7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-29421
Software Genérico General
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

xmedcon 0.23.0 and fixed in v.0.24.0 is vulnerable to Buffer Overflow via libs/dicom/basic.c which allows an attacker to execute arbitrary code.

CVE-2024-35137
Security Verify Access Docker DevOps
6.2
MEDIUM
EPSS
0.0%
2024 CWE-258 2 PoCs

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileges due to sensitive configuration information being exposed. IBM X-Force ID: 292413.

CVE-2024-31957
Software Genérico General
6.2
MEDIUM
EPSS
0.3%
2024 2 PoCs

A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which can result in a DoS(Denial of Service) attack by unmapping an invalid length.

CVE-2024-45184
Software Genérico General
6.2
MEDIUM
EPSS
0.1%
2024 2 PoCs

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with chipset Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, and Modem 5300. A USAT out-of-bounds write due to a heap buffer overflow can lead to a Denial of Service.

CVE-2024-34608
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

CVE-2024-27154
Toshiba Tec e-Studio multi-function peripheral (MFP) General
6.2
MEDIUM
EPSS
0.1%
2024 CWE-532 1 PoC

Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/versions, see the reference URL.

CVE-2024-26329
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2024 1 PoC

Chilkat before v9.5.0.98, allows attackers to obtain sensitive information via predictable PRNG in ChilkatRand::randomBytes function.

CVE-2024-27159
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
6.2
MEDIUM
EPSS
0.0%
2024 CWE-798 2 PoCs

All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the hardcoded key. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.

CVE-2024-40833
iOS and iPadOS General
6.2
MEDIUM
EPSS
0.0%
2024 3 PoCs

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A shortcut may be able to use sensitive data with certain actions without prompting the user.

CVE-2024-34662
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 allows local attackers to execute privileged behaviors.

CVE-2024-34651
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.

CVE-2024-20048
MT2713, MT6781, MT6789, MT6835, MT6855, MT6879, MT6886, MT6895, MT6983, MT6985, MT6989, MT8167, MT8168, MT8173, MT8175, MT8188, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8390, MT8395, MT8666, MT8667, MT8673, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8796, MT8797, MT8798 General
6.2
MEDIUM
EPSS
0.0%
2024 1 PoC

In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541769; Issue ID: ALPS08541769.

CVE-2024-40540
Software Genérico Web Database
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/dept.

CVE-2024-34637
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on starting services from the background.

CVE-2024-35139
Security Verify Access Docker DevOps
6.2
MEDIUM
EPSS
0.0%
2024 CWE-276 2 PoCs

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from the container due to incorrect default permissions. IBM X-Force ID: 292415.

CVE-2024-40541
Software Genérico Web Database
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/dept/build.

CVE-2024-27160
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
6.2
MEDIUM
EPSS
0.1%
2024 CWE-798 2 PoCs

All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the hardcoded key. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.

CVE-2024-40539
Software Genérico Web Database
6.2
MEDIUM
EPSS
0.1%
2024 1 PoC

my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /api/user.

CVE-2024-37656
Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
0.1%
2024 0 PoCs

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter verification in bbs/logout.php.

CVE-2024-13328
Giga Messenger Web Windows ⚡ nuclei
6.1
MEDIUM
EPSS
2.3%
2024 1 PoC

The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin