40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-24321
Software Genérico General
9.8
CRITICAL
EPSS
2.2%
2024 1 PoC

An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.

CVE-2024-22916
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2024 2 PoCs

In D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack overflow.

CVE-2024-13160
🔥 KEV Endpoint Manager General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2024 CWE-36 1 PoC

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

CVE-2024-38886
Software Genérico General
9.8
CRITICAL
EPSS
0.9%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the source of a communication channel.

CVE-2024-4040
🔥 KEV CrushFTP General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2024 CWE-1336 21 PoCs

A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.

CVE-2024-28222
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2024 1 PoC

In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.

CVE-2024-1676
Chrome General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)

CVE-2024-56071
Simple Dashboard General
9.8
CRITICAL
EPSS
0.2%
2024 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in mikeleembruggen Simple Dashboard simple-dashboard allows Privilege Escalation.This issue affects Simple Dashboard: from n/a through <= 2.0.

CVE-2024-48359
Software Genérico General
9.8
CRITICAL
EPSS
38.2%
2024 1 PoC

Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.

CVE-2024-1015
E-DDC3.3 General
9.8
CRITICAL
EPSS
3.7%
2024 CWE-94 1 PoC

Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of the device.

CVE-2024-55956
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
91.2%
2024 3 PoCs

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

CVE-2024-34945
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW parameter at ip/goform/WizardHandle.

CVE-2024-0244
Satera MF750C Series General
9.8
CRITICAL
EPSS
0.5%
2024 CWE-787 2 PoCs

Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS MF750C Series/Color imageCLASS X MF1333C firmware v03.07 and earlier sold in US. i-SENSYS MF754Cdw/C1333iF firmware v03.07 and earlier sold in Europe.

CVE-2024-22320
Operational Decision Manager General ⚡ nuclei
9.8
CRITICAL
EPSS
90.8%
2024 CWE-502 1 PoC

IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending specially crafted request, an attacker could exploit this vulnerability to execute arbitrary code in the context of SYSTEM. IBM X-Force ID: 279146.

CVE-2024-39705
Software Genérico General
9.8
CRITICAL
EPSS
10.8%
2024 1 PoC

NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.

CVE-2024-50490
PegaPoll General
9.8
CRITICAL
EPSS
52.4%
2024 CWE-862 1 PoC

Missing Authorization vulnerability in lowcage PegaPoll pegapoll allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects PegaPoll: from n/a through <= 1.0.2.

CVE-2024-48126
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service access.

CVE-2024-4358
🔥 KEV Telerik Report Server General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2024 CWE-290 7 PoCs

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

CVE-2024-46483
Software Genérico General
9.8
CRITICAL
EPSS
13.9%
2024 1 PoC

Xlight FTP Server <3.9.4.3 has an integer overflow vulnerability in the packet parsing logic of the SFTP server, which can lead to a heap overflow with attacker-controlled content.

CVE-2024-6890
Journyx (jtime) General
9.8
CRITICAL
EPSS
0.1%
2024 CWE-321 2 PoCs

Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.