3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-28066
Software Genérico General
8.8
HIGH
EPSS
0.0%
2024 2 PoCs

In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).

CVE-2024-32019
netdata General
8.8
HIGH
EPSS
0.6%
2024 CWE-426 9 PoCs

Netdata is an open source observability tool. In affected versions the `ndsudo` tool shipped with affected versions of the Netdata Agent allows an attacker to run arbitrary programs with root permissions. The `ndsudo` tool is packaged as a `root`-owned executable with the SUID bit set. It only runs a restricted set of external commands, but its search paths are supplied by the `PATH` environment variable. This allows an attacker to control where `ndsudo` looks for these commands, which may be a path the attacker has write access to. This may lead to local privilege escalation. This vulnerabili

CVE-2024-0800
Unified Data Protection General
8.8
HIGH
EPSS
0.3%
2024 CWE-434 1 PoC

A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.servlet.ImportNodeServlet.

CVE-2024-8636
Chrome General
8.8
HIGH
EPSS
0.6%
2024 CWE-122 2 PoCs

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-44625
Software Genérico General
8.8
HIGH
EPSS
75.1%
2024 2 PoCs

Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.

CVE-2024-39840
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Factorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the ability of certain Lua base module functions to execute bytecode and generate fake objects.

CVE-2024-12381
Chrome General
8.8
HIGH
EPSS
6.6%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-58336
Akuvox Smart Doorphone General
8.7
HIGH
EPSS
0.1%
2024 CWE-306 1 PoC

Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video.cgi endpoint on port 8080. Attackers can retrieve video stream data without authentication by directly accessing the specified endpoint on affected Akuvox doorphone and intercom devices.

CVE-2024-7584
i22 General
8.7
HIGH
EPSS
0.3%
2024 CWE-120 1 PoC

A vulnerability, which was classified as critical, was found in Tenda i22 1.0.0.3(4687). Affected is the function formApPortalPhoneAuth of the file /goform/apPortalPhoneAuth. The manipulation of the argument data leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-10282
RX9 General
8.7
HIGH
EPSS
0.4%
2024 CWE-121 1 PoC

A vulnerability classified as critical was found in Tenda RX9 and RX9 Pro 22.03.02.10/22.03.02.20. Affected by this vulnerability is the function sub_42EA38 of the file /goform/SetVirtualServerCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-10344
Helix Core General
8.7
HIGH
EPSS
0.9%
2024 CWE-400 1 PoC

In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the refuse function was identified. Reported by Karol Więsek.

CVE-2024-10314
Helix Core General
8.7
HIGH
EPSS
0.9%
2024 CWE-400 1 PoC

In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation function was identified. Reported by Karol Więsek.

CVE-2024-6963
O3 General
8.7
HIGH
EPSS
0.8%
2024 CWE-121 1 PoC

A vulnerability, which was classified as critical, has been found in Tenda O3 1.0.0.10. This issue affects the function formexeCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272117 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-45309
onedev General ⚡ nuclei
8.7
HIGH
EPSS
89.0%
2024 CWE-200 0 PoCs

OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary files accessible by the OneDev server process. This issue has been fixed in version 11.0.9.

CVE-2024-10345
Helix Core General
8.7
HIGH
EPSS
0.7%
2024 CWE-400 1 PoC

In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karol Więsek.

CVE-2024-7007
Broadcast Signal Processor TRA7005 General
8.7
HIGH
EPSS
0.1%
2024 CWE-288 1 PoC

Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas of the application.

CVE-2024-11303
JetPort 5601 General ⚡ nuclei
8.7
HIGH
EPSS
14.9%
2024 CWE-22 1 PoC

The pathname of the root directory to a Restricted Directory ('Path Traversal') vulnerability in Korenix JetPort 5601 allows Path Traversal.This issue affects JetPort 5601: through 1.2.

CVE-2024-11048
DI-8003 General
8.7
HIGH
EPSS
0.2%
2024 CWE-121 1 PoC

A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been rated as critical. Affected by this issue is the function dbsrv_asp of the file /dbsrv.asp. The manipulation of the argument str leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-7828
DNS-120 General
8.7
HIGH
EPSS
31.1%
2024 CWE-120 1 PoC

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814. This vulnerability affects the function cgi_set_cover of the file /cgi-bin/photocenter_mgr.cgi. The manipulation of the argument album_name leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability

CVE-2024-26290
Avid NEXIS E-series General
8.7
HIGH
EPSS
0.2%
2024 CWE-20 1 PoC

Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid System Director Appliance (SDA+) on Linux allows code execution on underlying operating system with root permissions.This issue affects Avid NEXIS E-series: before 2024.6.0; Avid NEXIS F-series: before 2024.6.0; Avid NEXIS PRO+: before 2024.6.0; System Director Appliance (SDA+): before 2024.6.0.