3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-41209
Software Genérico General
8.8
HIGH
EPSS
1.6%
2024 1 PoC

A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS) and Code Execution via a crafted MOV video file.

CVE-2024-27497
Software Genérico General ⚡ nuclei
8.8
HIGH
EPSS
81.9%
2024 0 PoCs

Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.

CVE-2024-8504
VICIdial General
8.8
HIGH
EPSS
93.1%
2024 CWE-78 3 PoCs

An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.

CVE-2024-50627
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file upload feature. It allows an attacker on the local area network (with specific permissions) to upload and execute malicious files, potentially leading to unauthorized system access.

CVE-2024-6778
Chrome General
8.8
HIGH
EPSS
12.8%
2024 CWE-362 2 PoCs

Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

CVE-2024-6891
Journyx (jtime) General
8.8
HIGH
EPSS
0.2%
2024 CWE-94 2 PoCs

Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.

CVE-2024-6774
Chrome General
8.8
HIGH
EPSS
0.7%
2024 CWE-416 1 PoC

Use after free in Screen Capture in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-3833
Chrome General
8.8
HIGH
EPSS
3.1%
2024 1 PoC

Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-39091
Software Genérico General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary code via a crafted HTML request.

CVE-2024-5705
Pentaho Data Integration & Analytics General
8.8
HIGH
EPSS
0.0%
2024 CWE-863 1 PoC

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions. (CWE-863)     Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, have modules enabled by default that allow execution of system level processes.   When access control checks are incorrectly applied, users can access data or perform actions that they should not be allowed to perform. This can lead to a wide

CVE-2024-27656
Software Genérico General
8.8
HIGH
EPSS
2.6%
2024 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Cookie parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.

CVE-2024-2627
Chrome General
8.8
HIGH
EPSS
1.0%
2024 1 PoC

Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-53345
Software Genérico General
8.8
HIGH
EPSS
6.8%
2024 1 PoC

An authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-50626
Software Genérico General
8.8
HIGH
EPSS
0.3%
2024 1 PoC

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This allows an attacker on the local area network to manipulate URLs to include traversal sequences, potentially leading to unauthorized access to data.

CVE-2024-34448
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Ghost before 5.82.0 allows CSV Injection during a member CSV export.

CVE-2024-11621
Remote Desktop Manager General
8.8
HIGH
EPSS
0.2%
2024 CWE-295 1 PoC

Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier Remote Desktop Manager Powershell 2024.3.6.0 and earlier

CVE-2024-10487
Chrome General
8.8
HIGH
EPSS
0.3%
2024 CWE-787 1 PoC

Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

CVE-2024-2487
AC18 General
8.8
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName/mac leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-256894 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-40431
Software Genérico General
8.8
HIGH
EPSS
24.8%
2024 2 PoCs

A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IOCTL_SCSI_PASS_THROUGH control of the SD card reader driver allows an attacker to write to predictable kernel memory locations, even as a low-privileged user.