9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-44565
Software Genérico General
8.0
HIGH
EPSS
0.2%
2024 1 PoC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the serverName parameter in the function form_fast_setting_internet_set.

CVE-2024-20815
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

CVE-2024-51009
Software Genérico General
8.0
HIGH
EPSS
1.1%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at ether.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-42915
Software Genérico General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This will allow attackers to arbitrarily reset other users' passwords and compromise their accounts.

CVE-2024-41596
Software Genérico General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form parameters.

CVE-2024-48633
Software Genérico General
8.0
HIGH
EPSS
0.3%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-52021
Software Genérico General
8.0
HIGH
EPSS
0.4%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at bsw_fix.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-51186
Software Genérico General
8.0
HIGH
EPSS
1.3%
2024 1 PoC

D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 and ping_v6 functions.

CVE-2024-54887
Software Genérico General
8.0
HIGH
EPSS
1.3%
2024 1 PoC

TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the remote device in the context of the root user.

CVE-2024-52018
Software Genérico General
8.0
HIGH
EPSS
0.4%
2024 1 PoC

Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at genie_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-48093
Software Genérico General
8.0
HIGH
EPSS
3.8%
2024 1 PoC

Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Execution via uploading and executing malicious files without validating file extensions or content types.

CVE-2024-41595
Software Genérico General
8.0
HIGH
EPSS
0.4%
2024 1 PoC

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cgi pages because of missing bounds checks on read and write operations.

CVE-2024-20816
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

CVE-2024-41590
Software Genérico General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor310 devices through 4.3.2.6.

CVE-2024-41592
Software Genérico General
8.0
HIGH
EPSS
1.9%
2024 1 PoC

DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs.

CVE-2024-51010
Software Genérico General
8.0
HIGH
EPSS
0.7%
2024 1 PoC

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component ap_mode.cgi via the apmode_gateway parameter. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-51008
Software Genérico General
8.0
HIGH
EPSS
0.7%
2024 1 PoC

Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at wiz_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-51024
Software Genérico General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the HostName parameter in the SetWanSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-48630
Software Genérico General
8.0
HIGH
EPSS
0.3%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the MacAddress parameter in the SetMACFilters2 function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2019-11542
Software Genérico General
8.0
HIGH
EPSS
34.7%
2019 1 PoC

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via the admin web interface) can send a specially crafted message resulting in a stack buffer overflow.