7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-21507
mysql2 Database
6.5
MEDIUM
EPSS
0.4%
2024 CWE-20 1 PoC

Versions of the package mysql2 before 3.9.3 are vulnerable to Improper Input Validation through the keyFromFields function, resulting in cache poisoning. An attacker can inject a colon (:) character within a value of the attacker-crafted key.

CVE-2024-7859
Visual Sound Web Windows
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-37363
Pentaho Data Integration & Analytics General
6.5
MEDIUM
EPSS
0.2%
2024 CWE-862 1 PoC

The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (CWE-862)  Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, do not correctly perform an authorization check in the data source management service. When access control checks are incorrectly applied, users can access data or perform actions that they should not be allowed to perform. This can lead to a wide range of problems, including information exposures and denial of service.

CVE-2024-28323
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.1%
2024 2 PoCs

The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a potential security vulnerability related to user input validation. The script retrieves user-provided date inputs without proper validation, making it susceptible to SQL injection attacks.

CVE-2024-21106
VM VirtualBox Database
6.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM Virt

CVE-2024-1287
pmpro-member-directory Web Database Windows
6.5
MEDIUM
EPSS
0.7%
2024 1 PoC

The pmpro-member-directory WordPress plugin before 1.2.6 does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector.

CVE-2024-54682
Mattermost General
6.5
MEDIUM
EPSS
0.2%
2024 CWE-409 1 PoC

Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size for slack import file uploads which allows a user to cause a DoS via zip bomb by importing data in a team they are a team admin.

CVE-2024-3959
GitLab DevOps
6.5
MEDIUM
EPSS
0.0%
2024 CWE-285 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows private job artifacts can be accessed by any user.

CVE-2024-57677
Software Genérico General
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

An access control issue in the component form2Wan.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the wan service of the device via a crafted POST request.

CVE-2024-2231
Himer General
6.5
MEDIUM
EPSS
0.5%
2024 1 PoC

The allows any authenticated user to join a private group due to a missing authorization check on a function

CVE-2024-48120
Software Genérico Web
6.5
MEDIUM
EPSS
2.6%
2024 1 PoC

X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject malicious JavaScript code into the "Name" field when creating a list.

CVE-2024-38030
Windows 10 Version 1809 Windows
6.5
MEDIUM
EPSS
67.5%
2024 CWE-200 2 PoCs

Windows Themes Spoofing Vulnerability

CVE-2024-7138
RS9116 Bluetooth SDK General
6.5
MEDIUM
EPSS
0.1%
2024 CWE-617 1 PoC

An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed L2CAP packet. If a watchdog timer is not enabled, a hard reset is required to recover the device.

CVE-2024-34946
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.

CVE-2024-23829
aiohttp Web
6.5
MEDIUM
EPSS
0.5%
2024 CWE-444 1 PoC

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input. Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling. The unhandled except

CVE-2024-50972
Software Genérico Web Database
6.5
MEDIUM
EPSS
4.8%
2024 1 PoC

A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.

CVE-2024-21104
Sun ZFS Storage Appliance Kit (AK) Software Database
6.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS Storage Appliance Kit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 6.5 (Confidentiality, Integrity and Availability imp

CVE-2024-57494
Software Genérico Web
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Cross Site Scripting vulnerability in Neto E-Commerce CMS v.6.313.0 through v.6.3115 allows a remote attacker to escalate privileges via the kw parameter.

CVE-2024-44651
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php.

CVE-2024-44641
Software Genérico Web Database
6.5
MEDIUM
EPSS
0.0%
2024 1 PoC

PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.