7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-47187
suricata General
7.5
HIGH
EPSS
0.1%
2024 CWE-330 1 PoC

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed for "thash" leads to datasets having predictable hash table behavior. This can lead to dataset file loading to use excessive time to load, as well as runtime performance issues during traffic handling. This issue has been addressed in 7.0.7. As a workaround, avoid loading datasets from untrusted sources. Avoid dataset rules that track traffic in rules.

CVE-2024-10400
Tutor LMS – eLearning and online course solution Web Database Windows ⚡ nuclei
7.5
HIGH
EPSS
93.2%
2024 CWE-89 1 PoC

The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-5334
stitionai/devika Web ⚡ nuclei
7.5
HIGH
EPSS
62.7%
2024 CWE-73 0 PoCs

A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerability is due to improper handling of the 'snapshot_path' parameter in the '/api/get-browser-snapshot' endpoint. An attacker can exploit this vulnerability by crafting a request with a malicious 'snapshot_path' parameter, leading to arbitrary file read from the system. This issue impacts the security of the application by allowing unauthorized access to sensitive files on the server.

CVE-2024-4469
WP STAGING WordPress Backup Plugin Web Windows
7.5
HIGH
EPSS
0.7%
2024 1 PoC

The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may be a problem in multisite configurations.

CVE-2024-21075
Trade Management Web Database
7.5
HIGH
EPSS
1.6%
2024 1 PoC

Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim Line LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trade Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2024-27316
Apache HTTP Server Web
7.5
HIGH
EPSS
89.4%
2024 CWE-770 3 PoCs

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.

CVE-2024-31964
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication control. A successful exploit could allow an attacker to modify system configuration settings and potentially cause a denial of service.

CVE-2024-51179
Software Genérico General
7.5
HIGH
EPSS
13.5%
2024 1 PoC

An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as the User Plane Function (UPF) and the Session Management Function (SMF), The Packet Data Unit (PDU) session establishment process.

CVE-2024-1483
mlflow/mlflow Web ⚡ nuclei
7.5
HIGH
EPSS
75.0%
2024 CWE-22 0 PoCs

A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on the server. By crafting a series of HTTP POST requests with specially crafted 'artifact_location' and 'source' parameters, using a local URI with '#' instead of '?', an attacker can traverse the server's directory structure. The issue occurs due to insufficient validation of user-supplied input in the server's handlers.

CVE-2024-23302
Software Genérico General
7.5
HIGH
EPSS
0.6%
2024 2 PoCs

Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.

CVE-2024-57452
Software Genérico Web
7.5
HIGH
EPSS
0.2%
2024 1 PoC

ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to delete any file and folder.

CVE-2024-10462
Firefox General
7.5
HIGH
EPSS
0.5%
2024 1 PoC

Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVE-2024-33214
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter in ip/goform/RouteStatic.

CVE-2024-6707
Open WebUI General
7.5
HIGH
EPSS
0.2%
2024 CWE-22 3 PoCs

Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.

CVE-2024-23261
macOS General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.8. An attacker may be able to read information belonging to another user.

CVE-2024-41594
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2024 1 PoC

An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL.

CVE-2024-4549
DIAEnergie General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.

CVE-2024-26026
BIG-IP Next Central Manager Web Database
7.5
HIGH
EPSS
89.4%
2024 CWE-89 2 PoCs

An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-11392
Transformers General
7.5
HIGH
EPSS
59.3%
2024 CWE-502 1 PoC

Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of configuration files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vul

CVE-2024-45432
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from an incorrect variable used as a function argument. An attacker can leverage this to cause unexpected behavior or obtain sensitive information.