6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-20854
Samsung Camera General
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper handling of insufficient privileges vulnerability in Samsung Camera prior to versions 12.1.0.31 in Android 12, 13.1.02.07 in Android 13, and 14.0.01.06 in Android 14 allows local attackers to access image data.

CVE-2024-10105
Job Postings Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-6243
HTML Forms Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.

CVE-2024-4752
EventON Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The EventON WordPress plugin before 2.2.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-3472
Modal Window Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2024-34586
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.

CVE-2024-24455
HPE Athonet Core General
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

An invalid memory access when handling a UE Context Release message containing an invalid UE identifier in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

CVE-2024-3113
FormFlow: WhatsApp Social and Advanced Form Builder with Easy Lead Collection Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The FormFlow: WhatsApp Social and Advanced Form Builder with Easy Lead Collection WordPress plugin before 2.12.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-34273
Software Genérico General
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

njwt up to v0.4.0 was discovered to contain a prototype pollution in the Parser.prototype.parse method.

CVE-2024-5604
Bug Library Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Bug Library WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-2118
Social Media Share Buttons & Social Sharing Icons Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-28818
Software Genérico General
5.9
MEDIUM
EPSS
0.3%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 2400, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not properly check states specified by the RRC (Radio Resource Control) module. This can lead to disclosure of sensitive information.

CVE-2024-10076
Jetpack Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelerator features when switching image URLs to their CDN counterpart. Unfortunately, some of them may match patterns it shouldn’t, ultimately making it possible for contributor and above users to perform Stored XSS attacks

CVE-2024-12289
Boundary Web
5.9
MEDIUM
EPSS
0.4%
2024 CWE-460 1 PoC

Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initialization of the Boundary controller, which may cause the Boundary server to terminate prematurely. Boundary is only vulnerable to this flaw during the initialization of the Boundary controller, which on average is measured in milliseconds during the Boundary startup process. This vulnerability, CVE-2024-12289, is fixed in Boundary Community Edition and Boundary Enterprise 0.16.4, 0.17.3, 0.18.2.

CVE-2024-1743
WooCommerce Customers Manager Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The WooCommerce Customers Manager WordPress plugin before 29.8 does not sanitise and escape various parameters before outputting them back in pages and attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-27623
Software Genérico Web
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumbs.

CVE-2024-13113
Countdown Timer for Elementor Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Countdown Timer for Elementor WordPress plugin before 1.3.7 does not sanitise and escape some parameters when outputting them on the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.

CVE-2024-53476
Software Genérico General
5.9
MEDIUM
EPSS
0.5%
2024 1 PoC

A race condition vulnerability in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f allows attackers to bypass inventory restrictions by simultaneously submitting purchase requests from multiple accounts for the same product. This can lead to overselling when stock is limited, as the system fails to accurately track inventory under high concurrency, resulting in potential loss and unfulfilled orders.

CVE-2024-32151
Multiple MFPs (multifunction printers) General
5.9
MEDIUM
EPSS
0.3%
2024 CWE-257 3 PoCs

User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-29146
Multiple MFPs (multifunction printers) General
5.9
MEDIUM
EPSS
0.2%
2024 CWE-312 3 PoCs

User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].