3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-5705
Pentaho Data Integration & Analytics General
8.8
HIGH
EPSS
0.0%
2024 CWE-863 1 PoC

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions. (CWE-863)     Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, have modules enabled by default that allow execution of system level processes.   When access control checks are incorrectly applied, users can access data or perform actions that they should not be allowed to perform. This can lead to a wide

CVE-2024-7969
Chrome General
8.8
HIGH
EPSS
0.2%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-27656
Software Genérico General
8.8
HIGH
EPSS
2.6%
2024 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Cookie parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.

CVE-2024-25092
NextMove Lite General
8.8
HIGH
EPSS
71.4%
2024 CWE-862 2 PoCs

Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0.

CVE-2024-5247
ProSAFE Network Management System General
8.8
HIGH
EPSS
58.1%
2024 CWE-434 1 PoC

NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is required to exploit this vulnerability. The specific flaw exists within the UpLoadServlet class. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-2292

CVE-2024-5706
Pentaho Data Integration & Analytics General
8.8
HIGH
EPSS
3.9%
2024 CWE-99 1 PoC

The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CWE-99)  Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, do not restrict JNDI identifiers during the creation of Community Dashboards, allowing control of system-level data sources.  An attacker could gain access to or modify sensitive data or system resources. This could allow access to protected files or d

CVE-2024-2627
Chrome General
8.8
HIGH
EPSS
1.0%
2024 1 PoC

Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-12053
Chrome General
8.8
HIGH
EPSS
0.1%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-46433
Software Genérico General
8.8
HIGH
EPSS
1.0%
2024 1 PoC

A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using the default rzadmin account with administrative privileges.

CVE-2024-6891
Journyx (jtime) General
8.8
HIGH
EPSS
0.2%
2024 CWE-94 2 PoCs

Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.

CVE-2024-24337
Software Genérico General
8.8
HIGH
EPSS
3.0%
2024 2 PoCs

CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components.

CVE-2024-39924
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It permits an attacker with granted emergency access to escalate their privileges by changing the access level and modifying the wait time. Consequently, the attacker can gain full control over the vault (when only intended to have read access) while bypassing the necessary wait period.

CVE-2024-3516
Chrome General
8.8
HIGH
EPSS
0.7%
2024 1 PoC

Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-0578
LR1200GB General
8.8
HIGH
EPSS
0.4%
2024 CWE-121 1 PoC

A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250794 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-27756
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.

CVE-2024-54378
Quietly Insights General
8.8
HIGH
EPSS
2.6%
2024 CWE-862 1 PoC

Missing Authorization vulnerability in Quietly Quietly Insights quietly-insights allows Privilege Escalation.This issue affects Quietly Insights: from n/a through <= 1.2.2.

CVE-2024-51023
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the SetNetworkTomographySettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-6995
Chrome General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-10230
Chrome General
8.8
HIGH
EPSS
0.2%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-11621
Remote Desktop Manager General
8.8
HIGH
EPSS
0.2%
2024 CWE-295 1 PoC

Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier Remote Desktop Manager Powershell 2024.3.6.0 and earlier