6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-38888
Software Genérico General
6.8
MEDIUM
EPSS
0.0%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform a Password Brute Forcing attack due to improper restriction of excessive authentication attempts.

CVE-2024-39832
Mattermost General
6.8
MEDIUM
EPSS
0.3%
2024 CWE-754 1 PoC

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error handling which allows a malicious remote to permanently delete local data by abusing dangerous error handling, when share channels were enabled.

CVE-2024-50657
Software Genérico Cloud
6.8
MEDIUM
EPSS
3.2%
2024 1 PoC

An issue in Owncloud android apk v.4.3.1 allows a physically proximate attacker to escalate privileges via the PassCodeViewModel class, specifically in the checkPassCodeIsValid method

CVE-2024-3901
Genesis Blocks Web Windows
6.8
MEDIUM
EPSS
0.3%
2024 1 PoC

The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks.

CVE-2024-13347
Essential WP Real Estate Web Windows
6.8
MEDIUM
EPSS
0.1%
2024 1 PoC

The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

CVE-2024-29090
AI Engine: ChatGPT Chatbot General
6.8
MEDIUM
EPSS
0.8%
2024 CWE-918 2 PoCs

Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.

CVE-2024-37600
Software Genérico Web
6.8
MEDIUM
EPSS
0.3%
2024 1 PoC

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible stack buffer overflow in the Service Broker service affects NTG 6 head units. To perform this attack, physical access to Ethernet pins of the head unit base board is needed. With a static IP address, an attacker can connect via the internal network to the Service Broker service. With prepared HTTP requests, an attacker can cause the Service-Broker service to fail.

CVE-2024-52794
discourse General
6.8
MEDIUM
EPSS
0.5%
2024 CWE-79 1 PoC

Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched in the latest version of Discourse. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-4305
Post Grid Gutenberg Blocks and WordPress Blog Plugin Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-5744
wp-eMember Web Windows
6.8
MEDIUM
EPSS
0.5%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

CVE-2024-3121
parisneo/lollms General
6.8
MEDIUM
EPSS
0.1%
2024 CWE-94 1 PoC

A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version 5.9.0. The vulnerability arises from the use of shell=True in the subprocess.Popen function, which allows an attacker to inject arbitrary commands by manipulating the env_name and python_version parameters. This issue could lead to a serious security breach as demonstrated by the ability to execute the 'whoami' command among potentially other harmful commands.

CVE-2024-7404
GitLab DevOps Web
6.8
MEDIUM
EPSS
0.4%
2024 CWE-1021 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.

CVE-2024-36440
Software Genérico General
6.8
MEDIUM
EPSS
0.0%
2024 2 PoCs

An issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may recover the administrative device password via password-cracking methods, because unsalted MD5 is used.

CVE-2024-34693
Apache Superset Web Database
6.8
MEDIUM
EPSS
12.6%
2024 CWE-20 3 PoCs

Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are set to allow for local infile, it's possible for the attacker to execute a specific MySQL/MariaDB SQL command that is able to read files from the server and insert their content on a MariaDB database table.This issue affects Apache Superset: before 3.1.3 and version 4.0.0 Users are recommended to upgrade to version 4.0.1 or 3.1.3, which fixes the is

CVE-2024-2322
WooCommerce Cart Abandonment Recovery Web Windows
6.8
MEDIUM
EPSS
0.2%
2024 1 PoC

The WooCommerce Cart Abandonment Recovery WordPress plugin before 1.2.27 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admins delete arbitrary email templates as well as delete and unsubscribe users from abandoned orders via CSRF attacks.

CVE-2024-30987
Software Genérico Web Database
6.8
MEDIUM
EPSS
0.2%
2024 2 PoCs

Cross Site Scripting vulnerability in /bwdates-reports-ds.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the fromdate and todate parameters.

CVE-2024-2640
Watu Quiz Web Windows
6.8
MEDIUM
EPSS
0.4%
2024 1 PoC

The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users such as authors (if they've been authorized by admins) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2024-1346
LaborOfficeFree Database
6.8
MEDIUM
EPSS
0.3%
2024 CWE-521 1 PoC

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of the MySQL database used by LaborOfficeFree using two constants.

CVE-2024-0671
Midgard GPU Kernel Driver General
6.8
MEDIUM
EPSS
0.1%
2024 CWE-416 1 PoC

Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Midgard GPU Kernel Driver: from r19p0 through r32p0; Bifrost GPU Kernel Driver: from r7p0 through r48p0; Valhall GPU Kernel Driver: from r19p0 through r48p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r48p0.

CVE-2024-56331
uptime-kuma General
6.8
MEDIUM
EPSS
53.2%
2024 CWE-22 1 PoC

Uptime Kuma is an open source, self-hosted monitoring tool. An **Improper URL Handling Vulnerability** allows an attacker to access sensitive local files on the server by exploiting the `file:///` protocol. This vulnerability is triggered via the **"real-browser"** request type, which takes a screenshot of the URL provided by the attacker. By supplying local file paths, such as `file:///etc/passwd`, an attacker can read sensitive data from the server. This vulnerability arises because the system does not properly validate or sanitize the user input for the URL field. Specifically: 1. The URL i