9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-50245
openexr-viewer General
9.8
CRITICAL
EPSS
3.3%
2023 CWE-120 1 PoC

OpenEXR-viewer is a viewer for OpenEXR files with detailed metadata probing. Versions prior to 0.6.1 have a memory overflow vulnerability. This issue is fixed in version 0.6.1.

CVE-2023-48031
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2023 2 PoCs

OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attacker can bypass security restrictions and upload a .bat file by manipulating the file's magic bytes to masquerade as an allowed type. This can enable the attacker to execute arbitrary code or establish a reverse shell, leading to unauthorized file writes or control over the victim's station via a crafted file upload operation.

CVE-2023-46480
Software Genérico General
9.8
CRITICAL
EPSS
1.5%
2023 1 PoC

An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth function.

CVE-2023-51959
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2023 1 PoC

Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.

CVE-2024-35339
Software Genérico General
9.8
CRITICAL
EPSS
3.4%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac.

CVE-2024-36526
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.

CVE-2024-23759
Software Genérico General
9.8
CRITICAL
EPSS
67.1%
2024 1 PoC

Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.

CVE-2024-23740
Software Genérico General
9.8
CRITICAL
EPSS
23.2%
2024 2 PoCs

An issue in Kap for macOS version 3.6.0 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

CVE-2024-28515
Software Genérico General
9.8
CRITICAL
EPSS
16.2%
2024 1 PoC

Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary code via the lab3 of csapp,lab3/buflab-update.pl component.

CVE-2024-21334
System Center Operations Manager (SCOM) 2019 General
9.8
CRITICAL
EPSS
6.9%
2024 CWE-416 1 PoC

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

CVE-2024-27764
Software Genérico General
9.8
CRITICAL
EPSS
1.1%
2024 1 PoC

An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.

CVE-2024-39844
Software Genérico General
9.8
CRITICAL
EPSS
37.1%
2024 1 PoC

In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.

CVE-2024-50649
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2024 1 PoC

The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.

CVE-2024-11704
Firefox General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133, Thunderbird < 133, Firefox ESR < 128.7, and Thunderbird < 128.7.

CVE-2024-41195
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.

CVE-2024-25291
Software Genérico General
9.8
CRITICAL
EPSS
15.8%
2024 2 PoCs

Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.

CVE-2024-37079
🔥 KEV VMware vCenter Server General
9.8
CRITICAL
EPSS
82.0%
2024 1 PoC

vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

CVE-2024-54809
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use of a request header parameter in a strncpy where size is determined based on the input specified. By sending a specially crafted packet, an attacker can take control of the program counter and hijack control flow of the program to execute arbitrary system commands.

CVE-2024-47943
IoT Interface & CMC III Processing Unit General
9.8
CRITICAL
EPSS
0.2%
2024 CWE-347 1 PoC

The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files are signed before executing the containing run.sh script. The signing process is kind of an HMAC with a long string as key which is hard-coded in the firmware and is freely available for download. This allows crafting malicious "signed" .patch files in order to compromise the device and execute arbitrary code.

CVE-2024-4885
🔥 KEV WhatsUp Gold General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2024 CWE-22 1 PoC

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.