2350 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-48453
Software Genérico General
9.8
CRITICAL
EPSS
4.0%
2024 1 PoC

An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgrade function

CVE-2024-41611
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.

CVE-2024-34257
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
89.6%
2024 0 PoCs

TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.

CVE-2024-34331
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root.

CVE-2024-25254
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.

CVE-2024-28213
nGrinder General
9.8
CRITICAL
EPSS
8.1%
2024 CWE-502 1 PoC

nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization.

CVE-2024-33775
Software Genérico General
9.8
CRITICAL
EPSS
3.4%
2024 1 PoC

An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

CVE-2024-25180
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2024 4 PoCs

An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after installing a test framework (that lives outside of the pdfmake applicaton). Anyone installing this is responsible for ensuring that it is only available to authorized testers.

CVE-2024-6396
aimhubio/aim General ⚡ nuclei
9.8
CRITICAL
EPSS
90.0%
2024 CWE-29 0 PoCs

A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vulnerability arises due to improper handling of the `run_hash` and `repo.path` parameters, which can be manipulated to create and write to arbitrary file paths. This can lead to denial of service by overwriting critical system files, loss of private data, and potential remote code execution.

CVE-2024-25249
Software Genérico General
9.8
CRITICAL
EPSS
2.4%
2024 1 PoC

An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

CVE-2024-40117
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting to the web administration server. Not existing for SL 200, 500, 1000 / fixed in 4.2.8 for SL 250, 300, 1200, 2000, SL 50 Gateway / fixed in 5.1.2 / 6.0.0 for SL Base.

CVE-2024-28713
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2024 1 PoC

An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.

CVE-2024-3847
Chrome General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-22857
Software Genérico General
9.8
CRITICAL
EPSS
4.3%
2024 1 PoC

Heap based buffer flow in zlog v1.1.0 to v1.2.17 in zlog_rule_new().The size of record_name is MAXLEN_PATH(1024) + 1 but file_path may have data upto MAXLEN_CFG_LINE(MAXLEN_PATH*4) + 1. So a check was missing in zlog_rule_new() while copying the record_name from file_path + 1 which caused the buffer overflow. An attacker can exploit this vulnerability to overwrite the zlog_record_fn record_func function pointer to get arbitrary code execution or potentially cause remote code execution (RCE).

CVE-2024-36404
geotools General ⚡ nuclei
9.8
CRITICAL
EPSS
90.7%
2024 CWE-95 2 PoCs

GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) is possible if an application uses certain GeoTools functionality to evaluate XPath expressions supplied by user input. Versions 31.2, 30.4, and 29.6 contain a fix for this issue. As a workaround, GeoTools can operate with reduced functionality by removing the `gt-complex` jar from one's application. As an example of the impact, application schema `datastore` would not function without the ability to use XPath expressions to query complex content.

CVE-2024-50476
GRÜN spendino Spendenformular General
9.8
CRITICAL
EPSS
24.7%
2024 CWE-862 1 PoC

Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege Escalation.This issue affects GRÜN spendino Spendenformular: from n/a through <= 1.0.1.

CVE-2024-12356
🔥 KEV Remote Support General
9.8
CRITICAL
EPSS
93.9%
2024 CWE-77 2 PoCs

A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.

CVE-2024-29276
Software Genérico General
9.8
CRITICAL
EPSS
14.7%
2024 1 PoC

An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess method in WorkFlowDesignerController.class component.

CVE-2024-22751
Software Genérico General
9.8
CRITICAL
EPSS
5.6%
2024 1 PoC

D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.

CVE-2024-53924
Software Genérico General
9.8
CRITICAL
EPSS
1.6%
2024 1 PoC

Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginning with the =IF(A1=200, eval("__import__('os').system( substring.