7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-55457
Software Genérico General ⚡ nuclei
6.5
MEDIUM
EPSS
80.4%
2024 1 PoC

MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit this vulnerability by manipulating the file parameter to access arbitrary files on the server, potentially exposing sensitive information.

CVE-2024-28275
Software Genérico Cloud
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Puwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was discovered to transmit sensitive information in cleartext. This vulnerability allows attackers to intercept and access sensitive information, including users' credentials and password change requests.

CVE-2024-5071
Bookster Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing attackers to manipulate the data sent when booking an appointment (the request body) to change its status from pending to approved.

CVE-2024-25742
Software Genérico General
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and can trigger its handler. This affects AMD SEV-SNP and AMD SEV-ES.

CVE-2024-25506
Software Genérico General
6.5
MEDIUM
EPSS
0.6%
2024 1 PoC

Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control of the pm_sys_sys cookie.

CVE-2024-48293
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level privileges to arbitrarily modify antivirus settings.

CVE-2024-42648
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

NanoMQ v0.22.10 was discovered to contain a heap overflow which allows attackers to cause a Denial of Service (DoS) via a crafted CONNECT message.

CVE-2024-21230
MySQL Cluster Database
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2024-4210
GitLab DevOps
6.5
MEDIUM
EPSS
0.1%
2024 CWE-400 1 PoC

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. It is possible for an attacker to cause a denial of service using crafted adoc files.

CVE-2024-0741
Firefox General
6.5
MEDIUM
EPSS
47.3%
2024 2 PoCs

An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

CVE-2024-9450
Free Booking Plugin for Hotels, Restaurants and Car Rentals Web Windows
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack

CVE-2024-1669
Chrome General
6.5
MEDIUM
EPSS
0.3%
2024 1 PoC

Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2024-0078
GPU Display driver, vGPU driver, Cloud Gaming driver Cloud Windows
6.5
MEDIUM
EPSS
0.0%
2024 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user in a guest can cause a NULL-pointer dereference in the host, which may lead to denial of service.

CVE-2024-43278
Meta Field Block Web
6.5
MEDIUM
EPSS
0.2%
2024 CWE-79 1 PoC

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Phi Phan Meta Field Block allows Stored XSS.This issue affects Meta Field Block: from n/a through 1.2.13.

CVE-2024-23525
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2024 2 PoCs

The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.

CVE-2024-39601
CPCI85 Central Processing/Communication General
6.5
MEDIUM
EPSS
0.4%
2024 CWE-306 1 PoC

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). Affected devices allow a remote authenticated user or an unauthenticated user with physical access to downgrade the firmware of the device. This could allow an attacker to downgrade the device to older versions with known vulnerabilities.

CVE-2024-57972
HoloLens Web Windows
6.5
MEDIUM
EPSS
1.9%
2024 CWE-770 1 PoC

The pairing API request handler in Microsoft HoloLens 1 (Windows Holographic) through 10.0.17763.3046 and HoloLens 2 (Windows Holographic) through 10.0.22621.1244 allows remote attackers to cause a Denial of Service (resource consumption and device unusability) by sending many requests through the Device Portal framework.

CVE-2024-48450
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

An arbitrary file upload vulnerability in Huly Platform v0.6.295 allows attackers to execute arbitrary code via uploading a crafted HTML file into chat group.

CVE-2024-44663
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.

CVE-2024-42649
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

NanoMQ v0.22.10 was discovered to contain a memory leak which allows attackers to cause a Denial of Service (DoS) via a crafted PUBLISH message.