3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-47943
IoT Interface & CMC III Processing Unit General
9.8
CRITICAL
EPSS
0.2%
2024 CWE-347 1 PoC

The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files are signed before executing the containing run.sh script. The signing process is kind of an HMAC with a long string as key which is hard-coded in the firmware and is freely available for download. This allows crafting malicious "signed" .patch files in order to compromise the device and execute arbitrary code.

CVE-2024-36445
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2024 2 PoCs

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.

CVE-2024-0039
Android General
9.8
CRITICAL
EPSS
19.6%
2024 3 PoCs

In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-36404
geotools General ⚡ nuclei
9.8
CRITICAL
EPSS
90.7%
2024 CWE-95 2 PoCs

GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) is possible if an application uses certain GeoTools functionality to evaluate XPath expressions supplied by user input. Versions 31.2, 30.4, and 29.6 contain a fix for this issue. As a workaround, GeoTools can operate with reduced functionality by removing the `gt-complex` jar from one's application. As an example of the impact, application schema `datastore` would not function without the ability to use XPath expressions to query complex content.

CVE-2024-30568
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
89.7%
2024 1 PoC

Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.

CVE-2024-32444
RealHomes General
9.8
CRITICAL
EPSS
0.2%
2024 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue affects RealHomes: from n/a through <= 4.3.6.

CVE-2024-22902
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.

CVE-2024-54756
Software Genérico General
9.8
CRITICAL
EPSS
2.1%
2024 2 PoCs

A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted PK3 file containing a malicious ZScript source file.

CVE-2024-57684
Software Genérico General
9.8
CRITICAL
EPSS
4.0%
2024 1 PoC

An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.

CVE-2024-6695
User Profile Builder General
9.8
CRITICAL
EPSS
1.1%
2024 1 PoC

it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.

CVE-2024-2055
Artica Proxy General
9.8
CRITICAL
EPSS
0.1%
2024 CWE-288 2 PoCs

The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user.

CVE-2024-12649
Satera MF656Cdw General
9.8
CRITICAL
EPSS
0.3%
2024 CWE-787 1 PoC

Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw firmware v05.04 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw firmware v05.04 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS LBP63

CVE-2024-28986
🔥 KEV Web Help Desk General ⚡ nuclei
9.8
CRITICAL
EPSS
79.7%
2024 CWE-502 0 PoCs

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been unable to reproduce it without authentication after thorough testing.   However, out of an abundance of caution, we recommend all Web Help Desk customers apply the patch, which is now available.

CVE-2024-50648
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2024 1 PoC

yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.

CVE-2024-2056
Artica Proxy General
9.8
CRITICAL
EPSS
4.9%
2024 CWE-288 2 PoCs

Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running as the root user, is bound to the loopback interface, and is listening on TCP port 7050. Security issues associated with exposing this network service are documented at gvalkov's 'tailon' GitHub repo. Using the tailon service, the contents of any file on the Artica Proxy can be viewed.

CVE-2024-42395
HPE Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10 General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2024-24329
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
83.3%
2024 0 PoCs

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.

CVE-2024-22891
Software Genérico General
9.8
CRITICAL
EPSS
39.4%
2024 2 PoCs

Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.

CVE-2024-29650
Software Genérico General
9.8
CRITICAL
EPSS
2.8%
2024 2 PoCs

An issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutInManyUnsafe components.

CVE-2024-3408
man-group/dtale General ⚡ nuclei
9.8
CRITICAL
EPSS
90.5%
2024 CWE-798 0 PoCs

man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded `SECRET_KEY` in the flask configuration, allowing attackers to forge a session cookie if authentication is enabled. Additionally, the application fails to properly restrict custom filter queries, enabling attackers to execute arbitrary code on the server by bypassing the restriction on the `/update-settings` endpoint, even when `enable_custom_filters` is not enabled. This vulnerability allows attackers to bypass aut