6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-49418
GamingHub Web
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to enable JavaScript in its webview.

CVE-2024-50972
Software Genérico Web Database
6.5
MEDIUM
EPSS
4.8%
2024 1 PoC

A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.

CVE-2024-21507
mysql2 Database
6.5
MEDIUM
EPSS
0.4%
2024 CWE-20 1 PoC

Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon (:) character within a value of the attacker-crafted key.

CVE-2024-37889
MyFinances General
6.5
MEDIUM
EPSS
10.9%
2024 CWE-639 1 PoC

MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method allows an actor to access PII and financial information from another account. The vulnerability is fixed in 0.4.6.

CVE-2024-39037
Software Genérico Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

MyNET up to v26.08.316 was discovered to contain an Unauthenticated SQL Injection vulnerability via the intmenu parameter.

CVE-2024-40789
Safari General
6.5
MEDIUM
EPSS
0.9%
2024 4 PoCs

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2024-48272
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers to connect to the device via a bruteforce attack.

CVE-2024-9450
Free Booking Plugin for Hotels, Restaurants and Car Rentals Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack

CVE-2024-54764
Software Genérico General ⚡ nuclei
6.5
MEDIUM
EPSS
9.0%
2024 0 PoCs

An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensitive information without authentication.

CVE-2024-6977
SDP Client Windows
6.5
MEDIUM
EPSS
0.0%
2024 CWE-532 1 PoC

A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account takeover. However, the attack requires bypassing protections on modifying the tunnel token on a the attacker's system.This issue affects SDP Client: before 5.10.34.

CVE-2024-0879
vector-admin General
6.5
MEDIUM
EPSS
0.0%
2024 CWE-287 1 PoC

Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email address.

CVE-2024-38435
Vision PLC General
6.5
MEDIUM
EPSS
0.1%
2024 CWE-703 1 PoC

Unitronics Vision PLC – CWE-703: Improper Check or Handling of Exceptional Conditions may allow denial of service

CVE-2024-53542
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the NCServiceManger via a crafted GET request.

CVE-2024-22411
avo Web
6.5
MEDIUM
EPSS
5.8%
2024 CWE-79 1 PoC

Avo is a framework to create admin panels for Ruby on Rails apps. In Avo 3 pre12, any HTML inside text that is passed to `error` or `succeed` in an `Avo::BaseAction` subclass will be rendered directly without sanitization in the toast/notification that appears in the UI on Action completion. A malicious user could exploit this vulnerability to trigger a cross site scripting attack on an unsuspecting user. This issue has been addressed in the 3.3.0 and 2.47.0 releases of Avo. Users are advised to upgrade.

CVE-2024-23709
Android General
6.5
MEDIUM
EPSS
4.4%
2024 2 PoCs

In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2024-44660
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php.

CVE-2024-41454
Software Genérico DevOps Web
6.5
MEDIUM
EPSS
0.6%
2024 2 PoCs

An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary code via uploading a crafted PHP or HTML file.

CVE-2024-47308
Templately General ⚡ nuclei
6.5
MEDIUM
EPSS
35.3%
2024 CWE-862 0 PoCs

Missing Authorization vulnerability in WPDeveloper Templately templately.This issue affects Templately: from n/a through <= 3.1.2.

CVE-2024-21388
Microsoft Edge (Chromium-based) General
6.5
MEDIUM
EPSS
24.2%
2024 CWE-20 1 PoC

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVE-2024-21485
dash-core-components Web ⚡ nuclei
6.5
MEDIUM
EPSS
0.9%
2024 CWE-79 5 PoCs

Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package dash-html-components before 2.0.0; versions of the package dash-html-components before 2.0.16 are vulnerable to Cross-site Scripting (XSS) when the href of the a tag is controlled by an adversary. An authenticated attacker who stores a view that exploits this vulnerability could steal the data that's visible to another user who opens that view - not just the data already included on the page, but they could al