7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-27161
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
6.2
MEDIUM
EPSS
0.1%
2024 CWE-798 2 PoCs

all the Toshiba printers have programs containing a hardcoded key used to encrypt files. An attacker can decrypt the encrypted files using the hardcoded key. Insecure algorithm is used for the encryption. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/mo

CVE-2024-22734
Software Genérico General
6.2
MEDIUM
EPSS
3.4%
2024 2 PoCs

An issue was discovered in AMCS Group Trux Waste Management Software before version 7.19.0018.26912, allows local attackers to obtain sensitive information via a static, hard-coded AES Key-IV pair in the TxUtilities.dll and TruxUser.cfg components.

CVE-2024-34606
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

CVE-2024-34609
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

CVE-2024-20886
Samsung Live Wallpaper PC General
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

Arbitrary directory creation in Samsung Live Wallpaper PC prior to version 3.3.8.0 allows attacker to create arbitrary directory.

CVE-2024-34654
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.

CVE-2024-25027
Security Verify Access Docker DevOps
6.2
MEDIUM
EPSS
0.0%
2024 CWE-311 1 PoC

IBM Security Verify Access 10.0.6 could disclose sensitive snapshot information due to missing encryption. IBM X-Force ID: 281607.

CVE-2024-20887
GalaxyBudsManager PC General
6.2
MEDIUM
EPSS
0.6%
2024 1 PoC

Arbitrary directory creation in GalaxyBudsManager PC prior to version 2.1.240315.51 allows attacker to create arbitrary directory.

CVE-2024-30270
mailcow-dockerized DevOps
6.2
MEDIUM
EPSS
48.8%
2024 CWE-22 2 PoCs

mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identified in mailcow affecting versions prior to 2024-04. This vulnerability is a combination of path traversal and arbitrary code execution, specifically targeting the `rspamd_maps()` function. It allows authenticated admin users to overwrite any file writable by the www-data user by exploiting improper path validation. The exploit chain can lead to the execution of arbitrary commands on the server. Version 2024-04 contains a patch for the issue.

CVE-2024-20850
Samsung Pay General
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

Use of Implicit Intent for Sensitive Communication in Samsung Pay prior to version 5.4.99 allows local attackers to access information of Samsung Pay.

CVE-2024-34604
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

CVE-2024-34655
Samsung Mobile Devices Web
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.

CVE-2024-40788
iOS and iPadOS General
6.2
MEDIUM
EPSS
0.0%
2024 4 PoCs

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. A local attacker may be able to cause unexpected system shutdown.

CVE-2024-20872
TalkbackSE General
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.

CVE-2024-20884
Samsung Mobile Devices Web
6.2
MEDIUM
EPSS
0.2%
2024 1 PoC

Incorrect use of privileged API vulnerability in getSemBatteryUsageStats in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.

CVE-2024-27154
Toshiba Tec e-Studio multi-function peripheral (MFP) General
6.2
MEDIUM
EPSS
0.1%
2024 CWE-532 1 PoC

Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/versions, see the reference URL.

CVE-2024-1014
E-DDC3.3 General
6.2
MEDIUM
EPSS
0.1%
2024 CWE-400 1 PoC

Uncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could interrupt the availability of the administration panel by sending multiple ICMP packets.

CVE-2024-34607
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

CVE-2024-34605
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

CVE-2024-35137
Security Verify Access Docker DevOps
6.2
MEDIUM
EPSS
0.0%
2024 CWE-258 2 PoCs

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 292413.