3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-9129
Zend Server General
9.3
CRITICAL
EPSS
0.2%
2024 CWE-134 1 PoC

In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan Marino

CVE-2024-0817
paddlepaddle/paddle General
9.3
CRITICAL
EPSS
0.3%
2024 CWE-77 1 PoC

Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0

CVE-2024-7024
Chrome General
9.3
CRITICAL
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-0815
paddlepaddle/paddle General
9.3
CRITICAL
EPSS
0.1%
2024 CWE-78 1 PoC

Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0

CVE-2024-0521
paddlepaddle/paddle General
9.3
CRITICAL
EPSS
0.1%
2024 CWE-94 1 PoC

Code Injection in paddlepaddle/paddle

CVE-2024-6915
Artifactory General
9.3
CRITICAL
EPSS
0.1%
2024 CWE-20 1 PoC

JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.

CVE-2024-7332
CP450 General ⚡ nuclei
9.3
CRITICAL
EPSS
92.1%
2024 CWE-259 0 PoCs

A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273255. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-24759
mindsdb General ⚡ nuclei
9.3
CRITICAL
EPSS
82.8%
2024 CWE-918 0 PoCs

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.

CVE-2024-9166
Atemio AM 520 HD Full HD Satellite Receiver General ⚡ nuclei
9.3
CRITICAL
EPSS
3.7%
2024 CWE-78 2 PoCs

The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.

CVE-2024-7988
ThinManager® ThinServer™ General
9.3
CRITICAL
EPSS
12.6%
2024 CWE-20 1 PoC

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be overwritten.

CVE-2024-4879
🔥 KEV Now Platform General ⚡ nuclei
9.3
CRITICAL
EPSS
94.3%
2024 CWE-1287 12 PoCs

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

CVE-2024-39376
Markoni-D (Compact) FM Transmitters General
9.3
CRITICAL
EPSS
0.2%
2024 CWE-284 1 PoC

TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performing actions beyond their designated permissions.

CVE-2024-13990
eScan AV General
9.3
CRITICAL
EPSS
0.2%
2024 CWE-295 3 PoCs

MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were delivered and accepted without robust cryptographic verification. As a result, an on-path attacker could perform a man-in-the-middle (MitM) attack and substitute malicious update payloads for legitimate ones. The eScan AV client accepted these substituted packages and executed or loaded their components (including sideloaded DLLs and Java/installer payloads), enabling remote code execution on affected systems. MicroWorld eScan confirmed remediation of the update mechanism on 2023

CVE-2024-58299
FTP Server General
9.3
CRITICAL
EPSS
0.3%
2024 CWE-121 1 PoC

PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during the FTP login process to overwrite memory and potentially gain system access.

CVE-2024-57823
Raptor RDF Syntax Library General
9.3
CRITICAL
EPSS
0.0%
2024 CWE-191 1 PoC

In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser in raptor_uri_normalize_path().

CVE-2024-39373
Markoni-D (Compact) FM Transmitters General
9.3
CRITICAL
EPSS
0.5%
2024 CWE-77 1 PoC

TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings and could allow an attacker to gain unauthorized access to the system with administrative privileges.

CVE-2024-7397
JetPort 5601v3 General
9.3
CRITICAL
EPSS
1.0%
2024 CWE-77 2 PoCs

Improper filering of special characters result in a command ('command injection') vulnerability in Korenix JetPort 5601v3.This issue affects JetPort 5601v3: through 1.2.

CVE-2024-58286
dizqueTV General
9.3
CRITICAL
EPSS
0.5%
2024 CWE-78 1 PoC

dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through the FFMPEG Executable Path settings. Attackers can modify the executable path with shell commands to read system files like /etc/passwd by exploiting improper input validation.

CVE-2024-47073
dataease General ⚡ nuclei
9.3
CRITICAL
EPSS
56.1%
2024 CWE-347 0 PoCs

DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a the lack of signature verification of jwt tokens allows attackers to forge jwts which then allow access to any interface. The vulnerability has been fixed in v2.10.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-58298
Compuware iStrobe Web General
9.2
CRITICAL
EPSS
2.0%
2024 CWE-434 1 PoC

Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to upload malicious JSP files through a path traversal in the file upload form. Attackers can exploit the 'fileName' parameter to upload a web shell and execute arbitrary commands by sending POST requests to the uploaded JSP endpoint.