6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-34625
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in applying connection point in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

CVE-2024-0147
NVIDIA GPU Display Driver, vGPU software Windows
5.5
MEDIUM
EPSS
0.0%
2024 CWE-416 1 PoC

NVIDIA GPU display driver for Windows and Linux contains a vulnerability where referencing memory after it has been freed can lead to denial of service or data tampering.

CVE-2024-0311
Skyhigh Client Proxy General
5.5
MEDIUM
EPSS
0.1%
2024 CWE-622 1 PoC

A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code.

CVE-2024-40137
Software Genérico Web
5.5
MEDIUM
EPSS
0.5%
2024 1 PoC

Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under the Users Module Setup function.

CVE-2024-1252
OA 2017 Web Database
5.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability classified as critical was found in Tongda OA 2017 up to 11.9. Affected by this vulnerability is an unknown functionality of the file /general/attendance/manage/ask_duty/delete.php. The manipulation of the argument ASK_DUTY_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-252991.

CVE-2024-0312
Skyhigh Client Proxy General
5.5
MEDIUM
EPSS
0.0%
2024 CWE-622 1 PoC

A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password.

CVE-2024-2982
FH1202 General
5.5
MEDIUM
EPSS
5.1%
2024 CWE-77 1 PoC

A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258151. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-34672
SamsungVideoPlayer General
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper input validation in SamsungVideoPlayer prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.3.41.230 in Android 14 allows local attackers to access video file of other users.

CVE-2024-8270
Rocket.Chat Desktop General
5.5
MEDIUM
EPSS
0.1%
2024 CWE-863 1 PoC

The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Control (TCC) policies, enabling the exploitation or abuse of permissions specified in its entitlements (e.g., microphone, camera, automation, network client). Since Rocket.Chat was not signed with the Hardened Runtime nor set to enforce Library Validation, it is vulnerable to DYLIB injection attacks, which can lead to unauthorized actions or escalation of permissions. Consequently, an attacker gains capabilities that are not permitted by default under the Sandbox and its applicat

CVE-2024-40656
Android General
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

In handleCreateConferenceComplete of ConnectionServiceWrapper.java, there is a possible way to reveal images across users due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2024-49412
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch.

CVE-2024-37674
Software Genérico Web
5.5
MEDIUM
EPSS
3.6%
2024 1 PoC

Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new activity.

CVE-2024-34621
Samsung Notes General
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-bounds read in applying binary with data in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

CVE-2024-22368
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2024 3 PoCs

The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX document. This occurs because the memoize implementation does not have appropriate constraints on merged cells.

CVE-2024-0092
GPU display driver, vGPU software, and Cloud Gaming Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2024 CWE-703 1 PoC

NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of service.

CVE-2024-56428
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the CONFIGS table) for their servers configured in the client.

CVE-2024-41832
Acrobat Reader General
5.5
MEDIUM
EPSS
0.1%
2024 CWE-125 1 PoC

Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2024-3207
Simd General
5.5
MEDIUM
EPSS
0.2%
2024 CWE-122 2 PoCs

A vulnerability was found in ermig1979 Simd up to 6.0.134. It has been declared as critical. This vulnerability affects the function ReadUnsigned of the file src/Simd/SimdMemoryStream.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. VDB-259054 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-26160
Windows 11 version 22H2 Cloud Windows
5.5
MEDIUM
EPSS
38.1%
2024 CWE-126 2 PoCs

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

CVE-2024-20869
Samsung Internet General
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies.