6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-52016
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component wlg_adv.cgi via the apmode_dns1_pri and apmode_dns1_sec parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-51002
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the l2tp_user_ip parameter at l2tp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-52023
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at pppoe2.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-50994
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component ipv6_fix.cgi via the ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, and ipv6_lan_length parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-51022
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the ssid parameter in bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-2101
Salon booking system Web Windows
5.7
MEDIUM
EPSS
0.7%
2024 1 PoC

The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Customers' page and the malicious script is executed in the admin context.

CVE-2024-44674
Software Genérico Web
5.7
MEDIUM
EPSS
3.8%
2024 1 PoC

D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, allowing it to be used as the value for src.

CVE-2024-52014
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at genie_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-11358
Mattermost General
5.7
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider.

CVE-2024-51003
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component ap_mode.cgi via the apmode_dns1_pri and apmode_dns1_sec parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-51018
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-20840
Samsung Voice Recorder General
5.7
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers using hardware keyboard to use VoiceRecorder on the lock screen.

CVE-2024-21306
Windows Server 2022 Windows
5.7
MEDIUM
EPSS
30.1%
2024 CWE-306 1 PoC

Microsoft Bluetooth Driver Spoofing Vulnerability

CVE-2024-50998
Software Genérico Networking
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component openvpn.cgi via the openvpn_service_port and openvpn_service_port_tun parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-36255
Mattermost General
5.7
MEDIUM
EPSS
0.2%
2024 CWE-352 1 PoC

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist task command as another user via creating and sharing a deceptive post action that unexpectedly runs a slash command in some arbitrary channel.

CVE-2024-6540
OTRS General
5.7
MEDIUM
EPSS
0.5%
2024 CWE-790 1 PoC

Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS could allow an authorized user to download a list of tickets containing information about tickets of other customers. The problem only occurs if the TicketSearchLegacyEngine has been disabled by the administrator. This issue affects OTRS: 8.0.X, 2023.X, from 2024.X through 2024.4.x

CVE-2024-51016
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the addName%d parameter in usb_approve.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-24565
crate Database ⚡ nuclei
5.7
MEDIUM
EPSS
86.5%
2024 CWE-22 0 PoCs

CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM function in the CrateDB database that is used to import file data into database tables. This function has a flaw, and authenticated attackers can use the COPY FROM function to import arbitrary file content into database tables, resulting in information leakage. This vulnerability is patched in 5.3.9, 5.4.8, 5.5.4, and 5.6.1.

CVE-2024-51000
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component wireless.cgi via the opmode, opmode_an, and opmode_an_2 parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-52017
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.