9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-3188
owncast/owncast General ⚡ nuclei
8.3
HIGH
EPSS
48.7%
2023 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0.

CVE-2024-5274
🔥 KEV Chrome General
8.3
HIGH
EPSS
5.0%
2024 3 PoCs

Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2024-7940
MicroSCADA SYS600 General
8.3
HIGH
EPSS
0.6%
2024 CWE-306 1 PoC

The product exposes a service that is intended for local only to all network interfaces without any authentication.

CVE-2024-22727
Software Genérico General
8.3
HIGH
EPSS
0.3%
2024 1 PoC

Teltonika TRB1-series devices with firmware before TRB1_R_00.07.05.2 allow attackers to exploit a firmware vulnerability via Ethernet LAN or USB.

CVE-2024-21525
node-twain General
8.3
HIGH
EPSS
0.1%
2024 CWE-703 1 PoC

All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the length of the source data not being checked. Creating a new twain.TwainSDK with a productName or productFamily, manufacturer, version.info property of length >= 34 chars leads to a buffer overflow vulnerability.

CVE-2024-50492
ScottCart General
8.3
HIGH
EPSS
62.3%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.

CVE-2024-37569
Software Genérico General
8.3
HIGH
EPSS
2.4%
2024 1 PoC

An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injection vulnerability exists in the hostname parameter taken in by the provis.html endpoint. The provis.html endpoint performs no sanitization on the hostname parameter (sent by an authenticated user), which is subsequently written to disk. During boot, the hostname parameter is executed as part of a series of shell commands. Attackers can achieve remote code execution in the root context by placing shell metacharacters in the hostname parameter.

CVE-2024-1621
uniFLOW Online General
8.3
HIGH
EPSS
0.3%
2024 CWE-940 1 PoC

The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to register themselves against a genuine user in the system and allow malicious users with similar access and capabilities via the app to the existing genuine user.

CVE-2024-33182
Software Genérico General
8.3
HIGH
EPSS
0.3%
2024 1 PoC

Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/addWifiMacFilter.

CVE-2024-29194
oneuptime General
8.3
HIGH
EPSS
0.1%
2024 CWE-639 1 PoC

OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation of client-side stored data within the web application. Specifically, the is_master_admin key, stored in the local storage of the browser, can be manipulated by an attacker. By changing this key from false to true, the application grants administrative privileges to the user, without proper server-side validation. This has been patched in 7.0.1815.

CVE-2024-4761
🔥 KEV Chrome General
8.3
HIGH
EPSS
3.1%
2024 1 PoC

Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVE-2024-46436
Software Genérico General
8.3
HIGH
EPSS
1.0%
2024 1 PoC

Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the device over the telnet service.

CVE-2024-35308
Pandora FMS General
8.3
HIGH
EPSS
1.0%
2024 CWE-22 1 PoC

A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3.

CVE-2024-42340
CyberArk Identity Management General
8.3
HIGH
EPSS
0.1%
2024 CWE-602 1 PoC

CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security

CVE-2024-21672
Confluence Data Center General
8.3
HIGH
EPSS
7.2%
2024 3 PoCs

This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H allows an unauthenticated attacker to remotely expose assets in your environment susceptible to exploitation which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version,

CVE-2024-22024
ICS General ⚡ nuclei
8.3
HIGH
EPSS
94.2%
2024 2 PoCs

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

CVE-2024-3323
JasperReports Server General
8.3
HIGH
EPSS
0.1%
2024 1 PoC

Cross Site Scripting in UI Request/Response Validation in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user's active session cookie via sending malicious link, enticing the user to interact.

CVE-2024-42381
Software Genérico General
8.3
HIGH
EPSS
0.4%
2024 1 PoC

os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve code execution via an ELF file with a custom .interp section. NOTE: this code execution would occur during an un-sandboxed binary relocation phase, which occurs before a user would expect execution of downloaded package content. (237d1e783f7ee261beaba7d3f6bde22da7148b0a was the tested vulnerable version.)

CVE-2024-42995
Software Genérico General
8.3
HIGH
EPSS
0.1%
2024 1 PoC

VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module to disable arbitrary modules.

CVE-2024-1555
Firefox General
8.3
HIGH
EPSS
0.1%
2024 1 PoC

When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123.