9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-45273
mbNET.mini General
8.4
HIGH
EPSS
0.1%
2024 CWE-261 1 PoC

An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.

CVE-2024-31959
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which can result in code execution.

CVE-2024-54028
catdoc General
8.4
HIGH
EPSS
0.2%
2024 CWE-191 2 PoCs

An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-3435
parisneo/lollms-webui General
8.4
HIGH
EPSS
0.4%
2024 CWE-29 1 PoC

A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest release before 9.5. The vulnerability arises due to insufficient sanitization of the 'config' parameter in the 'apply_settings' function, allowing an attacker to manipulate the application's configuration by sending specially crafted JSON payloads. This could lead to remote code execution (RCE) by bypassing existing patches designed to mitigate such vulnerabilities.

CVE-2024-6473
Browser General
8.4
HIGH
EPSS
3.1%
2024 CWE-426 1 PoC

Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.

CVE-2024-31319
Android General
8.4
HIGH
EPSS
0.0%
2024 2 PoCs

In updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a possible cross-user data leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-20812
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.0%
2024 1 PoC

Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

CVE-2024-41605
Software Genérico General
8.4
HIGH
EPSS
0.0%
2024 1 PoC

In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks integrity validation for the updater. Attacker-controlled code may thus be executed.

CVE-2024-48123
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue in the USB Autorun function of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to execute arbitrary code via uploading a crafted script from a USB device.

CVE-2024-48877
xls2csv General
8.4
HIGH
EPSS
0.2%
2024 CWE-680 2 PoCs

A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-52333
DCMTK General
8.4
HIGH
EPSS
0.1%
2024 CWE-119 1 PoC

An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-2448
LoadMaster General
8.4
HIGH
EPSS
44.8%
2024 CWE-78 1 PoC

An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.

CVE-2024-41340
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to upload crafted APP Enforcement modules, leading to arbitrary code execution.

CVE-2024-32503
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper memory deallocation checking, which can result in a UAF (Use-After-Free) vulnerability.

CVE-2024-5009
WhatsUp Gold General
8.4
HIGH
EPSS
36.0%
2024 CWE-269 2 PoCs

In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.InstallController.SetAdminPassword allows local attackers to modify admin's password.

CVE-2024-38399
Snapdragon General
8.4
HIGH
EPSS
0.1%
2024 CWE-416 1 PoC

Memory corruption while processing user packets to generate page faults.

CVE-2019-25332
FTP Commander Pro General
8.4
HIGH
EPSS
0.1%
2019 CWE-121 2 PoCs

FTP Commander Pro 8.03 contains a local stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting the EIP register through a custom command input. Attackers can craft a malicious payload of 4108 bytes to overwrite memory and execute shellcode, demonstrating remote code execution potential.

CVE-2019-18897
SUSE Linux Enterprise Server 12 General
8.4
HIGH
EPSS
0.1%
2019 CWE-59 2 PoCs

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to root. This issue affects: SUSE Linux Enterprise Server 12 salt-master version 2019.2.0-46.83.1 and prior versions. SUSE Linux Enterprise Server 15 salt-master version 2019.2.0-6.21.1 and prior versions. openSUSE Factory salt-master version 2019.2.2-3.1 and prior versions.

CVE-2019-25318
AVS Audio Converter General
8.4
HIGH
EPSS
0.0%
2019 CWE-121 2 PoCs

AVS Audio Converter 9.1.2.600 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by manipulating the output folder text input. Attackers can craft a malicious payload that overwrites stack memory and triggers a bind shell on port 9999 when the 'Browse' button is clicked.

CVE-2019-25327
Prime95 General
8.4
HIGH
EPSS
0.3%
2019 CWE-122 1 PoC

Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the PrimeNet user ID and proxy host fields to trigger a bind shell on port 3110.