7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-20899
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

CVE-2024-36795
Software Genérico General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.

CVE-2024-25260
Software Genérico General
4.0
MEDIUM
EPSS
0.0%
2024 1 PoC

elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.

CVE-2024-34632
Samsung Notes General
4.0
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

CVE-2024-34617
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.

CVE-2024-5473
Simple Photoswipe Web Windows
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

The Simple Photoswipe WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-34583
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.

CVE-2024-34670
Sound Assistant General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to get sensitive information.

CVE-2024-34677
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.

CVE-2024-34650
Samsung Mobile Devices Web
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.

CVE-2024-20875
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows local attackers to access arbitrary files.

CVE-2024-45989
Software Genérico General
4.0
MEDIUM
EPSS
0.0%
2024 1 PoC

Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injection allows an attacker to modify chatbot answer with an unloaded image that exfiltrates the user's sensitive chat data of the current session to a malicious third-party or attacker-controlled server.

CVE-2024-20858
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.

CVE-2024-34635
Samsung Notes General
4.0
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

CVE-2024-4841
parisneo/lollms-webui Web ⚡ nuclei
4.0
MEDIUM
EPSS
8.5%
2024 CWE-29 0 PoCs

A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 to the latest. By exploiting this vulnerability, an attacker can predict the folders, subfolders, and files present on the victim's computer. The vulnerability is present in the way the application handles the 'path' parameter in HTTP requests to the '/add_reference_to_local_model' endpoint.

CVE-2024-20809
Nearby device scanning General
4.0
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.

CVE-2024-34603
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.

CVE-2024-5318
GitLab DevOps
4.0
MEDIUM
EPSS
0.0%
2024 CWE-862 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from 16.11 prior to 16.11.3, and starting from 17.0 prior to 17.0.1. A Guest user can view dependency lists of private projects through job artifacts.

CVE-2024-10491
express General
4.0
MEDIUM
EPSS
0.3%
2024 CWE-74 1 PoC

A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used. The issue arises from improper sanitization in `Link` header values, which can allow a combination of characters like `,`, `;`, and `<>` to preload malicious resources. This vulnerability is especially relevant for dynamic parameters.

CVE-2024-6790
Bifrost GPU Kernel Driver General
4.0
MEDIUM
EPSS
0.1%
2024 CWE-835 1 PoC

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a non-privileged user process to make valid GPU memory processing operations, including via WebGL or WebGPU, to cause the whole system to become unresponsive.This issue affects Bifrost GPU Kernel Driver: r44p1, from r46p0 through r49p0, from r50p0 through r51p0; Valhall GPU Kernel Driver: r44p1, from r46p0 through r49p0, from r50p0 through r51p0; Arm 5th Gen GPU Architecture Kernel Driver: r44p1,