6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-21192
Oracle Enterprise Manager for Fusion Middleware Database
4.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Fusion Middleware (component: WebLogic Mgmt). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Enterprise Manager for Fusion Middleware executes to compromise Oracle Enterprise Manager for Fusion Middleware. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Manager for Fusion Middleware accessible data. CV

CVE-2024-0935
DELMIA Apriso General
4.4
MEDIUM
EPSS
0.1%
2024 CWE-532 1 PoC

Insertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Release 2024

CVE-2024-33401
Software Genérico Web
4.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to run arbitrary code via the mnum parameter.

CVE-2024-0322
gpac/gpac General
4.4
MEDIUM
EPSS
0.2%
2024 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.

CVE-2024-34597
Samsung Health General
4.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary document files to the sandbox of Samsung Health. User interaction is required for triggering this vulnerability.

CVE-2024-34676
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. User interaction is required for triggering this vulnerability.

CVE-2024-1977
Restaurant Solutions – Checklist Web Windows
4.4
MEDIUM
EPSS
0.5%
2024 1 PoC

The Restaurant Solutions – Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Checklist points in version 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE-2024-20041
MT2713, MT6781, MT6789, MT6835, MT6855, MT6879, MT6886, MT6895, MT6983, MT6985, MT6989, MT8188, MT8673, MT8676, MT8781 General
4.4
MEDIUM
EPSS
0.1%
2024 1 PoC

In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541746; Issue ID: ALPS08541746.

CVE-2024-55550
🔥 KEV Software Genérico General ⚡ nuclei
4.4
MEDIUM
EPSS
17.7%
2024 0 PoCs

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.

CVE-2024-37360
Pentaho Data Integration & Analytics Web
4.4
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')   The software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79)   Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.0 and 9.3.0.9, including 8.3.x, allow a malicious URL to inject content into the Analyzer plugin interface.   Once the malicious script is injected, the attacker can perform a variety

CVE-2024-21212
MySQL Server Database
4.4
MEDIUM
EPSS
0.2%
2024 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Health Monitor). Supported versions that are affected are 8.0.39 and prior and 8.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2024-7655
Community by PeepSo – Download from PeepSo.com Web Windows
4.4
MEDIUM
EPSS
0.3%
2024 CWE-79 1 PoC

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.4.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

CVE-2024-34643
Samsung Mobile Devices General
4.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.

CVE-2024-50584
Scan2Net Web Database
4.4
MEDIUM
EPSS
0.1%
2024 CWE-89 2 PoCs

An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_io.php file and supplying malicious GET parameters. The "templates" parameter is vulnerable against blind boolean-based SQL injection attacks. SQL syntax must be injected into the JSON syntax of the templates parameter.

CVE-2024-37891
urllib3 Web
4.4
MEDIUM
EPSS
0.3%
2024 CWE-669 1 PoC

urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured proxy, as expected. However, when sending HTTP requests *without* using urllib3's proxy support, it's possible to accidentally configure the `Proxy-Authorization` header even though it won't have any effect as the request is not using a forwarding proxy or a tunneling proxy. In those cases, urllib3 doesn't treat the `Proxy-Authorization` HTTP header as one carrying authentication material and thus doesn't strip the h

CVE-2024-20049
MT2713, MT2737, MT6781, MT6789, MT6835, MT6855, MT6879, MT6880, MT6886, MT6890, MT6895, MT6980, MT6983, MT6985, MT6989, MT6990, MT8167, MT8168, MT8173, MT8175, MT8188, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8390, MT8395, MT8666, MT8667, MT8673, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8796, MT8797, MT8798 General
4.4
MEDIUM
EPSS
0.0%
2024 1 PoC

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541765; Issue ID: ALPS08541765.

CVE-2024-40834
macOS General
4.4
MEDIUM
EPSS
0.0%
2024 2 PoCs

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A shortcut may be able to bypass sensitive Shortcuts app settings.

CVE-2024-41699
Priority General
4.4
MEDIUM
EPSS
0.2%
2024 CWE-552 1 PoC

Priority – CWE-552: Files or Directories Accessible to External Parties

CVE-2024-20868
Samsung Notes General
4.4
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper input validation in Samsung Notes prior to version 4.4.15 allows local attackers to delete files with Samsung Notes privilege under certain conditions.

CVE-2024-27882
macOS General
4.4
MEDIUM
EPSS
0.0%
2024 2 PoCs

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.