6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-40094
Software Genérico General
5.3
MEDIUM
EPSS
17.5%
2024 3 PoCs

GraphQL Java (aka graphql-java) before 21.5 does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service via introspection queries. 20.9 and 19.11 are also fixed versions.

CVE-2024-49358
ZimaOS Web
5.3
MEDIUM
EPSS
0.3%
2024 CWE-203 2 PoCs

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Server-IP>/v1/users/login` in ZimaOS returns distinct responses based on whether a username exists or the password is incorrect. This behavior can be exploited for username enumeration, allowing attackers to determine whether a user exists in the system or not. Attackers can leverage this information in further attacks, such as credential stuffing or targeted password brute-forcing. As of time of publication, no known patched versions

CVE-2024-5115
Complete Web-Based School Management System Web Database
5.3
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability classified as critical was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view/teacher_profile.php. The manipulation of the argument index leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-265105 was assigned to this vulnerability.

CVE-2024-8867
CRM Web
5.3
MEDIUM
EPSS
0.1%
2024 CWE-79 2 PoCs

A vulnerability was found in Perfex CRM 3.1.6. It has been declared as problematic. This vulnerability affects unknown code of the file application/controllers/Clients.php of the component Parameter Handler. The manipulation of the argument message leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

CVE-2024-9041
Best House Rental Management System Web Database
5.3
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=update_account. The manipulation of the argument firstname/lastname/email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-2473
WPS Hide Login Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
14.3%
2024 CWE-863 0 PoCs

The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.

CVE-2024-34663
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.0%
2024 1 PoC

Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory.

CVE-2024-26144
rails Web
5.3
MEDIUM
EPSS
3.1%
2024 CWE-200 1 PoC

Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak. The vulnerability is fixed in 7.0.8.1 and 6.1.7.7.

CVE-2024-12953
Portfolio Management System MCA Web
5.3
MEDIUM
EPSS
0.0%
2024 CWE-434 1 PoC

A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected by this issue is some unknown functionality of the file /update_pd_process.php. The manipulation of the argument profile leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-5370
College Management System Web
5.3
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability was found in Kashipara College Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file submit_enroll_staff.php. The manipulation of the argument class_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-266282 is the identifier assigned to this vulnerability.

CVE-2024-12941
Blood Donor Management System Web Database
5.3
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability was found in CodeAstro Blood Donor Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/deletedannounce.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-9536
CDG Database
5.3
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is some unknown functionality of the file /MultiServerBackService?path=1. The manipulation of the argument fileId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-8139
E-Commerce Website Web Database
5.3
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability has been found in itsourcecode E-Commerce Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file search_list.php. The manipulation of the argument user leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-43919
YARPP General ⚡ nuclei
5.3
MEDIUM
EPSS
84.5%
2024 CWE-862 1 PoC

Access Control vulnerability in YARPP YARPP allows . This issue affects YARPP: from n/a through 5.30.10.

CVE-2024-12845
Emlog Pro Web
5.3
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability classified as problematic was found in Emlog Pro up to 2.4.1. Affected by this vulnerability is an unknown functionality in the library /include/lib/common.php. The manipulation of the argument msg leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-7896
Online Store Management System ネット店舗管理システム Web
5.3
MEDIUM
EPSS
2.9%
2024 CWE-77 1 PoC

A vulnerability was found in Tosei Online Store Management System ネット店舗管理システム 4.02/4.03/4.04. It has been rated as critical. Affected by this issue is some unknown functionality of the file /cgi-bin/p1_ftpserver.php. The manipulation of the argument adr_txt leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-34580
Software Genérico Web
5.3
MEDIUM
EPSS
0.0%
2024 3 PoCs

Apache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing (XMLDsig) specification without protection against an SSRF payload in a KeyInfo element. NOTE: the project disputes this CVE Record on the grounds that any vulnerabilities are the result of a failure to configure XML Security for C++ securely. Even when avoiding this particular issue, any use of this library would need considerable additional code and a deep understanding of the standards and protocols involved to arrive at a secure implementation for any particular use case. We recommend against conti

CVE-2024-45440
Drupal core Web ⚡ nuclei
5.3
MEDIUM
EPSS
87.5%
2024 2 PoCs

core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.

CVE-2024-10406
Petrol Pump Management Software Web Database
5.3
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_fuel.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-2863
LG LED Assistant General ⚡ nuclei
5.3
MEDIUM
EPSS
56.8%
2024 CWE-35 0 PoCs

This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.