14993 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-22729
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
91.2%
2024 0 PoCs

NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.

CVE-2024-27683
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacker can send a POST request to trigger the vulnerablilify.

CVE-2024-45166
Software Genérico General
9.8
CRITICAL
EPSS
4.8%
2024 2 PoCs

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution. There is an access violation and EIP overwrite after five logins.

CVE-2024-22853
Software Genérico General
9.8
CRITICAL
EPSS
86.9%
2024 2 PoCs

D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.

CVE-2024-29937
Software Genérico General
9.8
CRITICAL
EPSS
4.4%
2024 1 PoC

NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.

CVE-2024-34399
Software Genérico General
9.8
CRITICAL
EPSS
1.9%
2024 1 PoC

**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without using any password. NOTE: This vulnerability only affects products that are no longer supported by the maintainer and the impacted version for this vulnerability is 7.6.04 only.

CVE-2024-25153
FileCatalyst General
9.8
CRITICAL
EPSS
82.2%
2024 CWE-472 3 PoCs

A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells.

CVE-2024-12647
Satera MF656Cdw General
9.8
CRITICAL
EPSS
0.3%
2024 CWE-787 1 PoC

Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw firmware v05.04 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS

CVE-2024-41570
Software Genérico General
9.8
CRITICAL
EPSS
74.1%
2024 4 PoCs

An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send arbitrary network traffic originating from the team server.

CVE-2024-48590
Software Genérico General
9.8
CRITICAL
EPSS
2.1%
2024 1 PoC

Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an attacker to escalate privileges and obtain sensitive information.

CVE-2024-33792
Software Genérico General
9.8
CRITICAL
EPSS
0.9%
2024 1 PoC

netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert page.

CVE-2024-54806
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2024 1 PoC

Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execution of system commands via the web interface.

CVE-2024-45167
Software Genérico General
9.8
CRITICAL
EPSS
4.0%
2024 3 PoCs

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution. A certain XmlMessage document causes 100% CPU consumption.

CVE-2024-36858
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
73.6%
2024 0 PoCs

An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-9680
🔥 KEV Firefox General
9.8
CRITICAL
EPSS
30.8%
2024 1 PoC

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0.

CVE-2024-50478
1-Click Login: Passwordless Authentication General
9.8
CRITICAL
EPSS
28.6%
2024 CWE-305 1 PoC

Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authentication Bypass.This issue affects 1-Click Login: Passwordless Authentication: 1.4.5.

CVE-2024-52430
Lis Video Gallery General
9.8
CRITICAL
EPSS
32.1%
2024 CWE-502 1 PoC

Deserialization of Untrusted Data vulnerability in bublick Lis Video Gallery lis-video-gallery allows Object Injection.This issue affects Lis Video Gallery: from n/a through <= 0.2.1.

CVE-2024-40453
Software Genérico General
9.8
CRITICAL
EPSS
3.5%
2024 1 PoC

squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName.