3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-22632
Software Genérico General
9.8
CRITICAL
EPSS
4.2%
2024 1 PoC

Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hmsg parameter. This vulnerability is triggered via a crafted POST request.

CVE-2024-28515
Software Genérico General
9.8
CRITICAL
EPSS
16.2%
2024 1 PoC

Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary code via the lab3 of csapp,lab3/buflab-update.pl component.

CVE-2024-47943
IoT Interface & CMC III Processing Unit General
9.8
CRITICAL
EPSS
0.2%
2024 CWE-347 1 PoC

The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files are signed before executing the containing run.sh script. The signing process is kind of an HMAC with a long string as key which is hard-coded in the firmware and is freely available for download. This allows crafting malicious "signed" .patch files in order to compromise the device and execute arbitrary code.

CVE-2024-57595
Software Genérico General
9.8
CRITICAL
EPSS
2.4%
2024 1 PoC

DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attackers to execute arbitrary commands via the parameter "wps_pin" passed to the apc_client_pin.cgi binary through a POST request.

CVE-2024-33180
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2024 1 PoC

Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/saveParentControlInfo.

CVE-2024-22988
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp.

CVE-2024-46451
Software Genérico General
9.8
CRITICAL
EPSS
16.2%
2024 1 PoC

TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.

CVE-2024-41196
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.

CVE-2024-25291
Software Genérico General
9.8
CRITICAL
EPSS
15.8%
2024 2 PoCs

Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.

CVE-2024-50649
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2024 1 PoC

The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.

CVE-2024-42919
Software Genérico General
9.8
CRITICAL
EPSS
10.2%
2024 1 PoC

eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport.

CVE-2024-10811
Endpoint Manager General
9.8
CRITICAL
EPSS
4.7%
2024 CWE-36 1 PoC

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

CVE-2024-42395
HPE Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10 General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2024-23917
TeamCity General ⚡ nuclei
9.8
CRITICAL
EPSS
72.9%
2024 CWE-288 0 PoCs

In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible

CVE-2024-41593
Software Genérico General
9.8
CRITICAL
EPSS
7.7%
2024 1 PoC

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the length argument of a _memcpy call, leading to a heap-based Buffer Overflow.

CVE-2024-41195
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.

CVE-2024-41651
Software Genérico General
9.8
CRITICAL
EPSS
32.3%
2024 1 PoC

An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack network requests made by an admin user (who, by design, is allowed to change the code that is running on the server).

CVE-2024-54809
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header function due to use of a request header parameter in a strncpy where size is determined based on the input specified. By sending a specially crafted packet, an attacker can take control of the program counter and hijack control flow of the program to execute arbitrary system commands.

CVE-2024-54239
Eyewear prescription form General
9.8
CRITICAL
EPSS
2.9%
2024 CWE-862 1 PoC

Missing Authorization vulnerability in dugudlabs Eyewear prescription form eyewear-prescription-form allows Privilege Escalation.This issue affects Eyewear prescription form: from n/a through <= 4.0.18.

CVE-2024-36526
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.