7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-23722
Software Genérico Web
7.5
HIGH
EPSS
0.9%
2024 3 PoCs

In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.

CVE-2024-2169
RouterOS-TFTP Networking
7.5
HIGH
EPSS
1.6%
2024 2 PoCs

Implementations of UDP application protocol are vulnerable to network loops. An unauthenticated attacker can use maliciously-crafted packets against a vulnerable implementation that can lead to Denial of Service (DOS) and/or abuse of resources.

CVE-2024-34478
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

btcd before 0.24.0 does not correctly implement the consensus rules outlined in BIP 68 and BIP 112, making it susceptible to consensus failures. Specifically, it uses the transaction version as a signed integer when it is supposed to be treated as unsigned. There can be a chain split and loss of funds.

CVE-2024-4773
Firefox General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site. This vulnerability affects Firefox < 126.

CVE-2024-24989
NGINX Plus Web
7.5
HIGH
EPSS
0.6%
2024 CWE-476 1 PoC

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . NOTE: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-13478
LTL Freight Quotes – TForce Edition Web Database Windows
7.5
HIGH
EPSS
18.7%
2024 CWE-89 1 PoC

The LTL Freight Quotes – TForce Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-36991
Splunk Enterprise Windows ⚡ nuclei
7.5
HIGH
EPSS
93.5%
2024 CWE-35 11 PoCs

In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.

CVE-2024-25734
Software Genérico General
7.5
HIGH
EPSS
6.3%
2024 1 PoC

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, which might make it easier for remote attackers to enumerate user accounts.

CVE-2024-55008
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent legitimate users from accessing their accounts by repeatedly sending multiple failed login attempts. Specifically, by submitting 3 incorrect login attempts every minute, the attacker can trigger the account lockout mechanism on the account level, effectively locking the user out indefinitely. Since the lockout is applied to the user account and not based on the IP address, any attacker can trigger the lockout on any user account, regardless of their privileges.

CVE-2024-48140
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

CVE-2024-30251
aiohttp Web
7.5
HIGH
EPSS
0.3%
2024 CWE-835 1 PoC

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server will enter an infinite loop and be unable to process any further requests. An attacker can stop the application from serving requests after sending a single request. This issue has been addressed in version 3.9.4. Users are advised to upgrade. Users unable to upgrade may manually apply a patch to their systems. Please see the linked GHSA for instructions.

CVE-2024-55272
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function.

CVE-2024-47922
PRI WEB General
7.5
HIGH
EPSS
0.1%
2024 CWE-200 1 PoC

Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-47522
suricata General
7.5
HIGH
EPSS
0.3%
2024 CWE-617 2 PoCs

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, invalid ALPN in TLS/QUIC traffic when JA4 matching/logging is enabled can lead to Suricata aborting with a panic. This issue has been addressed in 7.0.7. One may disable ja4 as a workaround.

CVE-2024-21522
audify General
7.5
HIGH
EPSS
0.3%
2024 CWE-129 1 PoC

All versions of the package audify are vulnerable to Improper Validation of Array Index when frameSize is provided to the new OpusDecoder().decode or new OpusDecoder().decodeFloat functions it is not checked for negative values. This can lead to a process crash.

CVE-2024-44083
Software Genérico General
7.5
HIGH
EPSS
11.7%
2024 2 PoCs

ida64.dll in Hex-Rays IDA Pro through 8.4 crashes when there is a section that has many jumps linked, and the final jump corresponds to the payload from where the actual entry point will be invoked. NOTE: in many use cases, this is an inconvenience but not a security issue.

CVE-2024-39614
Software Genérico General
7.5
HIGH
EPSS
6.8%
2024 1 PoC

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings containing specific characters.

CVE-2024-47920
CMS Web
7.5
HIGH
EPSS
0.1%
2024 CWE-79 1 PoC

Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2024-40786
iOS and iPadOS General
7.5
HIGH
EPSS
0.2%
2024 3 PoCs

This issue was addressed through improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Ventura 13.6.8. An attacker may be able to view sensitive user information.

CVE-2024-24444
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

Improper file descriptor handling for closed connections in OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface.