6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-36788
Software Genérico Web Networking
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly intercept and access sensitive communications between the router and connected devices.

CVE-2024-3837
Chrome General
5.9
MEDIUM
EPSS
0.7%
2024 2 PoCs

Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-24458
HPE Athonet Core General
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

An invalid memory access when handling the ENB Configuration Transfer messages containing invalid PLMN Identities in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

CVE-2024-21528
node-gettext General
5.9
MEDIUM
EPSS
0.1%
2024 CWE-1321 1 PoC

All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.

CVE-2024-28145
Scan2Net Web Database
5.9
MEDIUM
EPSS
0.1%
2024 CWE-89 2 PoCs

An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.

CVE-2024-5626
Inline Related Posts Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Inline Related Posts WordPress plugin before 3.7.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-5442
Photo Gallery, Sliders, Proofing and Themes Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-7141
Gliffy Online Web
5.9
MEDIUM
EPSS
0.1%
2024 CWE-352 1 PoC

Versions of Gliffy Online prior to versions 4.14.0-7 contains a Cross Site Request Forgery (CSRF) flaw.

CVE-2024-24452
HPE Athonet Core General
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

CVE-2024-40774
iOS and iPadOS General
5.9
MEDIUM
EPSS
0.0%
2024 3 PoCs

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.

CVE-2024-56087
Software Genérico General
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.

CVE-2024-5573
Easy Table of Contents Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

CVE-2024-4753
WP Secure Maintenance Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-25848
Software Genérico Database
5.9
MEDIUM
EPSS
0.0%
2024 1 PoC

In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affected versions.

CVE-2024-10472
Stylish Price List Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-35526
Software Genérico General
5.9
MEDIUM
EPSS
0.0%
2024 1 PoC

An issue in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to access sensitive information in the /facade directory.

CVE-2024-24453
HPE Athonet Core General
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

An invalid memory access when handling the ProtocolIE_ID field of E-RAB NotToBeModifiedBearerModInd information element in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

CVE-2024-24788
net General
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop.

CVE-2024-20852
SmartThings General
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to access testing configuration.

CVE-2024-2310
WP Google Review Slider Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The WP Google Review Slider WordPress plugin before 13.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)