3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-22722
Software Genérico General
7.2
HIGH
EPSS
0.1%
2024 1 PoC

Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.

CVE-2024-0795
mintplex-labs/anything-llm General
7.2
HIGH
EPSS
0.6%
2024 CWE-284 1 PoC

If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an `admin` role and then be able to use this new account to have elevated privileges on the instance

CVE-2024-34370
EAN for WooCommerce General
7.2
HIGH
EPSS
9.2%
2024 CWE-269 1 PoC

Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.

CVE-2024-27130
QTS General
7.2
HIGH
EPSS
81.0%
2024 CWE-120 3 PoCs

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute code via a network. We have already fixed the vulnerability in the following version: QTS 5.1.7.2770 build 20240520 and later QuTS hero h5.1.7.2770 build 20240520 and later

CVE-2024-0533
A15 General
7.2
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda A15 15.13.07.13. It has been rated as critical. This issue affects some unknown processing of the file /goform/SetOnlineDevName of the component Web-based Management Interface. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250703. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-41199
Software Genérico General
7.2
HIGH
EPSS
0.1%
2024 1 PoC

An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.

CVE-2024-3154
Software Genérico General
7.2
HIGH
EPSS
0.2%
2024 CWE-77 1 PoC

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.

CVE-2024-33529
Software Genérico General
7.2
HIGH
EPSS
0.8%
2024 1 PoC

ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to execute operating system commands via file uploads with dangerous types.

CVE-2024-21683
Confluence Data Center General ⚡ nuclei
7.2
HIGH
EPSS
94.1%
2024 9 PoCs

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.  Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the

CVE-2024-0918
TEW-800MB General
7.2
HIGH
EPSS
48.9%
2024 CWE-78 1 PoC

A vulnerability was found in TRENDnet TEW-800MB 1.0.1.0 and classified as critical. Affected by this issue is some unknown functionality of the component POST Request Handler. The manipulation of the argument DeviceURL leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252122 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-25946
Virtual Appliance (vApp) Manager General
7.2
HIGH
EPSS
0.4%
2024 CWE-78 1 PoC

Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.

CVE-2024-33250
Software Genérico General
7.2
HIGH
EPSS
0.4%
2024 1 PoC

An issue in Open-Source Technology Committee SRS real-time video server RS/4.0.268(Leo) and SRS/4.0.195(Leo) allows a remote attacker to execute arbitrary code via a crafted request.

CVE-2024-0998
N200RE General
7.2
HIGH
EPSS
0.5%
2024 CWE-121 1 PoC

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. This affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252267. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-45187
Software Genérico General
7.1
HIGH
EPSS
0.1%
2024 CWE-613 1 PoC

Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute arbitrary code through the Mage AI terminal server

CVE-2024-26292
Avid NEXIS E-series General
7.1
HIGH
EPSS
0.2%
2024 CWE-22 1 PoC

An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1.

CVE-2024-1938
Chrome General
7.1
HIGH
EPSS
0.4%
2024 1 PoC

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-44258
iOS and iPadOS General
7.1
HIGH
EPSS
1.7%
2024 2 PoCs

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, tvOS 18.1, visionOS 2.1. Restoring a maliciously crafted backup file may lead to modification of protected system files.

CVE-2024-40814
macOS General
7.1
HIGH
EPSS
0.0%
2024 1 PoC

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.6, macOS Ventura 13.7. An app may be able to bypass Privacy preferences.

CVE-2024-33899
Software Genérico General
7.1
HIGH
EPSS
1.0%
2024 1 PoC

RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape sequences.

CVE-2024-56084
Software Genérico General
7.1
HIGH
EPSS
2.6%
2024 CWE-77 1 PoC

An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.