7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-27383
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_get_scan_extra_ies(), there is no input validation check on default_ies coming from userspace, which can lead to a heap overwrite.

CVE-2024-39574
PowerScale InsightIQ General
6.7
MEDIUM
EPSS
0.0%
2024 CWE-269 1 PoC

Dell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service.

CVE-2024-28589
Software Genérico Windows
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbitrary code and escalate privileges via insecure DLL loading from a world-writable directory during service initialization.

CVE-2024-27375
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is no input validation check on hal_req->sdea_service_specific_info_len coming from userspace, which can lead to a heap overwrite.

CVE-2024-34638
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.

CVE-2024-49592
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

Trial installer for McAfee Total Protection (legacy trial installer software) 16.0.53 allows local privilege escalation because of an Uncontrolled Search Path Element. The attacker could be "an adversary or knowledgeable user" and the type of attack could be called "DLL-squatting." The issue only affects execution of this installer, and does not leave McAfee Total Protection in a vulnerable state after installation is completed. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2024-27372
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->infrastructure_ssid_len coming from userspace, which can lead to a heap overwrite.

CVE-2024-31953
Software Genérico General
6.7
MEDIUM
EPSS
0.2%
2024 1 PoC

An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)

CVE-2024-29975
NAS326 firmware Cloud
6.7
MEDIUM
EPSS
0.3%
2024 CWE-269 2 PoCs

** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated local attacker with administrator privileges to execute some system commands as the “root” user on a vulnerable device.

CVE-2024-27387
Software Genérico General
6.7
MEDIUM
EPSS
0.0%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_rx_range_done_ind(), there is no input validation check on rtt_id coming from userspace, which can lead to a heap overwrite.

CVE-2024-42642
Software Genérico General
6.7
MEDIUM
EPSS
1.5%
2024 1 PoC

Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states that this vulnerability was fully remediated in December 2024 and that updated firmware is available through Crucial’s official support page.

CVE-2024-49406
Blockchain Keystore General
6.7
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper validation of integrity check value in Blockchain Keystore prior to version 1.3.16 allows local attackers to modify transaction. Root privilege is required for triggering this vulnerability.

CVE-2024-27374
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_publish_get_nl_params(), there is no input validation check on hal_req->service_specific_info_len coming from userspace, which can lead to a heap overwrite.

CVE-2024-28283
Software Genérico Networking
6.7
MEDIUM
EPSS
0.5%
2024 1 PoC

There is stack-based buffer overflow vulnerability in pc_change_act function in Linksys E1000 router firmware version v.2.1.03 and before, leading to remote code execution.

CVE-2024-20863
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.

CVE-2024-21302
Windows 10 Version 1809 Cloud Windows
6.7
MEDIUM
EPSS
1.1%
2024 CWE-284 1 PoC

Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to protect your systems from this vulnerability. An elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machine SKUS. This vulnerability enables an attacker with administrator privileges to replace current versions of Windows system files wi

CVE-2024-27371
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is no input validation check on hal_req->service_specific_info_len coming from userspace, which can lead to a heap overwrite.

CVE-2024-31952
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)

CVE-2024-27377
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_get_security_info_nl(), there is no input validation check on sec_info->key_info.body.pmk_info.pmk_len coming from userspace, which can lead to a heap overwrite.

CVE-2024-27386
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 2 PoCs

A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for tx coming from userspace, which can lead to heap overwrite.