7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-2780
Online Marriage Registration System Web
3.5
LOW
EPSS
0.2%
2024 CWE-79 1 PoC

A vulnerability was found in Campcodes Online Marriage Registration System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-257614 is the identifier assigned to this vulnerability.

CVE-2024-11140
Real WP Shop Lite Ajax eCommerce Shopping Cart Web Windows
3.5
LOW
EPSS
0.6%
2024 1 PoC

The Real WP Shop Lite Ajax eCommerce Shopping Cart WordPress plugin through 2.0.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CVE-2024-24774
Mattermost General
3.4
LOW
EPSS
0.3%
2024 CWE-863 1 PoC

Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the subscription resulting in registered users on Jira being able to create webhooks that give them access to all Jira issues.

CVE-2024-3471
Button Generator Web Windows
3.4
LOW
EPSS
0.1%
2024 1 PoC

The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allow attackers to make a logged in admin delete buttons via a CSRF attack

CVE-2024-20836
Samsung Mobile Devices General
3.3
LOW
EPSS
0.1%
2024 1 PoC

Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out of bounds memory.

CVE-2024-20805
Samsung Mobile Devices General
3.3
LOW
EPSS
0.1%
2024 1 PoC

Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.

CVE-2024-20810
Samsung Mobile Devices General
3.3
LOW
EPSS
0.1%
2024 1 PoC

Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.

CVE-2024-29508
Software Genérico General
3.3
LOW
EPSS
0.0%
2024 2 PoCs

Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.

CVE-2024-30356
PDF Reader General
3.3
LOW
EPSS
0.3%
2024 CWE-125 1 PoC

Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects in AcroForms. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction w

CVE-2024-0149
NVIDIA GPU Display Driver, vGPU software General
3.3
LOW
EPSS
0.0%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Linux contains a vulnerability which could allow an attacker unauthorized access to files. A successful exploit of this vulnerability might lead to limited information disclosure.

CVE-2024-23743
Software Genérico General
3.3
LOW
EPSS
0.2%
2024 2 PoCs

Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "the attacker must launch the Notion Desktop application with nonstandard flags that turn the Electron-based application into a Node.js execution environment."

CVE-2024-30329
PDF Reader General
3.3
LOW
EPSS
0.5%
2024 CWE-416 1 PoC

Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to

CVE-2024-5198
ovpn-dco Networking Windows
3.3
LOW
EPSS
0.1%
2024 CWE-476 1 PoC

OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.

CVE-2024-30364
PDF Reader General
3.3
LOW
EPSS
0.4%
2024 CWE-125 1 PoC

Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with othe

CVE-2024-40832
macOS General
3.3
LOW
EPSS
0.2%
2024 1 PoC

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to view a contact's phone number in system logs.

CVE-2024-47896
Graphics DDK General
3.3
LOW
EPSS
0.0%
2024 CWE-823 1 PoC

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

CVE-2024-34671
Samsung Internet General
3.3
LOW
EPSS
0.1%
2024 1 PoC

Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

CVE-2024-30347
PDF Reader General
3.3
LOW
EPSS
0.3%
2024 CWE-125 1 PoC

Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with othe

CVE-2024-7722
PDF Reader General
3.3
LOW
EPSS
1.0%
2024 CWE-416 1 PoC

Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute

CVE-2024-34640
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2024 1 PoC

Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.