9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-48271
Software Genérico General
8.8
HIGH
EPSS
0.0%
2024 1 PoC

D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device via a bruteforce attack.

CVE-2024-4493
i21 General
8.8
HIGH
EPSS
0.2%
2024 CWE-121 1 PoC

A vulnerability, which was classified as critical, was found in Tenda i21 1.0.0.14(4656). Affected is the function formSetAutoPing. The manipulation of the argument ping1/ping2 leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263082 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-54498
macOS General
8.8
HIGH
EPSS
8.1%
2024 1 PoC

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to break out of its sandbox.

CVE-2024-5847
Chrome General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

CVE-2024-45352
Xiaomi smarthome application General
8.8
HIGH
EPSS
0.0%
2024 CWE-346 3 PoCs

An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.

CVE-2024-7971
🔥 KEV Chrome General
8.8
HIGH
EPSS
1.0%
2024 CWE-843 2 PoCs

Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-21378
Microsoft Office 2019 General
8.8
HIGH
EPSS
27.3%
2024 CWE-94 2 PoCs

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2024-56898
Software Genérico General
8.8
HIGH
EPSS
6.9%
2024 1 PoC

Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, which can be leveraged to escalate privileges, create, modify or delete accounts.

CVE-2024-39924
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It permits an attacker with granted emergency access to escalate their privileges by changing the access level and modifying the wait time. Consequently, the attacker can gain full control over the vault (when only intended to have read access) while bypassing the necessary wait period.

CVE-2024-30616
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, posing a significant risk to data integrity.

CVE-2024-2176
Chrome General
8.8
HIGH
EPSS
1.3%
2024 1 PoC

Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-27632
Software Genérico General
8.8
HIGH
EPSS
2.1%
2024 3 PoCs

An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.

CVE-2024-10826
Chrome General
8.8
HIGH
EPSS
0.4%
2024 CWE-416 1 PoC

Use after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-7965
🔥 KEV Chrome General
8.8
HIGH
EPSS
23.8%
2024 2 PoCs

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-24350
Software Genérico General
8.8
HIGH
EPSS
1.9%
2024 1 PoC

File Upload vulnerability in Software Publico e-Sic Livre v.2.0 and before allows a remote attacker to execute arbitrary code via the extension filtering component.

CVE-2024-8636
Chrome General
8.8
HIGH
EPSS
0.6%
2024 CWE-122 2 PoCs

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-12382
Chrome General
8.8
HIGH
EPSS
12.6%
2024 CWE-416 1 PoC

Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-26504
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An issue in Wifire Hotspot v.4.5.3 allows a local attacker to execute arbitrary code via a crafted payload to the dst parameter.

CVE-2024-28139
Scan2Net General
8.8
HIGH
EPSS
0.3%
2024 CWE-250 2 PoCs

The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the root user. The risk has been accepted by the vendor and won't be fixed in the near future.

CVE-2024-2763
AC10U General
8.8
HIGH
EPSS
0.4%
2024 CWE-121 1 PoC

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. Affected by this issue is the function formSetCfm of the file goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257600. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.