14993 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-40457
Software Genérico General
9.1
CRITICAL
EPSS
3.0%
2024 1 PoC

No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is that cleartext in /etc/default/noip-duc is recommended and is the intentional behavior.

CVE-2024-38736
Realtyna Organic IDX plugin General
9.1
CRITICAL
EPSS
1.0%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Injection.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.13.

CVE-2024-48905
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.

CVE-2024-5806
MOVEit Transfer General
9.1
CRITICAL
EPSS
89.9%
2024 CWE-287 2 PoCs

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

CVE-2019-11857
Software Genérico General
9.1
CRITICAL
EPSS
0.0%
2019 1 PoC

Lack of input sanitization in AceManager of ALEOS before 4.12.0, 4.9.5 and 4.4.9 allows disclosure of sensitive system information.

CVE-2019-20457
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2019 1 PoC

An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retrieved without authentication, because the response header of any failed login attempt returns an incomplete authorization cookie. The value of the authorization cookie is the MD5 hash of the password in hexadecimal. An attacker can easily derive the true MD5 hash from this, and use offline cracking attacks to obtain administrative access to the device.

CVE-2019-14418
Software Genérico General
9.1
CRITICAL
EPSS
3.7%
2019 1 PoC

An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. When uploading an application bundle, a directory traversal vulnerability allows a VRP user with sufficient privileges to overwrite any file in the VRP virtual machine. A malicious VRP user could use this to replace existing files to take control of the VRP virtual machine.

CVE-2019-5090
LEADTOOLS libltdic.so General
9.1
CRITICAL
EPSS
0.3%
2019 CWE-125 1 PoC

An exploitable information disclosure vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, version 20.0.2019.3.15. A specially crafted packet can cause an out-of-bounds read, resulting in information disclosure. An attacker can send a packet to trigger this vulnerability.

CVE-2021-4110
mruby/mruby General
9.1
CRITICAL
EPSS
0.5%
2021 CWE-476 1 PoC

mruby is vulnerable to NULL Pointer Dereference

CVE-2021-46756
Ryzen™ 2000 series Desktop Processors “Raven Ridge” AM4 General
9.1
CRITICAL
EPSS
0.2%
2021 2 PoCs

Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or ABL to send malformed or invalid syscall to the bootloader resulting in a potential denial of service and loss of integrity.

CVE-2021-21904
Garrett Metal Detectors General
9.1
CRITICAL
EPSS
2.1%
2021 CWE-22 1 PoC

A directory traversal vulnerability exists in the CMA CLI setenv command of Garrett Metal Detectors’ iC Module CMA Version 5.0. An attacker can provide malicious input to trigger this vulnerability

CVE-2021-41110
cwlviewer General
9.1
CRITICAL
EPSS
0.6%
2021 CWE-502 1 PoC

cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted Data vulnerability. Commit number f6066f09edb70033a2ce80200e9fa9e70a5c29de (dated 2021-09-30) contains a patch. There are no available workarounds aside from installing the patch. The SnakeYaml constructor, by default, allows any data to be parsed. To fix the issue the object needs to be created with a `SafeConstructor` object, as seen in the patch.

CVE-2021-27289
Software Genérico General
9.1
CRITICAL
EPSS
0.6%
2021 4 PoCs

A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As a result, an attacker within wireless range can resend captured packets with a higher sequence number, which the devices incorrectly accept as legitimate messages. This allows spoofed commands to be injected without authentication, triggering false alerts and misleading the user through notifications in the mobile appl

CVE-2021-21014
Magento Commerce General
9.1
CRITICAL
EPSS
0.4%
2021 CWE-434 1 PoC

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin console is required for successful exploitation.

CVE-2021-45650
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2021 1 PoC

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RS400 before 1.5.1.80, R6400v2 before 1.0.4.102, R7000P before 1.3.2.126, R6700v3 before 1.0.4.102, and R6900P before 1.3.2.126.

CVE-2021-34566
750-81xx/xxx-xxxFW General
9.1
CRITICAL
EPSS
0.9%
2021 CWE-120 1 PoC

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.

CVE-2021-46753
Ryzen™ 2000 series Desktop Processors “Raven Ridge” AM4 General
9.1
CRITICAL
EPSS
0.2%
2021 1 PoC

Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures leading to a potential loss of confidentiality and integrity.

CVE-2021-21001
Series PFC200 Controller General
9.1
CRITICAL
EPSS
0.2%
2021 CWE-22 1 PoC

On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.

CVE-2021-45496
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2021 1 PoC

NETGEAR D7000 devices before 1.0.1.82 are affected by authentication bypass.

CVE-2021-21819
D-Link General
9.1
CRITICAL
EPSS
1.3%
2021 CWE-78 1 PoC

A code execution vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.