7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-24458
HPE Athonet Core General
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

An invalid memory access when handling the ENB Configuration Transfer messages containing invalid PLMN Identities in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

CVE-2024-21528
node-gettext General
5.9
MEDIUM
EPSS
0.1%
2024 CWE-1321 1 PoC

All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.

CVE-2024-20854
Samsung Camera General
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper handling of insufficient privileges vulnerability in Samsung Camera prior to versions 12.1.0.31 in Android 12, 13.1.02.07 in Android 13, and 14.0.01.06 in Android 14 allows local attackers to access image data.

CVE-2024-46635
Software Genérico Web
5.9
MEDIUM
EPSS
1.0%
2024 1 PoC

An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber parameter.

CVE-2024-27142
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
5.9
MEDIUM
EPSS
0.1%
2024 CWE-776 1 PoC

Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable to a time-based blind XML External Entity (XXE) vulnerability. An attacker can DoS the printers. An attacker can exploit the XXE to retrieve information. As for the affected products/models/versions, see the reference URL.

CVE-2024-25053
Cognos Analytics General
5.9
MEDIUM
EPSS
0.1%
2024 CWE-295 1 PoC

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using the IBM Planning Analytics Data Source Connection. This could allow an attacker to spoof a trusted entity by interfering in the communication path between IBM Planning Analytics server and IBM Cognos Analytics server. IBM X-Force ID: 283364.

CVE-2024-10105
Job Postings Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-28145
Scan2Net Web Database
5.9
MEDIUM
EPSS
0.1%
2024 CWE-89 2 PoCs

An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.

CVE-2024-25848
Software Genérico Database
5.9
MEDIUM
EPSS
0.0%
2024 1 PoC

In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affected versions.

CVE-2024-34222
Software Genérico Database
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.

CVE-2024-40774
iOS and iPadOS General
5.9
MEDIUM
EPSS
0.0%
2024 3 PoCs

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.

CVE-2024-5626
Inline Related Posts Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Inline Related Posts WordPress plugin before 3.7.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVE-2024-2605
Firefox Web Windows
5.9
MEDIUM
EPSS
0.3%
2024 1 PoC

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVE-2024-5033
SULly Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-1905
Smart Forms Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The Smart Forms WordPress plugin before 2.6.96 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-6243
HTML Forms Web Windows
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privilege users, such as administrators, to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disabled.

CVE-2024-3472
Modal Window Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a logged in admin delete them via a CSRF attack

CVE-2024-10309
Tracking Code Manager Web Windows
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

The Tracking Code Manager WordPress plugin before 2.4.0 does not sanitise and escape some of its metabox settings when outputing them in the page, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.

CVE-2024-34678
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption.

CVE-2024-34586
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.