3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-9490
Silicon Labs IDE (8-bit) General
8.6
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in Silicon Labs (8-bit) IDE installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2024-35340
Software Genérico General
8.6
HIGH
EPSS
2.4%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip/goform/formexeCommand.

CVE-2024-42463
upKeeper Manager General
8.6
HIGH
EPSS
0.1%
2024 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue affects upKeeper Manager: through 5.1.9.

CVE-2024-9498
USBXpress SDK General
8.6
HIGH
EPSS
0.0%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress SDK installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2024-47076
libcupsfilters General
8.6
HIGH
EPSS
73.9%
2024 CWE-20 1 PoC

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` function in `libcupsfilters` does not sanitize IPP attributes returned from an IPP server. When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system.

CVE-2024-9154
Ewon Flexy 205 General
8.6
HIGH
EPSS
0.2%
2024 CWE-94 1 PoC

A code injection vulnerability in HMS Networks Ewon Flexy 205 allows executing commands on system level on the device. This issue affects Ewon Flexy 205: through 14.8s0 (#2633).

CVE-2024-9496
USBXpress Dev Kit General
8.6
HIGH
EPSS
0.0%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Dev Kit installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2024-9493
ToolStick General
8.6
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the  ToolStick installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2024-9497
USBXpress 4 SDK General
8.6
HIGH
EPSS
0.0%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress 4 SDK installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2024-21544
spatie/browsershot General
8.6
HIGH
EPSS
0.2%
2024 CWE-20 1 PoC

Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by using leading whitespace (%20) before the file:// protocol, resulting in Local File Inclusion, which allows the attacker to read sensitive files on the server.

CVE-2024-9494
CP210 VCP Win 2k General
8.6
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

DLL hijacking vulnerabilities, caused by an uncontrolled search path in the  CP210 VCP Win 2k installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.

CVE-2024-1019
ModSecurity General
8.6
HIGH
EPSS
0.3%
2024 CWE-20 1 PoC

ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded characters present in request URLs before it separates the URL path component from the optional query string component. This results in an impedance mismatch versus RFC compliant back-end applications. The vulnerability hides an attack payload in the path component of the URL from WAF rules inspecting it. A back-end may be vulnerable if it uses the path component of request URLs to construct queries. Integrators an

CVE-2024-58293
Akaunting General
8.6
HIGH
EPSS
0.0%
2024 CWE-1336 1 PoC

Akaunting 3.1.8 contains a server-side template injection vulnerability that allows authenticated administrators to execute template expressions in multiple form input fields. Attackers can inject template payloads in items, taxes, transactions, and vendor name fields to perform arithmetic operations and string manipulations.

CVE-2024-10093
ConvertXtoDvd General
8.5
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

A vulnerability, which was classified as critical, was found in VSO ConvertXtoDvd 7.0.0.83. Affected is an unknown function in the library avcodec.dll of the file ConvertXtoDvd.exe. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-14010
Typora General
8.5
HIGH
EPSS
0.6%
2024 CWE-78 1 PoC

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution.

CVE-2024-28981
Pentaho Data Integration & Analytics General
8.5
HIGH
EPSS
0.1%
2024 CWE-522 1 PoC

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.

CVE-2024-58315
Tosibox Key Service General
8.5
HIGH
EPSS
0.0%
2024 CWE-428 1 PoC

Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the service startup process by inserting malicious code in the system root path, enabling unauthorized code execution during application startup or system reboot.

CVE-2024-13206
Antivirus General
8.5
HIGH
EPSS
0.0%
2024 CWE-276 1 PoC

A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part of the file /usr/local/reveantivirus/tmp/reveinstall. The manipulation leads to incorrect default permissions. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-58278
perl2exe General
8.5
HIGH
EPSS
0.0%
2024 CWE-78 1 PoC

perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts. Attackers can control the 0th argument of packed executables to execute another executable, allowing them to bypass restrictions and gain unauthorized access.