7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-34653
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.

CVE-2024-6362
Ultimate Blocks Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

CVE-2024-34674
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.

CVE-2024-7394
Concrete CMS Web
4.6
MEDIUM
EPSS
3.9%
2024 CWE-79 1 PoC

Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue administrator could inject malicious code. The Concrete CMS team gave this a CVSS v4.0 rank of 4.6 with vector https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks, m3dium for reporting. (CNA updated this risk rank on 20 Jan 2025 by lowering the AC based on CVSS 4.0 documentation that access privileges should not be considered for AC)

CVE-2024-12247
Mattermost General
4.6
MEDIUM
EPSS
0.1%
2024 CWE-863 1 PoC

Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a user to keep old permissions, even if the permission scheme has been updated.

CVE-2024-13096
WP Finance Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The WP Finance WordPress plugin through 1.3.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-34639
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.

CVE-2024-40813
iOS and iPadOS General
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

A lock screen issue was addressed with improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data.

CVE-2024-20839
Samsung Voice Recorder General
4.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers to access recording files on the lock screen.

CVE-2024-34051
Software Genérico Web
4.6
MEDIUM
EPSS
1.0%
2024 1 PoC

A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.

CVE-2024-40818
iOS and iPadOS General
4.6
MEDIUM
EPSS
0.1%
2024 4 PoCs

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. An attacker with physical access may be able to use Siri to access sensitive user data.

CVE-2024-40635
containerd DevOps
4.6
MEDIUM
EPSS
0.1%
2024 CWE-190 1 PoC

containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can cause an overflow condition where the container ultimately runs as root (UID 0). This could cause unexpected behavior for environments that require containers to run as a non-root user. This bug has been fixed in containerd 1.6.38, 1.7.27, and 2.04. As a workaround, ensure that only trusted images are used and that only trusted users have permissions to import images.

CVE-2024-25412
Software Genérico Web
4.6
MEDIUM
EPSS
32.5%
2024 1 PoC

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email field.

CVE-2024-49402
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles.

CVE-2024-3993
AZAN Plugin Web Windows
4.6
MEDIUM
EPSS
0.2%
2024 1 PoC

The AZAN Plugin WordPress plugin through 0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-20882
Samsung Mobile Devices General
4.6
MEDIUM
EPSS
0.3%
2024 1 PoC

Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.

CVE-2024-24857
Linux kernel General
4.6
MEDIUM
EPSS
0.0%
2024 CWE-362 1 PoC

A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to bluetooth connection abnormality or denial of service.

CVE-2024-24859
Linux kernel General
4.6
MEDIUM
EPSS
0.0%
2024 CWE-362 1 PoC

A race condition was found in the Linux kernel's net/bluetooth in sniff_{min,max}_interval_set() function. This can result in a bluetooth sniffing exception issue, possibly leading denial of service.

CVE-2024-3843
Chrome General
4.6
MEDIUM
EPSS
0.7%
2024 1 PoC

Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-24858
Linux kernel General
4.6
MEDIUM
EPSS
0.0%
2024 CWE-362 1 PoC

A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading to denial of service.