7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-22526
Software Genérico General
5.5
MEDIUM
EPSS
1.3%
2024 1 PoC

Buffer Overflow vulnerability in bandisoft bandiview v7.0, allows local attackers to cause a denial of service (DoS) via exr image file.

CVE-2024-27863
iOS and iPadOS General
5.5
MEDIUM
EPSS
0.0%
2024 2 PoCs

An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. A local attacker may be able to determine kernel memory layout.

CVE-2024-5285
wp-affiliate-platform Web Windows
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack

CVE-2024-34621
Samsung Notes General
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-bounds read in applying binary with data in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

CVE-2024-22368
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2024 3 PoCs

The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX document. This occurs because the memoize implementation does not have appropriate constraints on merged cells.

CVE-2024-0092
GPU display driver, vGPU software, and Cloud Gaming Cloud Windows
5.5
MEDIUM
EPSS
0.1%
2024 CWE-703 1 PoC

NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of service.

CVE-2024-20859
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege.

CVE-2024-0911
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2024 CWE-122 1 PoC

A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a specially crafted file to trigger a heap-based buffer overflow, causing the application to crash.

CVE-2024-1900
Server General
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticated user via an identity provider to stay authenticated after his user is disabled or deleted in the identity provider such as Okta or Microsoft O365. The user will stay authenticated until the Devolutions Server token expiration.

CVE-2024-0344
TimeMail Web Database
5.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in soxft TimeMail up to 1.1. Affected by this issue is some unknown functionality of the file check.php. The manipulation of the argument c leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250112.

CVE-2024-0313
Skyhigh Client Proxy General
5.5
MEDIUM
EPSS
0.0%
2024 CWE-670 1 PoC

A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organization. On the contrary, if the victim is legitimately using the temporary bypass to reach out to the Internet for retrieving application and system updates, a remote device could target it and undo the bypass, thereby denying the victim access to the update service, causing it to fail.

CVE-2024-0466
Employee Profile Management System Web Database
5.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the file file_table.php. The manipulation of the argument per_id leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250571.

CVE-2024-20826
UPHelper General
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Implicit intent hijacking vulnerability in UPHelper library prior to version 4.0.0 allows local attackers to access sensitive information via implicit intent.

CVE-2024-0094
vGPU software and Cloud Gaming Cloud
5.5
MEDIUM
EPSS
0.0%
2024 CWE-799 1 PoC

NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where an untrusted guest VM can cause improper control of the interaction frequency in the host. A successful exploit of this vulnerability might lead to denial of service.

CVE-2024-54471
macOS General
5.5
MEDIUM
EPSS
0.1%
2024 2 PoCs

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may be able to leak a user's credentials.

CVE-2024-49532
Acrobat Reader General
5.5
MEDIUM
EPSS
0.0%
2024 CWE-125 1 PoC

Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2024-40779
Safari General
5.5
MEDIUM
EPSS
0.0%
2024 4 PoCs

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.

CVE-2024-7421
Remote Desktop Manager Windows
5.5
MEDIUM
EPSS
0.1%
2024 CWE-532 1 PoC

An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions

CVE-2024-0684
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2024 CWE-122 1 PoC

A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.

CVE-2024-22105
Software Genérico Windows
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error.