9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-24386
Software Genérico General
7.2
HIGH
EPSS
1.4%
2024 1 PoC

An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder.

CVE-2024-56161
AMD EPYC™ 7001 Series General
7.2
HIGH
EPSS
0.1%
2024 CWE-347 1 PoC

Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.

CVE-2024-5672
mbNET.mini General
7.2
HIGH
EPSS
0.7%
2024 CWE-78 1 PoC

A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.

CVE-2024-1003
N200RE General
7.2
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability, which was classified as critical, has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this issue is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument lang leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252272. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-40442
Software Genérico General
7.2
HIGH
EPSS
0.5%
2024 1 PoC

An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via a crafted REST Request.

CVE-2024-11066
DSL6740C General
7.2
HIGH
EPSS
0.9%
2024 CWE-78 1 PoC

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through the specific web page.

CVE-2024-0918
TEW-800MB General
7.2
HIGH
EPSS
48.9%
2024 CWE-78 1 PoC

A vulnerability was found in TRENDnet TEW-800MB 1.0.1.0 and classified as critical. Affected by this issue is some unknown functionality of the component POST Request Handler. The manipulation of the argument DeviceURL leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252122 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-45844
BIG-IP General
7.2
HIGH
EPSS
0.1%
2024 CWE-306 1 PoC

BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2024-0200
Enterprise Server General ⚡ nuclei
7.2
HIGH
EPSS
70.8%
2024 CWE-470 1 PoC

An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-controlled methods and remote code execution. To exploit this bug, an actor would need to be logged into an account on the GHES instance with the organization owner role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.8.13, 3.9.8, 3.10.5, and 3.11.3. This vulnerability was reported via the GitHub Bug Bounty program.

CVE-2024-21683
Confluence Data Center General ⚡ nuclei
7.2
HIGH
EPSS
94.1%
2024 9 PoCs

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.  Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the

CVE-2024-0998
N200RE General
7.2
HIGH
EPSS
0.5%
2024 CWE-121 1 PoC

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. This affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252267. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-1001
N200RE General
7.2
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability classified as critical has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected is the function main of the file /cgi-bin/cstecgi.cgi. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-252270 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-6333
AltaLink® B8045 / B8055 / B8065 / B8075 / B8090 | C8030 / C8035 / C8045 / C8055 / C807 General
7.2
HIGH
EPSS
3.7%
2024 CWE-78 1 PoC

Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.

CVE-2024-38288
Software Genérico General ⚡ nuclei
7.2
HIGH
EPSS
68.5%
2024 0 PoCs

A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root.

CVE-2024-0533
A15 General
7.2
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda A15 15.13.07.13. It has been rated as critical. This issue affects some unknown processing of the file /goform/SetOnlineDevName of the component Web-based Management Interface. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250703. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-27130
QTS General
7.2
HIGH
EPSS
81.0%
2024 CWE-120 3 PoCs

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later

CVE-2024-34370
EAN for WooCommerce General
7.2
HIGH
EPSS
9.2%
2024 CWE-269 1 PoC

Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.

CVE-2024-0795
mintplex-labs/anything-llm General
7.2
HIGH
EPSS
0.6%
2024 CWE-284 1 PoC

If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an `admin` role and then be able to use this new account to have elevated privileges on the instance

CVE-2024-25420
Software Genérico General
7.2
HIGH
EPSS
1.6%
2024 1 PoC

An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.

CVE-2024-54330
Hurrakify General ⚡ nuclei
7.2
HIGH
EPSS
72.5%
2024 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) vulnerability in hurraki Hurrakify hurrakify allows Server Side Request Forgery.This issue affects Hurrakify: from n/a through <= 2.4.