7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-47522
suricata General
7.5
HIGH
EPSS
0.3%
2024 CWE-617 2 PoCs

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, invalid ALPN in TLS/QUIC traffic when JA4 matching/logging is enabled can lead to Suricata aborting with a panic. This issue has been addressed in 7.0.7. One may disable ja4 as a workaround.

CVE-2024-56889
Software Genérico Web
7.5
HIGH
EPSS
3.4%
2024 2 PoCs

Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrarily delete complaints via modification of the id parameter.

CVE-2024-22871
Software Genérico General
7.5
HIGH
EPSS
0.7%
2024 2 PoCs

An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function.

CVE-2024-12157
Popup – MailChimp, GetResponse and ActiveCampaign Intergrations Web Database Windows
7.5
HIGH
EPSS
10.2%
2024 CWE-89 1 PoC

The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'upc_delete_db_record' AJAX action in all versions up to, and including, 3.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-33605
Multiple MFPs (multifunction printers) General ⚡ nuclei
7.5
HIGH
EPSS
60.2%
2024 CWE-22 3 PoCs

Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-24419
Software Genérico Networking
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_traffic_flow_template_packet_filter function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

CVE-2024-21526
speaker General
7.5
HIGH
EPSS
0.1%
2024 CWE-400 1 PoC

All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to the channels property of the Speaker object makes it possible to reach an assert macro. Exploiting this vulnerability can lead to a process crash.

CVE-2024-10462
Firefox General
7.5
HIGH
EPSS
0.5%
2024 1 PoC

Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVE-2024-56527
tcpdf General
7.5
HIGH
EPSS
0.5%
2024 CWE-79 1 PoC

An issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.

CVE-2024-45241
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
90.8%
2024 2 PoCs

A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information.

CVE-2024-41695
PineApp Mail Relay General
7.5
HIGH
EPSS
0.7%
2024 CWE-22 1 PoC

Cybonet - CWE-22: Improper Limitation of a Pathname to a Restricted Directory

CVE-2024-33530
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the disclosure of the meeting password when a user is invited to a call after waiting in the lobby.

CVE-2024-32739
CyberPower PowerPanel Enterprise Database ⚡ nuclei
7.5
HIGH
EPSS
59.0%
2024 1 PoC

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_verbose" function within MCUDBHelper.

CVE-2024-50945
Software Genérico General
7.5
HIGH
EPSS
5.0%
2024 1 PoC

An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, allowing users to submit reviews without verifying if they have purchased the product.

CVE-2024-39206
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials used in a backup due to enginesettings.list being encrypted with a hard coded key.

CVE-2024-24417
Software Genérico Networking
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_protocol_configuration_options function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

CVE-2024-12274
Appointment Booking Calendar Plugin and Scheduling Plugin Web Windows
7.5
HIGH
EPSS
0.5%
2024 1 PoC

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessable file name, allowing unauthenticated attackers to access the exported files (if they exist).

CVE-2024-12172
WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses Web Windows
7.5
HIGH
EPSS
11.2%
2024 CWE-862 1 PoC

The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpc_update_user_meta_option() function in all versions up to, and including, 3.2.21. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary user's metadata which can be levereged to block an administrator from accessing their site when wp_capabilities is set to 0.

CVE-2024-28854
tls-listener General
7.5
HIGH
EPSS
0.2%
2024 CWE-400 1 PoC

tls-listener is a rust lang wrapper around a connection listener to support TLS. With the default configuration of tls-listener, a malicious user can open 6.4 `TcpStream`s a second, sending 0 bytes, and can trigger a DoS. The default configuration options make any public service using `TlsListener::new()` vulnerable to a slow-loris DoS attack. This impacts any publicly accessible service using the default configuration of tls-listener in versions prior to 0.10.0. Users are advised to upgrade. Users unable to upgrade may mitigate this by passing a large value, such as `usize::MAX` as the parame

CVE-2024-36823
Software Genérico General
7.5
HIGH
EPSS
11.8%
2024 1 PoC

The encrypt() function of Ninja Core v7.0.0 was discovered to use a weak cryptographic algorithm, leading to a possible leakage of sensitive information.