6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-46921
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, Modem 5123, Modem 5300, Modem 5400. UE does not limit the number of attempts for the RRC Setup procedure in the 5G SA, leading to a denial of service (battery-drain attack).

CVE-2024-6230
پلاگین پرداخت دلخواه Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The پلاگین پرداخت دلخواه WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action via a CSRF attack

CVE-2024-45433
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

OpenSynergy BlueSDK (aka Blue SDK) through 6.x has Incorrect Control Flow Scoping. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from the lack of proper return control flow after detecting an unusual condition. An attacker can leverage this to bypass a security validation and make the incoming data be processed.

CVE-2024-8094
Ntz Antispam Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-50967
Software Genérico Web ⚡ nuclei
6.5
MEDIUM
EPSS
37.9%
2024 2 PoCs

The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely access this endpoint without authentication, leading to unauthorized disclosure of sensitive information.

CVE-2024-38030
Windows 10 Version 1809 Windows
6.5
MEDIUM
EPSS
67.5%
2024 CWE-200 2 PoCs

Windows Themes Spoofing Vulnerability

CVE-2024-54682
Mattermost General
6.5
MEDIUM
EPSS
0.2%
2024 CWE-409 1 PoC

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size for slack import file uploads which allows a user to cause a DoS via zip bomb by importing data in a team they are a team admin.

CVE-2024-29197
pimcore General
6.5
MEDIUM
EPSS
0.0%
2024 CWE-200 1 PoC

Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true` allows to view unpublished sites. In previous versions of Pimcore, session information would propagate to previews, so only a logged in user could open a preview. This no longer applies. Previews are broad open to any user and with just the hint of a restricted link one could gain access to possible confident / unreleased information. This vulnerability is fixed in 11.2.2 and 11.1.6.1.

CVE-2024-7137
RS9116 Bluetooth SDK General
6.5
MEDIUM
EPSS
0.2%
2024 CWE-787 1 PoC

The L2CAP receive data buffer for L2CAP packets is restricted to packet sizes smaller than the maximum supported packet size. Receiving a packet that exceeds the restricted buffer length may cause a crash. A hard reset is required to recover the crashed device.

CVE-2024-7514
Comments Import & Export Web Windows
6.5
MEDIUM
EPSS
47.4%
2024 CWE-22 1 PoC

The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and including, 2.3.7. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The issue was partially fixed in version 2.3.8 and fully fixed in 2.3.9

CVE-2024-4260
Page Builder Gutenberg Blocks Web Windows
6.5
MEDIUM
EPSS
0.7%
2024 1 PoC

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow high privilege users such as contributors to perform SSRF attacks.

CVE-2024-5947
DSE855 General ⚡ nuclei
6.5
MEDIUM
EPSS
74.0%
2024 CWE-306 1 PoC

Deep Sea Electronics DSE855 Configuration Backup Missing Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Deep Sea Electronics DSE855 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web-based UI. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-22679.

CVE-2024-7602
Unified SecOps Platform Web
6.5
MEDIUM
EPSS
0.8%
2024 CWE-22 1 PoC

Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within the HTTP API service, which listens on TCP port 443 by default. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to disclose information in the context of root. Was ZDI-C

CVE-2024-53615
Software Genérico General
6.5
MEDIUM
EPSS
20.9%
2024 1 PoC

A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through 0.11.0 allows remote attackers to execute arbitrary code via a crafted video file.

CVE-2024-50651
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

CVE-2024-45987
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vulnerability allows an attacker to craft a malicious link that, when clicked by an authenticated user, automatically submits a vote for a specified party without the user's consent or knowledge. The attack leverages the user's active session to perform the unauthorized action, compromising the integrity of the voting process.

CVE-2024-12301
JSP Store Locator Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.

CVE-2024-45190
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 CWE-35 1 PoC

Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "Pipeline Interaction" request

CVE-2024-27658
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2024-25227
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.6%
2024 2 PoCs

SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive information via the tb_login parameter in admin login page.