3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-40821
macOS General
8.4
HIGH
EPSS
0.0%
2024 2 PoCs

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Third party app extensions may not receive the correct sandbox restrictions.

CVE-2024-32229
Software Genérico General
8.4
HIGH
EPSS
0.2%
2024 1 PoC

FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.

CVE-2024-51381
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security and integrity of the platform, especially if an attacker gains administrative control.

CVE-2024-28146
Scan2Net General
8.4
HIGH
EPSS
0.1%
2024 CWE-798 2 PoCs

The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some passwords allow a direct connection to the database server of the affected device.

CVE-2024-48214
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulnerability allows an attacker to create a custom, unauthenticated QR code and abuse one of the parameters, either SSID or PASSWORD, in the JSON data contained within the QR code. By that, the attacker can execute arbitrary code on the camera.

CVE-2024-20812
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.0%
2024 1 PoC

Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

CVE-2024-48123
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue in the USB Autorun function of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to execute arbitrary code via uploading a crafted script from a USB device.

CVE-2024-31319
Android General
8.4
HIGH
EPSS
0.0%
2024 2 PoCs

In updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a possible cross-user data leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-31956
Software Genérico General
8.4
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length checking, which can result in an Out-of-Bounds Write.

CVE-2024-31959
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which can result in code execution.

CVE-2024-38890
Software Genérico General
8.4
HIGH
EPSS
0.0%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by Capture-replay attack due to insufficient protection against capture-replay attacks.

CVE-2024-40781
macOS General
8.4
HIGH
EPSS
0.0%
2024 2 PoCs

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A local attacker may be able to elevate their privileges.

CVE-2024-40811
macOS General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to modify protected parts of the file system.

CVE-2024-45271
mbNET.mini General
8.4
HIGH
EPSS
0.1%
2024 CWE-94 1 PoC

An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.

CVE-2024-29050
Windows 10 Version 1809 Windows
8.4
HIGH
EPSS
38.3%
2024 CWE-197 1 PoC

Windows Cryptographic Services Remote Code Execution Vulnerability

CVE-2024-54028
catdoc General
8.4
HIGH
EPSS
0.2%
2024 CWE-191 2 PoCs

An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-45273
mbNET.mini General
8.4
HIGH
EPSS
0.1%
2024 CWE-261 1 PoC

An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.

CVE-2024-2608
Firefox General
8.4
HIGH
EPSS
0.2%
2024 1 PoC

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVE-2024-36600
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.

CVE-2024-51380
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Stored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9.3. This flaw allows an attacker to inject malicious JavaScript into the properties section of a study, specifically within the UUID field. When an admin user accesses the study's properties, the injected script is executed in the admin's browser, which could lead to unauthorized actions, including account compromise and privilege escalation.