9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-3393
fossbilling/fossbilling General
8.0
HIGH
EPSS
0.1%
2023 CWE-94 1 PoC

Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1.

CVE-2023-21476
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.0%
2023 1 PoC

Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-51148
Software Genérico General
8.0
HIGH
EPSS
0.1%
2023 1 PoC

An issue in TRENDnet Trendnet AC1200 Dual Band PoE Indoor Wireless Access Point TEW-821DAP v.3.00b06 allows an attacker to execute arbitrary code via the 'mycli' command-line interface component.

CVE-2023-3491
fossbilling/fossbilling General
8.0
HIGH
EPSS
0.1%
2023 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository fossbilling/fossbilling prior to 0.5.3.

CVE-2023-47564
Qsync Central General
8.0
HIGH
EPSS
8.0%
2023 CWE-732 1 PoC

An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.15 ( 2024/01/04 ) and later Qsync Central 4.3.0.11 ( 2024/01/11 ) and later

CVE-2023-28909
Volkswagen MIB3 infotainment system MIB3 OI MQB General
8.0
HIGH
EPSS
0.2%
2023 CWE-190 2 PoCs

A specific flaw exists within the Bluetooth stack of the MIB3 unit. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow when receiving fragmented HCI packets on a channel. An attacker can leverage this vulnerability to bypass the MTU check on a channel with enabled fragmentation. Consequently, this can lead to a buffer overflow in upper layer profiles, which can be used to obtain remote code execution. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The lis

CVE-2023-51795
Software Genérico General
8.0
HIGH
EPSS
0.1%
2023 2 PoCs

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame

CVE-2023-1094
MonicaHQ General
8.0
HIGH
EPSS
0.8%
2023 1 PoC

MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/food` endpoint and food parameter.

CVE-2023-21475
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.0%
2023 1 PoC

Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

CVE-2023-24334
Software Genérico General
8.0
HIGH
EPSS
0.1%
2023 1 PoC

A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.

CVE-2023-28905
Volkswagen MIB3 infotainment system MIB3 OI MQB General
8.0
HIGH
EPSS
0.3%
2023 CWE-122 2 PoCs

A heap buffer overflow in the image processing binary of the MIB3 infotainment unit allows an attacker to execute arbitrary code on it. The vulnerability was originally discovered in Skoda Superb III car with MIB3 infotainment unit OEM part number 3V0035820. The list of affected MIB3 OEM part numbers is provided in the referenced resources.

CVE-2024-48632
Software Genérico General
8.0
HIGH
EPSS
0.3%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the LocalIPAddress, TCPPorts, and UDPPorts parameters in the SetPortForwardingSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-50993
Software Genérico General
8.0
HIGH
EPSS
1.1%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at admin_account.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-30572
Software Genérico General
8.0
HIGH
EPSS
1.0%
2024 1 PoC

Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.

CVE-2024-48636
Software Genérico General
8.0
HIGH
EPSS
0.8%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:0/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-48637
Software Genérico General
8.0
HIGH
EPSS
0.8%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:1/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-48634
Software Genérico General
8.0
HIGH
EPSS
3.7%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the key parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-41586
Software Genérico General
8.0
HIGH
EPSS
1.1%
2024 1 PoC

A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to execute arbitrary code via a long query string to the cgi-bin/ipfedr.cgi component.

CVE-2024-7023
Chrome General
8.0
HIGH
EPSS
0.7%
2024 1 PoC

Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)

CVE-2024-24590
ClearML General
8.0
HIGH
EPSS
82.8%
2024 CWE-502 11 PoCs

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with.