6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-2697
socialdriver-framework Web Windows
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

The socialdriver-framework WordPress plugin before 2024.0.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

CVE-2024-55457
Software Genérico General ⚡ nuclei
6.5
MEDIUM
EPSS
80.4%
2024 1 PoC

MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by manipulating the file parameter to access arbitrary files on the server, potentially exposing sensitive information.

CVE-2024-25742
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and can trigger its handler. This affects AMD SEV-SNP and AMD SEV-ES.

CVE-2024-48450
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into chat group.

CVE-2024-44663
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.

CVE-2024-44664
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php.

CVE-2024-7864
Favicon Generator (CLOSED) Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server

CVE-2024-38348
Software Genérico Database
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Staff Info module via the searvalu parameter.

CVE-2024-3963
Giveaways and Contests by RafflePress Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks

CVE-2024-21196
MySQL Server Database
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2024-34020
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

A stack-based buffer overflow was found in the putSDN() function of mail.c in hcode through 2.1.

CVE-2024-48121
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The HI-SCAN 6040i Hitrax HX-03-19-I was discovered to transmit user credentials in cleartext over the GIOP protocol. This allows attackers to possibly gain access to sensitive information via a man-in-the-middle attack.

CVE-2024-7859
Visual Sound Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-28323
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.1%
2024 2 PoCs

The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The script retrieves user-provided date inputs without proper validation, making it susceptible to SQL injection attacks.

CVE-2024-21106
VM VirtualBox Database
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM Virt

CVE-2024-48120
Software Genérico Web
6.5
MEDIUM
EPSS
2.6%
2024 1 PoC

X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject malicious JavaScript code into the "Name" field when creating a list.

CVE-2024-34946
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.

CVE-2024-21104
Sun ZFS Storage Appliance Kit (AK) Software Database
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS Storage Appliance Kit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 6.5 (Confidentiality, Integrity and Availability imp

CVE-2024-47217
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated endpoint. It can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.

CVE-2024-52317
Apache Tomcat Web
6.5
MEDIUM
EPSS
21.1%
2024 1 PoC

Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.