6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-43451
🔥 KEV Windows Server 2025 Windows
6.5
MEDIUM
EPSS
90.3%
2024 CWE-73 1 PoC

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2024-48442
Software Genérico Networking
6.5
MEDIUM
EPSS
0.1%
2024 2 PoCs

Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows attackers to access the SSH protocol without authentication.

CVE-2024-54763
Software Genérico General ⚡ nuclei
6.5
MEDIUM
EPSS
5.5%
2024 0 PoCs

An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.

CVE-2024-39601
CPCI85 Central Processing/Communication General
6.5
MEDIUM
EPSS
0.4%
2024 CWE-306 1 PoC

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). Affected devices allow a remote authenticated user or an unauthenticated user with physical access to downgrade the firmware of the device. This could allow an attacker to downgrade the device to older versions with known vulnerabilities.

CVE-2024-45877
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User Management function in /Apps/TOPqw/BenutzerManagement.aspx. This allows a low privileged user to access all modules in the web portal, view and manipulate information and permissions of other users, lock other user or unlock the own account, change the password of other users, create new users or delete existing users and view, manipulate and delete reference data.

CVE-2024-3044
LibreOffice General
6.5
MEDIUM
EPSS
2.4%
2024 CWE-356 1 PoC

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.

CVE-2024-44644
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php.

CVE-2024-42849
Software Genérico General
6.5
MEDIUM
EPSS
11.3%
2024 2 PoCs

An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

CVE-2024-22532
Software Genérico Windows
6.5
MEDIUM
EPSS
5.1%
2024 1 PoC

Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file.

CVE-2024-40673
Android General
6.5
MEDIUM
EPSS
1.7%
2024 1 PoC

In Source of ZipFile.java, there is a possible way for an attacker to execute arbitrary code by manipulating Dynamic Code Loading due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-44630
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Multiple parameters in register.php in PHPGurukul Student Record System 3.20 are vulnerable to SQL injection. These include: c-full, fname, mname,lname, gname, ocp, nation, mobno, email, board1, roll1, pyear1, board2, roll2, pyear2, sub1,marks1, sub2, course-short, income, category, ph, country, state, city, padd, cadd, and gender.

CVE-2024-7135
Tainacan Web Windows
6.5
MEDIUM
EPSS
48.0%
2024 CWE-862 2 PoCs

The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions up to, and including, 0.21.7. The function is also vulnerable to directory traversal. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2024-40617
FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS) General
6.5
MEDIUM
EPSS
17.0%
2024 1 PoC

Path traversal vulnerability exists in FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS). If a remote authenticated attacker with User Class privilege sends a specially crafted request to the affected product, access restricted files containing sensitive information may be accessed. As a result, Administrator Class privileges of the product may be hijacked.

CVE-2024-38200
Microsoft Office 2019 General
6.5
MEDIUM
EPSS
55.7%
2024 CWE-200 1 PoC

Microsoft Office Spoofing Vulnerability

CVE-2024-12379
GitLab DevOps
6.5
MEDIUM
EPSS
0.1%
2024 CWE-770 1 PoC

A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.

CVE-2024-40472
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."

CVE-2024-5692
Firefox Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

CVE-2024-54999
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module.

CVE-2024-5071
Bookster Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

CVE-2024-54083
Mattermost General
6.5
MEDIUM
EPSS
0.5%
2024 CWE-1287 1 PoC

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the type of callProps which allows a user to cause a client side (webapp and mobile) DoS to users of particular channels, by sending a specially crafted post.