6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-40818
iOS and iPadOS General
4.6
MEDIUM
EPSS
0.1%
2024 4 PoCs

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data.

CVE-2024-40635
containerd DevOps
4.6
MEDIUM
EPSS
0.1%
2024 CWE-190 1 PoC

containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This could cause unexpected behavior for environments that require containers to run as a non-root user. This bug has been fixed in containerd 1.6.38, 1.7.27, and 2.04. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

CVE-2024-8661
Concrete CMS Web
4.6
MEDIUM
EPSS
0.5%
2024 CWE-79 1 PoC

Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in the "Next&Previous Nav" block. A rogue administrator could add a malicious payload by executing it in the browsers of targeted users. The Concrete CMS Security Team gave this vulnerability a CVSS v4 score of 4.6 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N  Since the "Next&Previous Nav" block output was not sufficiently sanitized, the malicious payload could be executed in

CVE-2024-13126
Download Manager Web Windows ⚡ nuclei
4.6
MEDIUM
EPSS
1.5%
2024 1 PoC

The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web servers that don't use htaccess, allowing unauthorized access of files.

CVE-2024-48415
Software Genérico Web
4.6
MEDIUM
EPSS
0.6%
2024 1 PoC

itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastname, firstname, middlename, address, contact_no, email and tax_id parameters in new borrowers functionality on the Borrowers page.

CVE-2024-49403
Samsung Voice Recorder General
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper access control in Samsung Voice Recorder prior to version 21.5.40.37 allows physical attackers to access recording files on the lock screen.

CVE-2024-20827
Gallery General
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access the picture using physical keyboard on the lockscreen.

CVE-2024-37601
Software Genérico General
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6. A possible heap buffer overflow exists in the user data import/export function of NTG 6 head units. To perform this attack, local access to the USB interface of the car is needed. With prepared data, an attacker can cause the User-Data service to fail. The failed service instance will restart automatically.

CVE-2024-40886
Mattermost Web
4.6
MEDIUM
EPSS
0.2%
2024 CWE-352 1 PoC

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in User Management page of the system console.

CVE-2024-31799
Software Genérico General
4.6
MEDIUM
EPSS
0.0%
2024 1 PoC

Information Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the WiFi passphrase via the UART Debugging Port.

CVE-2024-49407
Samsung Flow General
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles.

CVE-2024-46872
Mattermost Web
4.6
MEDIUM
EPSS
0.1%
2024 CWE-352 1 PoC

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks

CVE-2024-34642
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.

CVE-2024-20802
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users&#39; notification in a multi-user environment.

CVE-2024-4271
SVGator Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.

CVE-2024-22854
Software Genérico General
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before has been identified. A URL, crafted by a remote attacker and visited by an authenticated user, allows open redirect and potential credential stealing using an injected HTML form.

CVE-2024-34653
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.

CVE-2024-34674
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.

CVE-2024-34639
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.

CVE-2024-40813
iOS and iPadOS General
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

A lock screen issue was addressed with improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data.