6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-34051
Software Genérico Web
4.6
MEDIUM
EPSS
1.0%
2024 1 PoC

A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.

CVE-2024-25412
Software Genérico Web
4.6
MEDIUM
EPSS
32.5%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email field.

CVE-2024-3993
AZAN Plugin Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The AZAN Plugin WordPress plugin through 0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-20882
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.3%
2024 1 PoC

Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.

CVE-2024-37602
Software Genérico Web
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Mercedes Benz NTG (New Telematics Generation) 6 through 2021. A possible NULL pointer dereference in the Apple Car Play function affects NTG 6 head units. To perform this attack, physical access to Ethernet pins of the head unit base board is needed. With a static IP address, an attacker can connect via the internal network to the AirTunes / AirPlay service. With prepared HTTP requests, an attacker can cause the Car Play service to fail.

CVE-2024-12247
Mattermost General
4.6
MEDIUM
EPSS
0.1%
2024 CWE-863 1 PoC

Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.

CVE-2024-3843
Chrome General
4.6
MEDIUM
EPSS
0.7%
2024 1 PoC

Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-46335
Software Genérico Web
4.6
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parameters in between-date-userreport.php.

CVE-2024-3919
OpenPGP Form Encryption for WordPress Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-20839
Samsung Voice Recorder General
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers to access recording files on the lock screen.

CVE-2024-24858
Linux kernel General
4.6
MEDIUM
EPSS
0.0%
2024 CWE-362 1 PoC

A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading to denial of service.

CVE-2024-24859
Linux kernel General
4.6
MEDIUM
EPSS
0.0%
2024 CWE-362 1 PoC

A race condition was found in the Linux kernel's net/bluetooth in sniff_{min,max}_interval_set() function. This can result in a bluetooth sniffing exception issue, possibly leading denial of service.

CVE-2024-24857
Linux kernel General
4.6
MEDIUM
EPSS
0.0%
2024 CWE-362 1 PoC

A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to bluetooth connection abnormality or denial of service.

CVE-2024-2432
GlobalProtect App Networking Windows
4.5
MEDIUM
EPSS
0.4%
2024 CWE-269 2 PoCs

A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition.

CVE-2024-3060
ENL Newsletter Web Database Windows
4.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin+ to perform SQL injection attacks

CVE-2024-21530
cocoon General
4.5
MEDIUM
EPSS
0.0%
2024 CWE-323 1 PoC

Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, wrap, and dump functions are sequentially called. An attacker can generate the same ciphertext by creating a new encrypted message with the same cocoon object. **Note:** The issue does NOT affect objects created with Cocoon::new which utilizes ThreadRng.

CVE-2024-47914
VaeMendis Ubooquity version 2.1.2 Web
4.5
MEDIUM
EPSS
0.1%
2024 CWE-352 1 PoC

VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF)

CVE-2024-2405
Float menu Web Windows
4.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers to make logged in admin delete arbitrary menu via a CSRF attack.

CVE-2024-57523
Software Genérico Web
4.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user.

CVE-2024-45833
Mattermost General
4.5
MEDIUM
EPSS
0.2%
2024 CWE-693 1 PoC

Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Swiftkey as the default keyboard, the masking is off and the password contains a special character..