7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-34659
Group Sharing General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victim to join the group.

CVE-2024-49757
zitadel General ⚡ nuclei
7.5
HIGH
EPSS
10.8%
2024 CWE-287 0 PoCs

The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option only hid the registration button on the login page. Users could bypass this restriction by directly accessing the registration URL (/ui/login/loginname) and register a user that way. Versions 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available.

CVE-2024-4227
gSOAP General
7.5
HIGH
EPSS
0.2%
2024 CWE-834 1 PoC

In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forcing to parse an XML having duplicate ID attributes which can lead to a DoS.

CVE-2024-20440
Cisco Smart License Utility Web Networking ⚡ nuclei
7.5
HIGH
EPSS
79.0%
2024 CWE-532 0 PoCs

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain log files that contain sensitive data, including credentials that can be used to access the API.

CVE-2024-34220
Software Genérico Database
7.5
HIGH
EPSS
0.4%
2024 1 PoC

Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.

CVE-2024-31392
Firefox for iOS General
7.5
HIGH
EPSS
0.5%
2024 1 PoC

If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.

CVE-2024-57762
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.

CVE-2024-21523
images General
7.5
HIGH
EPSS
0.2%
2024 CWE-400 1 PoC

All versions of the package images are vulnerable to Denial of Service (DoS) due to providing unexpected input types to several different functions. This makes it possible to reach an assert macro, leading to a process crash. **Note:** By providing some specific integer values (like 0) to the size function, it is possible to obtain a Segmentation fault error, leading to the process crash.

CVE-2024-21536
http-proxy-middleware Web
7.5
HIGH
EPSS
0.4%
2024 CWE-400 1 PoC

Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.

CVE-2024-47920
CMS Web
7.5
HIGH
EPSS
0.1%
2024 CWE-79 1 PoC

Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2024-23660
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the device time is the only entropy source, leading to economic losses, as exploited in the wild in July 2023. An attacker can systematically generate mnemonics for each timestamp within an applicable timeframe, and link them to specific wallet addresses in order to steal funds from those wallets.

CVE-2024-21246
Oracle Service Bus Web Database
7.5
HIGH
EPSS
0.6%
2024 1 PoC

Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Core Functionality). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Bus. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Service Bus accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2024-34350
next.js Web
7.5
HIGH
EPSS
0.9%
2024 CWE-444 1 PoC

Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by Next.js, leading to desynchronized responses. This led to a response queue poisoning vulnerability in the affected Next.js versions. For a request to be exploitable, the affected route also had to be making use of the [rewrites](https://nextjs.org/docs/app/api-reference/next-config-js/rewrites) feature in Next.js. The vulnerability is resolved in

CVE-2024-4558
Chrome General
7.5
HIGH
EPSS
2.4%
2024 4 PoCs

Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-45253
VideoIQ iCVR HD camera General
7.5
HIGH
EPSS
0.4%
2024 CWE-22 1 PoC

Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2024-47212
Software Genérico Web
7.5
HIGH
EPSS
0.4%
2024 1 PoC

An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu Server and can render it completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.

CVE-2024-8484
REST API TO MiniProgram Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
88.8%
2024 CWE-89 1 PoC

The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint in all versions up to, and including, 4.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-34665
Samsung Mobile Devices General
7.5
HIGH
EPSS
5.1%
2024 1 PoC

Out-of-bounds write in parsing h.264 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2024-8700
Event Calendar Web Windows
7.5
HIGH
EPSS
0.5%
2024 1 PoC

The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.

CVE-2024-49196
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 2 PoCs

An issue was discovered in the GPU in Samsung Mobile Processor Exynos 1480 and 2400. Type confusion leads to a Denial of Service.