3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-9537
🔥 KEV SL1 General
9.8
CRITICAL
EPSS
63.9%
2024 4 PoCs

ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions back to version lines 10.1.x, 10.2.x, 11.1.x, 11.2.x, and 11.3.x.

CVE-2024-22852
Software Genérico General
9.8
CRITICAL
EPSS
5.6%
2024 1 PoC

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.

CVE-2024-54808
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2024 1 PoC

Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionService function due to an unconstrained use of sscanf. The vulnerability allows for control of the program counter and can be utilized to achieve arbitrary code execution.

CVE-2024-55557
Software Genérico General
9.8
CRITICAL
EPSS
21.3%
2024 2 PoCs

ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric encryption of proxy credentials.

CVE-2024-34832
Software Genérico General
9.8
CRITICAL
EPSS
8.3%
2024 1 PoC

Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.

CVE-2024-23705
Android General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

In multiple locations, there is a possible failure to persist or enforce user restrictions due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2024-36042
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often providing an unauthenticated user with superadmin access.

CVE-2024-56058
VRPConnector General
9.8
CRITICAL
EPSS
43.8%
2024 CWE-502 1 PoC

Deserialization of Untrusted Data vulnerability in denniskravetstns VRPConnector vrpconnector allows Object Injection.This issue affects VRPConnector: from n/a through <= 2.0.1.

CVE-2024-20017
MT6890, MT7915, MT7916, MT7981, MT7986 General
9.8
CRITICAL
EPSS
68.2%
2024 2 PoCs

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Issue ID: MSV-1132.

CVE-2024-57684
Software Genérico General
9.8
CRITICAL
EPSS
4.0%
2024 1 PoC

An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated attackers to set the DMZ service of the device via a crafted POST request.

CVE-2024-54363
Wp NssUser Register General
9.8
CRITICAL
EPSS
38.2%
2024 CWE-266 2 PoCs

Incorrect Privilege Assignment vulnerability in saiful.total Wp NssUser Register wp-nssuser-register allows Privilege Escalation.This issue affects Wp NssUser Register: from n/a through <= 1.0.0.

CVE-2024-52433
My Geo Posts Free General ⚡ nuclei
9.8
CRITICAL
EPSS
80.5%
2024 CWE-502 1 PoC

Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Object Injection.This issue affects My Geo Posts Free: from n/a through <= 1.2.

CVE-2024-51358
Software Genérico General
9.8
CRITICAL
EPSS
38.6%
2024 1 PoC

An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application.

CVE-2024-34313
Software Genérico General
9.8
CRITICAL
EPSS
24.7%
2024 1 PoC

An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a public endpoint.

CVE-2024-50485
Exam Matrix General
9.8
CRITICAL
EPSS
21.9%
2024 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in Udit Rawat Exam Matrix exam-matrix allows Privilege Escalation.This issue affects Exam Matrix: from n/a through <= 1.5.

CVE-2024-23761
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template.

CVE-2024-38812
🔥 KEV VMware vCenter Server General
9.8
CRITICAL
EPSS
77.9%
2024 CWE-122 1 PoC

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

CVE-2024-0039
Android General
9.8
CRITICAL
EPSS
19.6%
2024 3 PoCs

In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-45251
Halo version 11.7.1.5 General
9.8
CRITICAL
EPSS
0.7%
2024 CWE-78 1 PoC

Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVE-2024-52475
Wawp General
9.8
CRITICAL
EPSS
29.1%
2024 CWE-288 2 PoCs

Authentication Bypass Using an Alternate Path or Channel vulnerability in Information Technology Wawp automation-web-platform allows Authentication Bypass.This issue affects Wawp: from n/a through < 3.0.18.