6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-21583
github.com/gitpod-io/gitpod/components/server/go/pkg/lib Web
4.1
MEDIUM
EPSS
0.3%
2024 CWE-15 6 PoCs

Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/components/ws-proxy/pkg/proxy before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/install/installer/pkg/components/auth before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/install/installer/pkg/components/public-api-server before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/install/installer/pkg/components/server before main-gha.27122; versions of the package @gitpod/gitpo

CVE-2024-12109
Product Labels For Woocommerce (Sale Badges) Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-52935
Graphics DDK General
4.1
MEDIUM
EPSS
0.1%
2024 CWE-823 1 PoC

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

CVE-2024-9828
Taskbuilder Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it in a SQL statement, allowing high privilege users such as admin to perform SQL Injection attacks

CVE-2024-41162
Mattermost General
4.1
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel read-only.

CVE-2024-34673
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service.

CVE-2024-0134
NVIDIA Container Toolkit DevOps
4.1
MEDIUM
EPSS
0.2%
2024 CWE-61 1 PoC

NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to data tampering.

CVE-2024-20833
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.0%
2024 1 PoC

Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption.

CVE-2024-10638
Product Labels For Woocommerce (Sale Badges) Web Database Windows
4.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-34583
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.

CVE-2024-34680
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information.

CVE-2024-34618
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.

CVE-2024-34635
Samsung Notes General
4.0
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

CVE-2024-4841
parisneo/lollms-webui Web ⚡ nuclei
4.0
MEDIUM
EPSS
8.5%
2024 CWE-29 0 PoCs

A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 to the latest. By exploiting this vulnerability, an attacker can predict the folders, subfolders, and files present on the victim's computer. The vulnerability is present in the way the application handles the 'path' parameter in HTTP requests to the '/add_reference_to_local_model' endpoint.

CVE-2024-34603
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.

CVE-2024-20899
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

CVE-2024-34650
Samsung Mobile Devices Web
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.

CVE-2024-20898
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

CVE-2024-20897
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

CVE-2024-25260
Software Genérico General
4.0
MEDIUM
EPSS
0.0%
2024 1 PoC

elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.