Vulnerabilidades CVE
Base de datos de vulnerabilidades CVE enriquecida con datos de CISA KEV y NVD
| CVE ID | CVSS | Severidad | KEV | Avistamientos |
|---|---|---|---|---|
| CVE-2024-31162 The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute... | 7.2 | HIGH | — | 0 |
| CVE-2024-31163 ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the d... | 7.2 | HIGH | — | 0 |
| CVE-2024-36499 Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | 6.8 | MEDIUM | — | 0 |
| CVE-2024-10305 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | N/A | NONE | — | 0 |
| CVE-2024-36500 Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | 7.8 | HIGH | — | 0 |
| CVE-2024-36501 Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity. | 5.6 | MEDIUM | — | 0 |
| CVE-2024-36502 Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnerability will affect availability. | 7.9 | HIGH | — | 0 |
| CVE-2024-36503 Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability. | 7.3 | HIGH | — | 0 |
| CVE-2024-3912 Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the device. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-5464 Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | 4.0 | MEDIUM | — | 0 |
| CVE-2024-5465 Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availability. | 5.9 | MEDIUM | — | 0 |
| CVE-2024-5577 The Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the WIW_HEADER parameter of the /system/include/include_user.php file. This makes i... | 9.8 | CRITICAL | — | 0 |
| CVE-2024-5961 Improper neutralization of input during web page generation vulnerability in 2ClickPortal software allows reflected cross-site scripting (XSS). An attacker might trick somebody into using a crafted UR... | N/A | NONE | — | 0 |
| CVE-2024-5995 The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the session is not properly configured, remaining valid for more than 7 days and can be r... | 8.8 | HIGH | — | 0 |
| CVE-2024-36287 Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS. | 3.8 | LOW | — | 0 |
| CVE-2024-37182 Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs ... | 4.7 | MEDIUM | — | 0 |
| CVE-2024-26520 An issue in Hangzhou Xiongwei Technology Development Co., Ltd. Restaurant Digital Comprehensive Management platform v1 allows an attacker to bypass authentication and perform arbitrary password resets... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-51376 Missing Authorization vulnerability in Brainstorm Force ProjectHuddle Client Site.This issue affects ProjectHuddle Client Site: from n/a through 1.0.34. | 4.3 | MEDIUM | — | 0 |
| CVE-2024-36459 A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for IIS Web Server and SiteMinder Web Agent for Domino Web Server. As a result, an a... | N/A | NONE | — | 0 |
| CVE-2024-2023 The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0 in Folders and 3.0.2 in Folders Pro via the 'handle_folders_file_upload'... | 4.3 | MEDIUM | — | 0 |
| CVE-2024-2024 The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_folders_file_upload' function in all versions up to, and including, 3.0.... | 8.8 | HIGH | — | 0 |
| CVE-2024-5671 Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS Manager. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-5731 A vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to control the destination of a request by manipulating the parameter, thereby leveragi... | 6.8 | MEDIUM | — | 0 |
| CVE-2024-23442 An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL. | 6.1 | MEDIUM | — | 0 |
| CVE-2024-39337 Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass. | 6.5 | MEDIUM | — | 0 |
| CVE-2024-33374 Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal without authentication. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-34539 Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also be used to login to the administra... | 9.4 | CRITICAL | — | 0 |
| CVE-2024-34694 LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered failed, even though it ma... | 8.1 | HIGH | — | 0 |
| CVE-2024-37314 Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud En... | 3.5 | LOW | — | 0 |
| CVE-2024-37367 A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s serv... | 7.5 | HIGH | — | 0 |
| CVE-2024-37315 Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore older versions of a document when the files_versions app is enabled. It is recom... | 3.5 | LOW | — | 0 |
| CVE-2024-0066 Johan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device) and (O3C) server. If O3C is not being used this f... | 5.3 | MEDIUM | — | 0 |
| CVE-2024-37316 Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommende... | 4.6 | MEDIUM | — | 0 |
| CVE-2024-37317 The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a newly created user before they logged in, the Notes app wo... | 4.6 | MEDIUM | — | 0 |
| CVE-2024-37882 Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It is recommended that the Nextcloud Server is... | 8.1 | HIGH | — | 0 |
| CVE-2024-37883 Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to a deck board was able to access commen... | 4.3 | MEDIUM | — | 0 |
| CVE-2024-37889 MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while signed in as a user. This method allows an actor to access PII and financial informa... | 6.5 | MEDIUM | — | 0 |
| CVE-2024-43628 Windows Telephony Service Remote Code Execution Vulnerability | 8.8 | HIGH | — | 0 |
| CVE-2024-37884 Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only got shared with read permissions. It is recommended that ... | 3.5 | LOW | — | 0 |
| CVE-2024-37885 The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when startin... | 3.8 | LOW | — | 0 |
| CVE-2024-24320 Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter of the l... | 8.8 | HIGH | — | 0 |
| CVE-2024-36598 An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file. | 8.1 | HIGH | — | 0 |
| CVE-2024-37888 The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerability allowed to execute JavaScript code by abusing link href attribute. It affects... | 6.1 | MEDIUM | — | 0 |
| CVE-2024-37831 Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter. | 9.8 | CRITICAL | — | 0 |
| CVE-2024-30119 HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during redirection. | 3.7 | LOW | — | 0 |
| CVE-2024-6003 A vulnerability was found in Guangdong Baolun Electronics IP Network Broadcasting Service Platform 2.0. It has been classified as critical. Affected is an unknown function of the file /api/v2/maps. Th... | 7.3 | HIGH | — | 0 |
| CVE-2023-6696 The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several ... | 8.1 | HIGH | — | 0 |
| CVE-2024-2544 The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all AJAX actions. This makes it possible for authenticat... | 7.4 | HIGH | — | 0 |
| CVE-2024-3813 The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' shortcode 'block_template_id' attribute. This makes it... | 8.8 | HIGH | — | 0 |
| CVE-2024-3814 The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module in all versions up to, and including, 4.8 due to insufficient input sanitization ... | 5.5 | MEDIUM | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.