7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-31846
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2024-55568
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The absence of a NULL check leads to a Denial of Service when an attacker sends malformed MM packets to the target.

CVE-2024-28757
Software Genérico General
7.5
HIGH
EPSS
1.2%
2024 3 PoCs

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

CVE-2024-30569
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
28.6%
2024 1 PoC

An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.

CVE-2024-53605
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS v10.9.9.7 allows attackers to access sensitive data.

CVE-2024-34619
Samsung Mobile Devices General
7.5
HIGH
EPSS
1.5%
2024 1 PoC

Improper input validation in librtp.so prior to SMR Aug-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2024-0801
Unified Data Protection General ⚡ nuclei
7.5
HIGH
EPSS
49.2%
2024 1 PoC

A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.

CVE-2024-6291
Chrome General
7.5
HIGH
EPSS
0.3%
2024 CWE-416 1 PoC

Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-4437
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2024 CWE-400 1 PoC

The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2021-44716. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux versions, meaning it should be updated at compile time instead.

CVE-2024-24792
golang.org/x/image/tiff General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

Parsing a corrupt or malicious image with invalid color indices can cause a panic.

CVE-2024-34667
Samsung Mobile Devices General
7.5
HIGH
EPSS
5.1%
2024 1 PoC

Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2024-42861
Software Genérico General
7.5
HIGH
EPSS
31.9%
2024 1 PoC

An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function

CVE-2024-3848
mlflow/mlflow Networking Cloud ⚡ nuclei
7.5
HIGH
EPSS
78.7%
2024 CWE-29 0 PoCs

A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the application's handling of artifact URLs, where a '#' character can be used to insert a path into the fragment, effectively skipping validation. This allows an attacker to construct a URL that, when processed, ignores the protocol scheme and uses the provided path for filesystem access. As a result, an attacker can read arbitrary files, including sensitive information such as SSH and cloud keys, by exploiting the way the appl

CVE-2024-11423
Gift Cards for WooCommerce Pro Web Windows
7.5
HIGH
EPSS
20.7%
2024 CWE-862 1 PoC

The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, and Use Advance Coupons With Personalized Templates plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several REST API endpoints such as /wp-json/gifting/recharge-giftcard in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to recharge a gift card balance, without making a payment along with reducing gift card balances wi

CVE-2024-13481
LTL Freight Quotes – R+L Carriers Edition Web Database Windows
7.5
HIGH
EPSS
14.8%
2024 CWE-89 1 PoC

The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropship_edit_id' parameters in all versions up to, and including, 3.3.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-36254
Multiple MFPs (multifunction printers) General
7.5
HIGH
EPSS
0.2%
2024 CWE-125 1 PoC

Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition.

CVE-2024-9399
Firefox General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

CVE-2024-32736
CyberPower PowerPanel Enterprise Database ⚡ nuclei
7.5
HIGH
EPSS
69.1%
2024 1 PoC

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper.

CVE-2024-12849
Error Log Viewer By WP Guru Web Windows ⚡ nuclei
7.5
HIGH
EPSS
93.0%
2024 CWE-22 2 PoCs

The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1.3 via the wp_ajax_nopriv_elvwp_log_download AJAX action. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVE-2024-51163
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

A Local File Inclusion vulnerability in Vegam Solutions Vegam 4i versions 6.3.47.0 and earlier allows a remote attacker to obtain sensitive information through the print label function. Specifically, the filePathList parameter is susceptible to LFI, enabling a malicious user to include files from the web server, such as web.config or /etc/host, leading to the disclosure of sensitive information.