3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-21488
network General
7.3
HIGH
EPSS
2.2%
2024 CWE-77 1 PoC

Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for the attacker to execute arbitrary commands on the operating system that this package is being run on.

CVE-2024-43093
🔥 KEV Android General
7.3
HIGH
EPSS
0.2%
2024 2 PoCs

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2024-34614
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.2%
2024 1 PoC

Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

CVE-2024-38499
CA Client Automation (ITCM) General
7.3
HIGH
EPSS
0.1%
2024 CWE-269 1 PoC

CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a non-admin/non-root user to execute "caf encrypt"/"sd_acmd encrypt" commands.

CVE-2024-45246
Vynamic View prior to v5.9.5 General
7.3
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

Diebold Nixdorf – CWE-427: Uncontrolled Search Path Element

CVE-2024-46507
Software Genérico General ⚡ nuclei
7.3
HIGH
EPSS
0.2%
2024 2 PoCs

A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.

CVE-2024-40511
Software Genérico General
7.3
HIGH
EPSS
13.9%
2024 1 PoC

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMServerAdmin.asmx function.

CVE-2024-42471
toolkit General
7.3
HIGH
EPSS
7.7%
2024 CWE-22 1 PoC

actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or higher. There are no known workarounds for this issue.

CVE-2024-1112
Resource Hacker General
7.3
HIGH
EPSS
38.8%
2024 CWE-119 1 PoC

Heap-based buffer overflow vulnerability in Resource Hacker, developed by Angus Johnson, affecting version 3.6.0.92. This vulnerability could allow an attacker to execute arbitrary code via a long filename argument.

CVE-2024-0242
IQ Panel 4 General
7.3
HIGH
EPSS
0.1%
2024 CWE-200 1 PoC

Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.

CVE-2024-20849
Samsung Mobile Devices General
7.3
HIGH
EPSS
0.1%
2024 1 PoC

Out-of-bound Write vulnerability in chunk parsing implementation of libsdffextractor prior to SMR Apr-2023 Release 1 allows local attackers to execute arbitrary code.

CVE-2024-49601
Unity General
7.3
HIGH
EPSS
1.2%
2024 CWE-78 1 PoC

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

CVE-2024-40512
Software Genérico General
7.3
HIGH
EPSS
17.1%
2024 1 PoC

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMReporting.asmx function.

CVE-2024-34656
Samsung Notes General
7.3
HIGH
EPSS
0.1%
2024 1 PoC

Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

CVE-2024-45257
Software Genérico General
7.3
HIGH
EPSS
58.0%
2024 1 PoC

A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators.py.

CVE-2024-27199
🔥 KEV TeamCity General ⚡ nuclei
7.3
HIGH
EPSS
91.4%
2024 CWE-23 1 PoC

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

CVE-2024-50450
MDTF General
7.3
HIGH
EPSS
52.5%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Code Injection.This issue affects MDTF: from n/a through <= 1.3.3.4.

CVE-2024-50986
Software Genérico General
7.3
HIGH
EPSS
10.9%
2024 2 PoCs

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.

CVE-2024-6333
AltaLink® B8045 / B8055 / B8065 / B8075 / B8090 | C8030 / C8035 / C8045 / C8055 / C807 General
7.2
HIGH
EPSS
3.7%
2024 CWE-78 1 PoC

Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.

CVE-2024-40318
Software Genérico General
7.2
HIGH
EPSS
10.1%
2024 1 PoC

An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.