3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-50626
Software Genérico General
8.8
HIGH
EPSS
0.3%
2024 1 PoC

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This allows an attacker on the local area network to manipulate URLs to include traversal sequences, potentially leading to unauthorized access to data.

CVE-2024-2486
AC18 General
8.8
HIGH
EPSS
0.5%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda AC18 15.03.05.05. It has been classified as critical. This affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256893 was assigned to this vulnerability.

CVE-2024-11395
Chrome General
8.8
HIGH
EPSS
0.3%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 131.0.6778.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-0692
Security Event Manager General ⚡ nuclei
8.8
HIGH
EPSS
78.3%
2024 CWE-502 0 PoCs

The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.

CVE-2024-12381
Chrome General
8.8
HIGH
EPSS
6.6%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-4242
W9 General
8.8
HIGH
EPSS
0.4%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been rated as critical. This issue affects the function formwrlSSIDget of the file /goform/wifiSSIDget. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-262133 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-5837
Chrome General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2024-22899
Software Genérico General
8.8
HIGH
EPSS
21.2%
2024 2 PoCs

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

CVE-2024-51442
Software Genérico General
8.8
HIGH
EPSS
32.7%
2024 1 PoC

Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specially crafted minidlna.conf configuration file.

CVE-2024-34221
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.

CVE-2024-24337
Software Genérico General
8.8
HIGH
EPSS
3.0%
2024 2 PoCs

CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components.

CVE-2024-41622
Software Genérico General
8.8
HIGH
EPSS
1.7%
2024 2 PoCs

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.

CVE-2024-0745
Firefox General
8.8
HIGH
EPSS
0.8%
2024 1 PoC

The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 122.

CVE-2024-8504
VICIdial General
8.8
HIGH
EPSS
93.1%
2024 CWE-78 3 PoCs

An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.

CVE-2024-41667
OpenAM General ⚡ nuclei
8.8
HIGH
EPSS
74.3%
2024 CWE-94 0 PoCs

OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.java is vulnerable to template injection due to its usage of user input. Although the developer intended to implement a custom URL for handling login to override the default OpenAM login, they did not restrict the `CustomLoginUrlTemplate`, allowing it to be set freely. Commit fcb8432aa77d5b2e147624fe954cb150c568e0b8 introduces `TemplateClassResolver.SAFER_RESOLVER` to disable the resolution of commonly exploited classes in FreeMarker template injecti

CVE-2024-2896
AC7 General
8.8
HIGH
EPSS
0.6%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. This issue affects the function formWifiWpsStart of the file /goform/WifiWpsStart. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257939. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-1675
Chrome General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-44341
Software Genérico General
8.8
HIGH
EPSS
3.8%
2024 2 PoCs

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.

CVE-2024-51162
Software Genérico General
8.8
HIGH
EPSS
2.2%
2024 2 PoCs

An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was identified that it is possible for any user (with any privilege) of Audimex to dump the whole Audimex database. This gives visibility upon password hashes of any user, ongoing audit data and more.

CVE-2024-0517
Chrome General
8.8
HIGH
EPSS
75.5%
2024 1 PoC

Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)