6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-6512
Devolutions Server General
6.5
MEDIUM
EPSS
0.1%
2024 CWE-863 1 PoC

Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism.

CVE-2024-51030
Software Genérico Web Database
6.5
MEDIUM
EPSS
7.6%
2024 2 PoCs

A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, leading to unauthorized access and potential compromise of sensitive data within the database.

CVE-2024-30043
Microsoft SharePoint Enterprise Server 2016 Windows
6.5
MEDIUM
EPSS
54.1%
2024 CWE-611 1 PoC

Microsoft SharePoint Server Information Disclosure Vulnerability

CVE-2024-13117
Social Share Buttons for WordPress Web Windows
6.5
MEDIUM
EPSS
1.1%
2024 1 PoC

The Social Share Buttons for WordPress plugin through 2.7 allows an unauthenticated user to upload arbitrary images and change the path where they are uploaded

CVE-2024-0378
AI Engine – The Chatbot, AI Framework & MCP for WordPress Web Windows
6.5
MEDIUM
EPSS
6.2%
2024 CWE-79 1 PoC

The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the AI chat data when discussion tracking is enabled in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2024-38359
lnd General
6.5
MEDIUM
EPSS
0.2%
2024 CWE-20 1 PoC

The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability in lnd's onion processing logic and lead to a DoS vector due to excessive memory allocation. The issue was patched in lnd v0.17.0. Users should update to a version > v0.17.0 to be protected. Users unable to upgrade may set the `--rejecthtlc` CLI flag and also disable forwarding on channels via the `UpdateChanPolicyCommand`, or disable listening on a public network interface via the `--nolisten` flag as a mitigation.

CVE-2024-53614
Software Genérico Cloud
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive data and execute arbitrary commands with elevated privileges.

CVE-2024-42903
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows attackers to send users a crafted password reset link that will direct victims to a malicious domain.

CVE-2024-52531
libsoup General
6.5
MEDIUM
EPSS
0.1%
2024 CWE-787 1 PoC

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this remotely via soup_message_headers_get_content_type (e.g., an application may want to retrieve the content type of a request or response).

CVE-2024-45736
Splunk Enterprise Web Cloud
6.5
MEDIUM
EPSS
0.1%
2024 CWE-400 1 PoC

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a search query with an improperly formatted "INGEST_EVAL" parameter as part of a [Field Transformation](https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Managefieldtransforms) which could crash the Splunk daemon (splunkd).

CVE-2024-24445
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

OpenAirInterface CN5G AMF (oai-cn5g-amf) <= 2.0.0 contains a null dereference in its handling of unsupported NGAP protocol messages which allows an attacker with network-adjacent access to the AMF to carry out denial of service. When a procedure code/presence field tuple is received that is unsupported, OAI indexes into a null function pointer and subsequently dereferences it.

CVE-2024-8308
UmweltOffice Web Database
6.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP request input data which allows to exfiltrate all data.

CVE-2024-44658
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection via the subcategory and category parameters in subcategory.php.

CVE-2024-27661
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2024-55963
Software Genérico DevOps Web
6.5
MEDIUM
EPSS
37.2%
2024 1 PoC

An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limited to Appsmith's own server only, but there is a denial of service because it can be continually restarted. This is due to incorrect access control checks, which should check for super user permissions on the incoming request.

CVE-2024-52917
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., large M-SEARCH replies from a fake UPnP device.

CVE-2024-27878
macOS General
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code with kernel privileges.

CVE-2024-57725
Software Genérico General
6.5
MEDIUM
EPSS
15.0%
2024 1 PoC

An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication, causing an internet service disruption via the /firstconnection.cgi endpoint.

CVE-2024-46978
xwiki-platform General
6.5
MEDIUM
EPSS
0.5%
2024 CWE-648 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible for any user knowing the ID of a notification filter preference of another user, to enable/disable it or even delete it. The impact is that the target user might start loosing notifications on some pages because of this. This vulnerability is present in XWiki since 13.2-rc-1. This vulnerability has been patched in XWiki 14.10.21, 15.5.5, 15.10.1, 16.0-rc-1. The patch consists in checking properly the rights of the user before performing any action on the filters. Users are adv

CVE-2024-49197
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 2 PoCs

An issue was discovered in Wi-Fi in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, W920, W930, and W1000. Lack of a boundary check in STOP_KEEP_ALIVE_OFFLOAD leads to out-of-bounds access.