9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-28340
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.

CVE-2024-32406
Software Genérico General
7.5
HIGH
EPSS
2.8%
2024 1 PoC

Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue Exam Tickets function.

CVE-2024-38881
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Rainbow Table Password cracking attack due to the use of one-way hashes without salts when storing user passwords.

CVE-2024-46307
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.

CVE-2024-21538
cross-spawn General
7.5
HIGH
EPSS
0.1%
2024 CWE-1333 2 PoCs

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

CVE-2024-57698
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, even after initial configuration and password change. This happens due to excessive exposure of information and the lack of adequate access control on the /user/list?culture=en-us endpoint.

CVE-2024-50945
Software Genérico General
7.5
HIGH
EPSS
5.0%
2024 1 PoC

An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, allowing users to submit reviews without verifying if they have purchased the product.

CVE-2024-39206
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials used in a backup due to enginesettings.list being encrypted with a hard coded key.

CVE-2024-28854
tls-listener General
7.5
HIGH
EPSS
0.2%
2024 CWE-400 1 PoC

tls-listener is a rust lang wrapper around a connection listener to support TLS. With the default configuration of tls-listener, a malicious user can open 6.4 `TcpStream`s a second, sending 0 bytes, and can trigger a DoS. The default configuration options make any public service using `TlsListener::new()` vulnerable to a slow-loris DoS attack. This impacts any publicly accessible service using the default configuration of tls-listener in versions prior to 0.10.0. Users are advised to upgrade. Users unable to upgrade may mitigate this by passing a large value, such as `usize::MAX` as the parame

CVE-2024-24736
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The POP3 service in YahooPOPs (aka YPOPs!) 1.6 allows a remote denial of service (reboot) via a long string to TCP port 110, a related issue to CVE-2004-1558.

CVE-2024-33214
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter in ip/goform/RouteStatic.

CVE-2024-4549
DIAEnergie General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.

CVE-2024-22328
Maximo Application Suite General
7.5
HIGH
EPSS
0.0%
2024 CWE-22 1 PoC

IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 279950.

CVE-2024-24426
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

CVE-2024-36857
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
53.4%
2024 0 PoCs

Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.

CVE-2024-8176
Software Genérico General
7.5
HIGH
EPSS
0.7%
2024 CWE-674 2 PoCs

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.

CVE-2024-42651
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

NanoMQ v0.17.9 was discovered to contain a heap use-after-free vulnerability via the component sub_Ctx_handle. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SUBSCRIBE message.

CVE-2024-31841
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.

CVE-2024-45248
Multi-DNC General
7.5
HIGH
EPSS
0.3%
2024 CWE-35 1 PoC

Multi-DNC – CWE-35: Path Traversal: '.../...//'

CVE-2024-47916
Boa web server 0.94.14rc21 General
7.5
HIGH
EPSS
0.4%
2024 CWE-22 1 PoC

Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')