6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-21262
MySQL Connectors Database
6.5
MEDIUM
EPSS
0.2%
2024 2 PoCs

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS

CVE-2024-48052
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources. This can lead to the download of local resources and sensitive information.

CVE-2024-37607
Software Genérico Web
6.5
MEDIUM
EPSS
0.8%
2024 2 PoCs

A Buffer overflow vulnerability in D-Link DAP-2555 REVA_FIRMWARE_1.20 allows remote attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

CVE-2024-40776
Safari General
6.5
MEDIUM
EPSS
0.5%
2024 4 PoCs

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2024-9765
EKC Tournament Manager Web Windows ⚡ nuclei
6.5
MEDIUM
EPSS
4.6%
2024 1 PoC

The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory

CVE-2024-45183
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPEG length check leads to an out-of-bound write.

CVE-2024-34958
Software Genérico Web
6.5
MEDIUM
EPSS
2.8%
2024 2 PoCs

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/banner_deal.php?mudi=add

CVE-2024-2430
Website Content in Page or Post Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-56915
Software Genérico Web
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget.

CVE-2024-1076
SSL Zen Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.

CVE-2024-43278
Meta Field Block Web
6.5
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Phi Phan Meta Field Block allows Stored XSS.This issue affects Meta Field Block: from n/a through 1.2.13.

CVE-2024-44662
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.

CVE-2024-7518
Firefox General
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.

CVE-2024-57760
Software Genérico Database
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CGReportDao.java.

CVE-2024-33213
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/RouteStatic.

CVE-2024-21641
framework General ⚡ nuclei
6.5
MEDIUM
EPSS
39.1%
2024 CWE-601 0 PoCs

Flarum is open source discussion platform software. Prior to version 1.8.5, the Flarum `/logout` route includes a redirect parameter that allows any third party to redirect users from a (trusted) domain of the Flarum installation to redirect to any link. For logged-in users, the logout must be confirmed. Guests are immediately redirected. This could be used by spammers to redirect to a web address using a trusted domain of a running Flarum installation. The vulnerability has been fixed and published as flarum/core v1.8.5. As a workaround, some extensions modifying the logout route can remedy t

CVE-2024-50848
Software Genérico General
6.5
MEDIUM
EPSS
7.9%
2024 2 PoCs

An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.

CVE-2024-43998
Blogpoet General
6.5
MEDIUM
EPSS
26.0%
2024 CWE-862 2 PoCs

Missing Authorization vulnerability in WebsiteinWP Blogpoet allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blogpoet: from n/a through 1.0.3.

CVE-2024-54994
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature.

CVE-2024-6755
Social Auto Poster Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 CWE-862 1 PoC

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the ‘wpw_auto_poster_quick_delete_multiple’ function in all versions up to, and including, 5.3.14. This makes it possible for unauthenticated attackers to delete arbitrary posts.