7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-42011
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.

CVE-2024-47213
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to the pipeline. Upon receiving this event and trying to validate it, Enrich crashes and attempts to restart indefinitely. As a result, event processing would be halted.

CVE-2024-9631
GitLab DevOps
7.5
HIGH
EPSS
0.1%
2024 CWE-407 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.

CVE-2024-7713
AI ChatBot with ChatGPT and Content Generator by AYS Web Windows
7.5
HIGH
EPSS
0.4%
2024 1 PoC

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it

CVE-2024-45248
Multi-DNC General
7.5
HIGH
EPSS
0.3%
2024 CWE-35 1 PoC

Multi-DNC – CWE-35: Path Traversal: '.../...//'

CVE-2024-41628
Software Genérico Web ⚡ nuclei
7.5
HIGH
EPSS
91.5%
2024 1 PoC

Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API.

CVE-2024-5882
Ultimate Classified Listings Web Windows
7.5
HIGH
EPSS
2.3%
2024 1 PoC

The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page

CVE-2024-30569
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
28.6%
2024 1 PoC

An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.

CVE-2024-33818
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.

CVE-2024-13184
The Ultimate WordPress Toolkit – WP Extended Web Database Windows
7.5
HIGH
EPSS
0.9%
2024 CWE-89 1 PoC

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to time-based SQL Injection via the Login Attempts module in all versions up to, and including, 3.0.12 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-54767
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
7.0%
2024 0 PoCs

An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sensitive information without authentication. NOTE: this is disputed by the Supplier because it cannot be reproduced, and the issue report focuses on an unintended configuration with direct Internet exposure.

CVE-2024-26477
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2024 1 PoC

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the api parameter of the oauth, amazon_sns, export endpoints.

CVE-2024-46609
Software Genérico Web
7.5
HIGH
EPSS
0.3%
2024 1 PoC

An access control issue in the CheckVip function in UserController.java of IceCMS v3.4.7 and before allows unauthenticated attackers to access and returns all user information, including passwords

CVE-2024-47916
Boa web server 0.94.14rc21 General
7.5
HIGH
EPSS
0.4%
2024 CWE-22 1 PoC

Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2024-56528
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). It involves sending very large payloads to the Collector and can render it unresponsive to the rest of the requests. As a result, data would not enter the pipeline and would be potentially lost.

CVE-2024-2449
LoadMaster Web
7.5
HIGH
EPSS
3.3%
2024 CWE-352 1 PoC

A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a scenario, the CSRF payload hosted on the malicious site would execute HTTP transactions on behalf of the LoadMaster administrator.

CVE-2024-4340
Software Genérico Database
7.5
HIGH
EPSS
12.4%
2024 CWE-674 1 PoC

Passing a heavily nested list to sqlparse.parse() leads to a Denial of Service due to RecursionError.

CVE-2024-27170
Toshiba Tec e-Studio multi-function peripheral (MFP) General
7.4
HIGH
EPSS
0.1%
2024 CWE-798 1 PoC

It was observed that all the Toshiba printers contain credentials used for WebDAV access in the readable file. Then, it is possible to get a full access with WebDAV to the printer. As for the affected products/models/versions, see the reference URL.

CVE-2024-44779
Software Genérico Web
7.4
HIGH
EPSS
2.2%
2024 1 PoC

A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

CVE-2024-31320
Android General
7.4
HIGH
EPSS
0.7%
2024 1 PoC

In setSkipPrompt of AssociationRequest.java , there is a possible way to establish a companion device association without any confirmation due to CDM. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.