7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-12753
PDF Reader General
6.7
MEDIUM
EPSS
0.1%
2024 CWE-59 1 PoC

Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the product installer. By creating a junction, an attacker can abuse the installer process to create an arbitrary file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI

CVE-2024-20863
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.

CVE-2024-27376
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->rx_match_filter_len coming from userspace, which can lead to a heap overwrite.

CVE-2024-27146
Toshiba Tec e-Studio multi-function peripheral (MFP) General
6.7
MEDIUM
EPSS
0.1%
2024 CWE-250 1 PoC

The Toshiba printers do not implement privileges separation. As for the affected products/models/versions, see the reference URL.

CVE-2024-22026
EPMM General
6.7
MEDIUM
EPSS
0.2%
2024 1 PoC

A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.

CVE-2024-27460
Plantronics Hub General
6.7
MEDIUM
EPSS
2.5%
2024 3 PoCs

A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.

CVE-2024-10573
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 CWE-787 1 PoC

An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located buffer. Consequently, heap corruption may happen, and arbitrary code execution is not discarded. The complexity required to exploit this flaw is considered high as the payload must be validated by the MPEG decoder and the PCM synth before execution. Additionally, to successfully execute the attack, the user must scan through the stream, making web live stream content (such as web radios) a very unlikely attack vector.

CVE-2024-29975
NAS326 firmware Cloud
6.7
MEDIUM
EPSS
0.3%
2024 CWE-269 2 PoCs

** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel NAS326 firmware versions before V5.21(AAZF.17)C0 and NAS542 firmware versions before V5.21(ABAG.14)C0 could allow an authenticated local attacker with administrator privileges to execute some system commands as the “root” user on a vulnerable device.

CVE-2024-31804
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 2 PoCs

An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privileges via the Program.exe component.

CVE-2024-38433
NPCM7xx (Poleg) BootBlock General
6.7
MEDIUM
EPSS
0.0%
2024 CWE-305 1 PoC

Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code execution.

CVE-2024-27371
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is no input validation check on hal_req->service_specific_info_len coming from userspace, which can lead to a heap overwrite.

CVE-2024-34646
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.

CVE-2024-33895
Software Genérico Cloud
6.6
MEDIUM
EPSS
0.4%
2024 1 PoC

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device.

CVE-2024-20054
MT2735, MT2737, MT6762, MT6765, MT6769, MT6833, MT6835, MT6853, MT6855, MT6873, MT6875, MT6877, MT6879, MT6883, MT6885, MT6889, MT6890, MT6891, MT6893, MT6895, MT6983, MT6985, MT6989, MT6990, MT8168, MT8173, MT8195, MT8321, MT8385, MT8390, MT8666, MT8667, MT8673, MT8676, MT8678, MT8755, MT8765, MT8766, MT8768, MT8775, MT8781, MT8786, MT8788, MT8791T, MT8792, MT8796, MT8893 General
6.6
MEDIUM
EPSS
0.1%
2024 1 PoC

In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200.

CVE-2024-22724
Software Genérico General
6.6
MEDIUM
EPSS
0.0%
2024 1 PoC

An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.

CVE-2024-27282
Software Genérico General
6.6
MEDIUM
EPSS
0.6%
2024 1 PoC

An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.

CVE-2024-41958
mailcow-dockerized DevOps
6.6
MEDIUM
EPSS
30.3%
2024 CWE-697 1 PoC

mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the two-factor authentication (2FA) mechanism. This flaw allows an authenticated attacker to bypass the 2FA protection, enabling unauthorized access to other accounts that are otherwise secured with 2FA. To exploit this vulnerability, the attacker must first have access to an account within the system and possess the credentials of the target account that has 2FA enabled. By leveraging these credentials, the attacker can circumvent the 2FA process and gain access to the protected

CVE-2024-20818
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

CVE-2024-56264
ACF City Selector General
6.6
MEDIUM
EPSS
13.8%
2024 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Beee ACF City Selector acf-city-selector allows Upload a Web Shell to a Web Server.This issue affects ACF City Selector: from n/a through <= 1.14.0.