7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-30325
PDF Reader General
7.8
HIGH
EPSS
2.2%
2024 CWE-416 1 PoC

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects in AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of th

CVE-2024-46973
Graphics DDK General
7.8
HIGH
EPSS
0.1%
2024 CWE-416 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

CVE-2024-6379
3DSwymer Web
7.7
HIGH
EPSS
1.0%
2024 CWE-79 1 PoC

A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-8040
3DSwymer General
7.7
HIGH
EPSS
0.0%
2024 CWE-639 1 PoC

An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an authenticated attacker to access some unauthorized data.

CVE-2024-34737
Android Windows
7.7
HIGH
EPSS
0.1%
2024 1 PoC

In ensureSetPipAspectRatioQuotaTracker of ActivityClientController.java, there is a possible way to generate unmovable and undeletable pip windows due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-34598
GoodLock General
7.7
HIGH
EPSS
0.0%
2024 1 PoC

Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to install arbitrary applications from Galaxy Store.

CVE-2024-12015
WP Project Manager Web Database Windows
7.7
HIGH
EPSS
0.3%
2024 CWE-89 1 PoC

The 'Project Manager' WordPress Plugin is affected by an authenticated SQL injection vulnerability in the 'orderby' parameter in the '/pm/v2/activites' route.

CVE-2024-31210
wordpress-develop Web Windows
7.7
HIGH
EPSS
1.0%
2024 CWE-434 1 PoC

WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted as a new plugin by an administrative user on the Plugins -> Add New -> Upload Plugin screen in WordPress. If FTP credentials are requested for installation (in order to move the file into place outside of the `uploads` directory) then the uploaded file remains temporary available in the Media Library despite it not being allowed. If the `DISALLOW_FILE_EDIT` constant is set to `true` on the site _and_ FTP credentials are required when uploading a new theme or plugin, th

CVE-2024-43687
TimeProvider 4100 Web
7.7
HIGH
EPSS
3.4%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

CVE-2024-40824
iOS and iPadOS General
7.7
HIGH
EPSS
0.0%
2024 2 PoCs

This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.

CVE-2024-8698
Software Genérico General ⚡ nuclei
7.7
HIGH
EPSS
81.3%
2024 CWE-347 1 PoC

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the full document or only for specific assertions based on the position of the signature in the XML document, rather than the Reference element used to specify the signed element. This flaw allows attackers to create crafted responses that can bypass the validation, potentially leading to privilege escalation or impersonation attacks.

CVE-2024-38449
Software Genérico General
7.7
HIGH
EPSS
0.2%
2024 1 PoC

A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versions allows remote authenticated attackers to browse parent directories and read the content of files outside the scope of the application.

CVE-2024-9183
GitLab DevOps
7.7
HIGH
EPSS
0.0%
2024 CWE-367 1 PoC

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context under specific conditions.

CVE-2024-40676
Android General
7.7
HIGH
EPSS
0.1%
2024 3 PoCs

In checkKeyIntent of AccountManagerService.java, there is a possible way to bypass intent security check and install an unknown app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-1163
mbloch/mapshaper General
7.7
HIGH
EPSS
0.1%
2024 CWE-22 1 PoC

The attacker may exploit a path traversal vulnerability leading to information disclosure.

CVE-2024-27155
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.7
HIGH
EPSS
0.1%
2024 CWE-276 1 PoC

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by malicious programs by any local or remote attacker. As for the affected products/models/versions, see the reference URL.

CVE-2024-40805
iOS and iPadOS General
7.7
HIGH
EPSS
0.0%
2024 2 PoCs

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.

CVE-2024-20895
Samsung Mobile Devices General
7.7
HIGH
EPSS
0.0%
2024 1 PoC

Improper access control in Dar service prior to SMR Jul-2024 Release 1 allows local attackers to bypass restriction for calling SDP features.

CVE-2024-56429
iLabClient General
7.7
HIGH
EPSS
0.1%
2024 CWE-321 1 PoC

itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users to read or write to the database.

CVE-2024-5585
PHP Web Windows
7.7
HIGH
EPSS
0.9%
2024 CWE-116 1 PoC

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.