2350 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-22252
VMware ESXi General
9.3
CRITICAL
EPSS
0.2%
2024 1 PoC

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

CVE-2024-39373
Markoni-D (Compact) FM Transmitters General
9.3
CRITICAL
EPSS
0.5%
2024 CWE-77 1 PoC

TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings and could allow an attacker to gain unauthorized access to the system with administrative privileges.

CVE-2024-39375
Markoni-D (Compact) FM Transmitters General
9.3
CRITICAL
EPSS
0.0%
2024 CWE-603 1 PoC

TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileges.

CVE-2024-7024
Chrome General
9.3
CRITICAL
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-7397
JetPort 5601v3 General
9.3
CRITICAL
EPSS
1.0%
2024 CWE-77 2 PoCs

Improper filering of special characters result in a command ('command injection') vulnerability in Korenix JetPort 5601v3.This issue affects JetPort 5601v3: through 1.2.

CVE-2024-39376
Markoni-D (Compact) FM Transmitters General
9.3
CRITICAL
EPSS
0.2%
2024 CWE-284 1 PoC

TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performing actions beyond their designated permissions.

CVE-2024-7988
ThinManager® ThinServer™ General
9.3
CRITICAL
EPSS
12.6%
2024 CWE-20 1 PoC

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be overwritten.

CVE-2024-39374
Markoni-D (Compact) FM Transmitters General
9.3
CRITICAL
EPSS
0.2%
2024 CWE-798 1 PoC

TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials.

CVE-2024-25293
Software Genérico General
9.3
CRITICAL
EPSS
19.9%
2024 2 PoCs

mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.

CVE-2024-27954
Automatic General ⚡ nuclei
9.3
CRITICAL
EPSS
93.4%
2024 CWE-22 4 PoCs

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0.

CVE-2024-9166
Atemio AM 520 HD Full HD Satellite Receiver General ⚡ nuclei
9.3
CRITICAL
EPSS
3.7%
2024 CWE-78 2 PoCs

The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.

CVE-2024-24759
mindsdb General ⚡ nuclei
9.3
CRITICAL
EPSS
82.8%
2024 CWE-918 0 PoCs

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.

CVE-2024-7332
CP450 General ⚡ nuclei
9.3
CRITICAL
EPSS
92.1%
2024 CWE-259 0 PoCs

A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273255. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2019-25441
thesystem General
9.3
CRITICAL
EPSS
6.2%
2019 CWE-78 1 PoC

thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious input to the run_command endpoint. Attackers can send POST requests with shell commands in the command parameter to execute arbitrary code on the server without authentication.

CVE-2019-25614
Free Float FTP General
9.3
CRITICAL
EPSS
0.8%
2019 CWE-787 1 PoC

Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containing 247 bytes of padding followed by a return address and shellcode to trigger code execution on the FTP server.

CVE-2019-25709
CF Image Hosting Script General
9.3
CRITICAL
EPSS
0.4%
2019 CWE-552 1 PoC

CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter.

CVE-2019-25646
Mail Carrier General
9.3
CRITICAL
EPSS
0.7%
2019 CWE-787 1 PoC

Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote attackers to execute arbitrary code by sending a crafted MAIL FROM parameter. Attackers can connect to the SMTP service on port 25 and send a malicious MAIL FROM command with an oversized buffer to overwrite the EIP register and execute a bind shell payload.

CVE-2019-25714
A8-V5 Collaborative Management Software General
9.3
CRITICAL
EPSS
0.8%
2019 CWE-434 1 PoC

Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with custom base64-encoded payloads. Attackers can write JSP webshells to the web root and execute them through the web server to achieve arbitrary OS command execution with web server privileges. Exploitation evidence was first observed by the Shadowserver Foundation on 2021-03-26 (UTC).

CVE-2019-25568
Memu Play General
9.3
CRITICAL
EPSS
0.0%
2019 CWE-306 1 PoC

Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuService.exe executable. Attackers can rename and overwrite MemuService.exe in the installation directory with a malicious executable, which executes with system-level privileges when the service restarts after a computer reboot.

CVE-2019-25291
Smartliving SmartLAN/G/SI General
9.3
CRITICAL
EPSS
0.1%
2019 CWE-798 2 PoCs

INIM Electronics Smartliving SmartLAN/G/SI <=6.x contains hard-coded credentials in its Linux distribution image that cannot be changed through normal device operations. Attackers can exploit these persistent credentials to log in and gain unauthorized system access across multiple SmartLiving device models.