7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-6856
WP MultiTasking Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-44633
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Student Record System 3.20 is vulnerable to SQL Injection via the currentpassword parameter in change-password.php.

CVE-2024-33663
Software Genérico Networking
6.5
MEDIUM
EPSS
0.7%
2024 1 PoC

python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.

CVE-2024-52926
Privilege Manager Windows
6.5
MEDIUM
EPSS
0.0%
2024 CWE-269 1 PoC

Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.

CVE-2024-38434
Vision PLC General
6.5
MEDIUM
EPSS
0.1%
2024 CWE-676 1 PoC

Unitronics Vision PLC – CWE-676: Use of Potentially Dangerous Function may allow security feature bypass

CVE-2024-9391
Firefox General
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.

CVE-2024-2756
PHP Web
6.5
MEDIUM
EPSS
7.7%
2024 CWE-20 1 PoC

Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications.

CVE-2024-21089
Concurrent Processing Web Database
6.5
MEDIUM
EPSS
0.6%
2024 1 PoC

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: Request Submission and Scheduling). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Concurrent Processing accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N

CVE-2024-28418
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php

CVE-2024-27279
a-blog cms Ver.3.1.x series Web
6.5
MEDIUM
EPSS
1.6%
2024 1 PoC

Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series Ver.3.1.9 and earlier, Ver.3.0.x series Ver.3.0.30 and earlier, Ver.2.11.x series Ver.2.11.59 and earlier, Ver.2.10.x series Ver.2.10.51 and earlier, and Ver.2.9 and earlier versions. If this vulnerability is exploited, a user with editor or higher privilege who can login to the product may obtain arbitrary files on the server including password files.

CVE-2024-45589
Software Genérico Web Cloud
6.5
MEDIUM
EPSS
7.8%
2024 2 PoCs

RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters.

CVE-2024-33849
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.

CVE-2024-40395
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

An Insecure Direct Object Reference (IDOR) in PTC ThingWorx v9.5.0 allows attackers to view sensitive information, including PII, regardless of access level.

CVE-2024-55016
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Student Record Management System 3.20 is vulnerable to SQL Injection via the id and password parameters in login.php.

CVE-2024-7139
RS9116 Bluetooth SDK General
6.5
MEDIUM
EPSS
0.2%
2024 CWE-787 1 PoC

Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow triggers an assert, which results in a temporary denial of service.  If a watchdog timer is not enabled, a hard reset is required to recover the device.

CVE-2024-5570
Simple Photoswipe Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which could allow any authenticated users, such as subscriber to update them

CVE-2024-24443
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

An uninitialized pointer dereference in the ngap_handle_pdu_session_resource_setup_response routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDU Session Resource Setup Response.

CVE-2024-29197
pimcore General
6.5
MEDIUM
EPSS
0.0%
2024 CWE-200 1 PoC

Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true` allows to view unpublished sites. In previous versions of Pimcore, session information would propagate to previews, so only a logged in user could open a preview. This no longer applies. Previews are broad open to any user and with just the hint of a restricted link one could gain access to possible confident / unreleased information. This vulnerability is fixed in 11.2.2 and 11.1.6.1.

CVE-2024-1076
SSL Zen Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who doesn't support .htaccess files, like NGINX.

CVE-2024-56915
Software Genérico Web
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget.