6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-49592
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

Trial installer for McAfee Total Protection (legacy trial installer software) 16.0.53 allows local privilege escalation because of an Uncontrolled Search Path Element. The attacker could be "an adversary or knowledgeable user" and the type of attack could be called "DLL-squatting." The issue only affects execution of this installer, and does not leave McAfee Total Protection in a vulnerable state after installation is completed. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2024-27372
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->infrastructure_ssid_len coming from userspace, which can lead to a heap overwrite.

CVE-2024-27387
Software Genérico General
6.7
MEDIUM
EPSS
0.0%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_rx_range_done_ind(), there is no input validation check on rtt_id coming from userspace, which can lead to a heap overwrite.

CVE-2024-21302
Windows 10 Version 1809 Cloud Windows
6.7
MEDIUM
EPSS
1.1%
2024 CWE-284 1 PoC

Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to protect your systems from this vulnerability. An elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machine SKUS. This vulnerability enables an attacker with administrator privileges to replace current versions of Windows system files wi

CVE-2024-27379
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->num_intf_addr_present coming from userspace, which can lead to a heap overwrite.

CVE-2024-12753
PDF Reader General
6.7
MEDIUM
EPSS
0.1%
2024 CWE-59 1 PoC

Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the product installer. By creating a junction, an attacker can abuse the installer process to create an arbitrary file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI

CVE-2024-27377
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_get_security_info_nl(), there is no input validation check on sec_info->key_info.body.pmk_info.pmk_len coming from userspace, which can lead to a heap overwrite.

CVE-2024-27383
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_get_scan_extra_ies(), there is no input validation check on default_ies coming from userspace, which can lead to a heap overwrite.

CVE-2024-27180
Toshiba Tec e-Studio multi-function peripheral (MFP) General
6.7
MEDIUM
EPSS
0.0%
2024 CWE-276 1 PoC

An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the reference URL.

CVE-2024-42642
Software Genérico General
6.7
MEDIUM
EPSS
1.5%
2024 1 PoC

Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states that this vulnerability was fully remediated in December 2024 and that updated firmware is available through Crucial’s official support page.

CVE-2024-27376
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->rx_match_filter_len coming from userspace, which can lead to a heap overwrite.

CVE-2024-52937
Graphics DDK General
6.7
MEDIUM
EPSS
0.0%
2024 CWE-823 1 PoC

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

CVE-2024-27370
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on hal_req->num_config_discovery_attr coming from userspace, which can lead to a heap overwrite.

CVE-2024-39580
PowerScale InsightIQ General
6.7
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

CVE-2024-27371
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is no input validation check on hal_req->service_specific_info_len coming from userspace, which can lead to a heap overwrite.

CVE-2024-27373
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->mesh_id_len coming from userspace, which can lead to a heap overwrite.

CVE-2024-29975
NAS326 firmware Cloud
6.7
MEDIUM
EPSS
0.3%
2024 CWE-269 2 PoCs

** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated local attacker with administrator privileges to execute some system commands as the “root” user on a vulnerable device.

CVE-2024-31804
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 2 PoCs

An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privileges via the Program.exe component.

CVE-2024-20863
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.

CVE-2024-21107
VM VirtualBox Database Windows
6.7
MEDIUM
EPSS
0.1%
2024 2 PoCs

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows hosts only. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/