7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-34673
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service.

CVE-2024-0134
NVIDIA Container Toolkit DevOps
4.1
MEDIUM
EPSS
0.2%
2024 CWE-61 1 PoC

NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to data tampering.

CVE-2024-52935
Graphics DDK General
4.1
MEDIUM
EPSS
0.1%
2024 CWE-823 1 PoC

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

CVE-2024-20833
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.0%
2024 1 PoC

Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption.

CVE-2024-10009
Melapress File Monitor Web Database Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-10638
Product Labels For Woocommerce (Sale Badges) Web Database Windows
4.1
MEDIUM
EPSS
0.1%
2024 1 PoC

The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks

CVE-2024-42906
Software Genérico Web
4.1
MEDIUM
EPSS
0.1%
2024 1 PoC

TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file. When uploading a file, the XSS payload can be entered into the file name.

CVE-2024-31843
Software Genérico General
4.1
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are processed on the server side. This allows authenticated users to execute commands on the Operating System.

CVE-2024-9689
Post From Frontend Web Windows
4.1
MEDIUM
EPSS
0.2%
2024 1 PoC

The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow attackers to make logged in admin perform such action via a CSRF attack

CVE-2024-34652
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

CVE-2024-57822
Raptor RDF Syntax Library General
4.0
MEDIUM
EPSS
0.0%
2024 CWE-125 1 PoC

In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().

CVE-2024-20804
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.

CVE-2024-20898
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

CVE-2024-34599
Tips General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper input validation in Tips prior to version 6.2.9.4 in Android 14 allows local attacker to send broadcast with Tips' privilege.

CVE-2024-20897
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

CVE-2024-36062
Software Genérico General
4.0
MEDIUM
EPSS
0.0%
2024 1 PoC

The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.callassistant.android.ui.call.incall.InCallActivity component.

CVE-2024-34618
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.

CVE-2024-33883
Software Genérico Web
4.0
MEDIUM
EPSS
1.3%
2024 1 PoC

The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.

CVE-2024-4755
Google CSE Web Windows
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

The Google CSE WordPress plugin through 1.0.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-20899
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.