7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-6856
WP MultiTasking Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-12196
Server General
6.5
MEDIUM
EPSS
0.2%
2024 CWE-863 1 PoC

Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password history of an entry without the view password permission.

CVE-2024-52917
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., large M-SEARCH replies from a fake UPnP device.

CVE-2024-10631
Countdown Timer for WordPress Block Editor Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVE-2024-38434
Vision PLC General
6.5
MEDIUM
EPSS
0.1%
2024 CWE-676 1 PoC

Unitronics Vision PLC – CWE-676: Use of Potentially Dangerous Function may allow security feature bypass

CVE-2024-48272
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers to connect to the device via a bruteforce attack.

CVE-2024-3839
Chrome General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Out of bounds read in Fonts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-57488
Software Genérico Web
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter in /admin/edit-vehicle.php.

CVE-2024-51317
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function

CVE-2024-1747
WooCommerce Customers Manager Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticated users, such as subscriber, to call them and update/delete/create customer metadata, also leading to Stored Cross-Site Scripting due to the lack of escaping of said metadata values.

CVE-2024-6133
wp-cart-for-digital-products Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-27878
macOS General
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code with kernel privileges.

CVE-2024-37605
Software Genérico Web
6.5
MEDIUM
EPSS
0.2%
2024 2 PoCs

A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

CVE-2024-57725
Software Genérico General
6.5
MEDIUM
EPSS
15.0%
2024 1 PoC

An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value without authentication, causing an internet service disruption via the /firstconnection.cgi endpoint.

CVE-2024-56340
Cognos Analytics General
6.5
MEDIUM
EPSS
12.2%
2024 CWE-23 2 PoCs

IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker to access sensitive files by inserting path traversal payloads inside the deficon parameter.

CVE-2024-21205
Oracle Service Bus Web Database
6.5
MEDIUM
EPSS
0.6%
2024 1 PoC

Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Core Functionality). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Bus. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Service Bus accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).

CVE-2024-0559
Enhanced Text Widget Web Windows
6.5
MEDIUM
EPSS
0.3%
2024 2 PoCs

The Enhanced Text Widget WordPress plugin before 1.6.6 does not validate and escape some of its Widget options before outputting them back in attributes, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-46978
xwiki-platform General
6.5
MEDIUM
EPSS
0.5%
2024 CWE-648 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible for any user knowing the ID of a notification filter preference of another user, to enable/disable it or even delete it. The impact is that the target user might start loosing notifications on some pages because of this. This vulnerability is present in XWiki since 13.2-rc-1. This vulnerability has been patched in XWiki 14.10.21, 15.5.5, 15.10.1, 16.0-rc-1. The patch consists in checking properly the rights of the user before performing any action on the filters. Users are adv

CVE-2024-49197
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 2 PoCs

An issue was discovered in Wi-Fi in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, W920, W930, and W1000. Lack of a boundary check in STOP_KEEP_ALIVE_OFFLOAD leads to out-of-bounds access.

CVE-2024-56114
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit templates from their account.