14993 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-50477
Stacks Mobile App Builder General ⚡ nuclei
9.8
CRITICAL
EPSS
82.2%
2024 CWE-288 1 PoC

Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Authentication Bypass.This issue affects Stacks Mobile App Builder: from n/a through <= 5.2.3.

CVE-2024-25830
Software Genérico General
9.8
CRITICAL
EPSS
39.1%
2024 1 PoC

F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password.

CVE-2024-33215
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat.

CVE-2024-22852
Software Genérico General
9.8
CRITICAL
EPSS
5.6%
2024 1 PoC

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.

CVE-2024-45488
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
86.9%
2024 0 PoCs

One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to cookies. This only affects virtual appliance installations (VMware or HyperV). The fixed versions are 7.0.5.1 LTS, 7.4.2, and 7.5.2.

CVE-2024-6602
Firefox General
9.8
CRITICAL
EPSS
0.8%
2024 1 PoC

A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

CVE-2024-45251
Halo version 11.7.1.5 General
9.8
CRITICAL
EPSS
0.7%
2024 CWE-78 1 PoC

Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVE-2024-24402
Software Genérico General
9.8
CRITICAL
EPSS
21.5%
2024 1 PoC

An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.

CVE-2024-34832
Software Genérico General
9.8
CRITICAL
EPSS
8.3%
2024 1 PoC

Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.

CVE-2024-9537
🔥 KEV SL1 General
9.8
CRITICAL
EPSS
63.9%
2024 4 PoCs

ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x.

CVE-2024-34313
Software Genérico General
9.8
CRITICAL
EPSS
24.7%
2024 1 PoC

An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a public endpoint.

CVE-2024-57604
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2024 1 PoC

An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.

CVE-2024-2921
Server General
9.8
CRITICAL
EPSS
0.7%
2024 1 PoC

Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to access unauthorized PAM entries via a specific set of permissions.

CVE-2024-24398
Software Genérico General
9.8
CRITICAL
EPSS
30.5%
2024 2 PoCs

Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.

CVE-2024-27776
DeviceHub General
9.8
CRITICAL
EPSS
0.6%
2024 CWE-22 1 PoC

MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE

CVE-2024-29650
Software Genérico General
9.8
CRITICAL
EPSS
2.8%
2024 2 PoCs

An issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutInManyUnsafe components.

CVE-2024-45274
mbNET.mini General
9.8
CRITICAL
EPSS
3.6%
2024 CWE-306 2 PoCs

An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.

CVE-2024-32444
RealHomes General
9.8
CRITICAL
EPSS
0.2%
2024 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue affects RealHomes: from n/a through <= 4.3.6.

CVE-2024-13159
🔥 KEV Endpoint Manager General ⚡ nuclei
9.8
CRITICAL
EPSS
94.0%
2024 CWE-36 1 PoC

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

CVE-2024-30568
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
89.7%
2024 1 PoC

Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.