6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-5083
Nexus Repository Web
5.1
MEDIUM
EPSS
0.4%
2024 CWE-79 2 PoCs

A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.

CVE-2024-47095
Destiny General
5.1
MEDIUM
EPSS
0.9%
2024 CWE-79 1 PoC

Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code via the expiredSupportMessage parameter of handleloginform.do.

CVE-2024-58323
Xperience Web
5.1
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Checkbox form component. This allows malicious scripts to execute in users' browsers by exploiting HTML support in the form builder.

CVE-2024-34641
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration.

CVE-2024-6937
Form Tools Web
5.1
MEDIUM
EPSS
0.1%
2024 CWE-73 1 PoC

A vulnerability, which was classified as problematic, was found in formtools.org Form Tools 3.1.1. Affected is the function curl_exec of the file /admin/forms/option_lists/edit.php of the component Import Option List. The manipulation of the argument url leads to file inclusion. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-271992. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-7900
TpMeCMS Web
5.1
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in xiaohe4966 TpMeCMS 1.3.3.2. Affected is an unknown function of the file /h.php/general/config?ref=addtabs of the component Basic Configuration Handler. The manipulation of the argument Site Name/Beian/Contact address/copyright/technical support leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-13013
Maid Hiring Management System Web
5.1
MEDIUM
EPSS
0.0%
2024 CWE-79 1 PoC

A vulnerability, which was classified as problematic, was found in PHPGurukul Maid Hiring Management System 1.0. Affected is an unknown function of the file /admin/contactus.php of the component Contact Us Page. The manipulation of the argument page title leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-7616
IC-6220DC General
5.1
MEDIUM
EPSS
0.5%
2024 CWE-77 1 PoC

A vulnerability was found in Edimax IC-6220DC and IC-5150W up to 3.06. It has been rated as critical. Affected by this issue is the function cgiFormString of the file ipcam_cgi. The manipulation of the argument host leads to command injection. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-7446
Ticket Reservation System Web Database
5.1
MEDIUM
EPSS
0.0%
2024 CWE-89 1 PoC

A vulnerability, which was classified as critical, was found in itsourcecode Ticket Reservation System 1.0. This affects an unknown part of the file list_tickets.php. The manipulation of the argument prefSeat_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273531.

CVE-2024-11101
Beauty Parlour Management System Web Database
5.1
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/search-invoices.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-22318
i Access Client Solutions Windows
5.1
MEDIUM
EPSS
0.2%
2024 CWE-327 2 PoCs

IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate using the current user's session. The hostile server could capture the NTLM hash information to obtain the user's credentials. IBM X-Force ID: 279091.

CVE-2024-5340
RG-UAC Web Networking
5.1
MEDIUM
EPSS
0.4%
2024 CWE-78 1 PoC

A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been rated as critical. Affected by this issue is some unknown functionality of the file /view/vpn/autovpn/sub_commit.php. The manipulation of the argument key leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-266246 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-20885
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper component protection vulnerability in Samsung Dialer prior to SMR May-2024 Release 1 allows local attackers to make a call without proper permission.

CVE-2024-10197
Pharmacy Management System Web
5.1
MEDIUM
EPSS
0.1%
2024 CWE-79 1 PoC

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /manage_supplier.php of the component Manage Supplier Page. The manipulation of the argument address leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

CVE-2024-7604
Unified SecOps Platform Web
5.1
MEDIUM
EPSS
0.0%
2024 CWE-863 1 PoC

Logsign Unified SecOps Platform Incorrect Authorization Authentication Bypass Vulnerability. This vulnerability allows local attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is required to exploit this vulnerability. The specific flaw exists within the HTTP API service, which listens on TCP port 443 by default. The issue results from the lack of proper validation of the user's license expiration date. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-25029.

CVE-2024-10354
Petrol Pump Management Software Web Database
5.1
MEDIUM
EPSS
0.1%
2024 CWE-89 3 PoCs

A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/print.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-5195
VAP2500 Web
5.1
MEDIUM
EPSS
0.3%
2024 CWE-77 1 PoC

A vulnerability was found in Arris VAP2500 08.50. It has been rated as critical. Affected by this issue is some unknown functionality of the file /diag_s.php. The manipulation of the argument customer_info leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-265832.

CVE-2024-6006
ZKBio CVSecurity V5000 General
5.1
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Summer Schedule Handler. The manipulation of the argument Schedule Name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor explains, "that ZKBio Security V5000 has been withdrawn from the market and [is] recommended for upgrading to the ZKBio CVSecurity latest version." This vulnerability only affects products that are no longer supported

CVE-2024-34648
Samsung Mobile Devices General
5.1
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.

CVE-2024-8523
lmxcms Web Database
5.1
MEDIUM
EPSS
0.9%
2024 CWE-94 1 PoC

A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatData of the file /admin.php?m=Acquisi&a=testcj&lid=1 of the component SQL Command Execution Module. The manipulation of the argument data leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.