs

The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.9. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.

CVE-2024-3204
c-blosc2 General
7.3
HIGH
EPSS
0.6%
2024 CWE-122 2 PoCs

A vulnerability has been found in c-blosc2 up to 2.13.2 and classified as critical. Affected by this vulnerability is the function ndlz4_decompress of the file /src/c-blosc2/plugins/codecs/ndlz/ndlz4x4.c. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.14.3 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-259051.

CVE-2024-45492
Software Genérico General
7.3
HIGH
EPSS
2.3%
2024 2 PoCs

An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_groupSize on 32-bit platforms (where UINT_MAX equals SIZE_MAX).

CVE-2024-4582
GM8181 General
7.3
HIGH
EPSS
0.7%
2024 CWE-78 1 PoC

A vulnerability classified as critical has been found in Faraday GM8181 and GM828x up to 20240429. Affected is an unknown function of the component NTP Service. The manipulation of the argument ntp_srv leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-263304.

CVE-2024-40507
Software Genérico General
7.3
HIGH
EPSS
7.8%
2024 1 PoC

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMPersonnel.asmx function.

CVE-2024-0294
LR1200GB General
7.3
HIGH
EPSS
2.1%
2024 CWE-78 1 PoC

A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected by this issue is the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249860. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-1302
Monitool General
7.3
HIGH
EPSS
0.3%
2024 CWE-200 1 PoC

Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a log file obtaining all sensitive information such as database credentials.

CVE-2024-1832
Complete File Management System Database
7.3
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability has been found in SourceCodester Complete File Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/ of the component Admin Login Form. The manipulation of the argument username with the input torada%27+or+%271%27+%3D+%271%27+--+- leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254623.

CVE-2024-35061
Software Genérico Windows
7.3
HIGH
EPSS
1.4%
2024 1 PoC

NASA AIT-Core v2.5.2 was discovered to use unencrypted channels to exchange data over the network, allowing attackers to execute a man-in-the-middle attack. When chained with CVE-2024-35059, the CVE in subject leads to an unauthenticated, fully remote code execution.

CVE-2024-21541
dom-iterator General
7.3
HIGH
EPSS
0.3%
2024 CWE-94 2 PoCs

Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function generates a new function body and thus care must be given to ensure that the inputs to Function are not attacker-controlled. The risks involved are similar to that of allowing attacker-controlled input to reach eval.

CVE-2024-38499
CA Client Automation (ITCM) General
7.3
HIGH
EPSS
0.1%
2024 CWE-269 1 PoC

CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a non-admin/non-root user to execute "caf encrypt"/"sd_acmd encrypt" commands.