3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-23759
Software Genérico General
9.8
CRITICAL
EPSS
67.1%
2024 1 PoC

Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.

CVE-2024-52475
Wawp General
9.8
CRITICAL
EPSS
29.1%
2024 CWE-288 2 PoCs

Authentication Bypass Using an Alternate Path or Channel vulnerability in Information Technology Wawp automation-web-platform allows Authentication Bypass.This issue affects Wawp: from n/a through < 3.0.18.

CVE-2024-57061
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses configuration.

CVE-2024-11704
Firefox General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133, Thunderbird < 133, Firefox ESR < 128.7, and Thunderbird < 128.7.

CVE-2024-35527
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

An arbitrary file upload vulnerability in /fileupload/upload.cfm in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to execute arbitrary code via uploading a crafted .cfm file.

CVE-2024-39844
Software Genérico General
9.8
CRITICAL
EPSS
37.1%
2024 1 PoC

In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.

CVE-2024-23740
Software Genérico General
9.8
CRITICAL
EPSS
23.2%
2024 2 PoCs

An issue in Kap for macOS version 3.6.0 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

CVE-2024-41197
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.

CVE-2024-41610
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.

CVE-2024-57595
Software Genérico General
9.8
CRITICAL
EPSS
2.4%
2024 1 PoC

DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attackers to execute arbitrary commands via the parameter "wps_pin" passed to the apc_client_pin.cgi binary through a POST request.

CVE-2024-54809
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use of a request header parameter in a strncpy where size is determined based on the input specified. By sending a specially crafted packet, an attacker can take control of the program counter and hijack control flow of the program to execute arbitrary system commands.

CVE-2024-0039
Android General
9.8
CRITICAL
EPSS
19.6%
2024 3 PoCs

In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-54363
Wp NssUser Register General
9.8
CRITICAL
EPSS
38.2%
2024 CWE-266 2 PoCs

Incorrect Privilege Assignment vulnerability in saiful.total Wp NssUser Register wp-nssuser-register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through <= 1.0.0.

CVE-2024-24882
Masteriyo - LMS General ⚡ nuclei
9.8
CRITICAL
EPSS
48.3%
2024 CWE-266 0 PoCs

Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.2.

CVE-2024-36080
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Westermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.

CVE-2024-23741
Software Genérico General
9.8
CRITICAL
EPSS
24.2%
2024 2 PoCs

An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

CVE-2024-27144
Toshiba Tec e-Studio multi-function peripheral (MFP) General
9.8
CRITICAL
EPSS
1.6%
2024 CWE-22 2 PoCs

The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker can overwrite any insecure files. And the Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by malicious programs by any local or remote attacker. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vul

CVE-2024-3660
keras General
9.8
CRITICAL
EPSS
0.4%
2024 3 PoCs

A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.

CVE-2024-45252
Halo version 11.7.1.5 General
9.8
CRITICAL
EPSS
0.6%
2024 CWE-78 1 PoC

Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVE-2024-22902
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.