116 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2024-9474
🔥 KEV Cloud NGFW Networking Cloud ⚡ nuclei
6.9
MEDIUM
EPSS
94.2%
2024 CWE-78 7 PoCs

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

CVE-2024-12987
🔥 KEV Vigor2960 General ⚡ nuclei
6.9
MEDIUM
EPSS
79.0%
2024 CWE-78 0 PoCs

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.

CVE-2024-37085
🔥 KEV VMware ESXi Web Windows
6.8
MEDIUM
EPSS
75.1%
2024 4 PoCs

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vsphere-hosts-to-active-directory.html by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD.

CVE-2024-43451
🔥 KEV Windows Server 2025 Windows
6.5
MEDIUM
EPSS
90.3%
2024 CWE-73 1 PoC

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2024-9379
🔥 KEV CSA (Cloud Services Appliance) Database Cloud
6.5
MEDIUM
EPSS
81.7%
2024 CWE-89 1 PoC

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

CVE-2024-37383
🔥 KEV Software Genérico Web
6.1
MEDIUM
EPSS
64.0%
2024 2 PoCs

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

CVE-2024-27443
🔥 KEV Software Genérico Web ⚡ nuclei
6.1
MEDIUM
EPSS
32.4%
2024 0 PoCs

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code.

CVE-2024-20359
🔥 KEV Cisco Adaptive Security Appliance (ASA) Software Networking
6.0
MEDIUM
EPSS
0.2%
2024 CWE-94 1 PoC

A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level privileges are required to exploit this vulnerability. This vulnerability is due to improper validation of a file when it is read from system flash memory. An attacker could exploit this vulnerability by copying a crafted file to the disk0: file sys

CVE-2024-20399
🔥 KEV Cisco NX-OS Software Networking
6.0
MEDIUM
EPSS
0.8%
2024 CWE-78 1 PoC

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the p

CVE-2024-50302
🔥 KEV Linux General
5.5
MEDIUM
EPSS
1.7%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak kernel memory via specially-crafted report.

CVE-2024-38217
🔥 KEV Windows 10 Version 1809 Windows
5.4
MEDIUM
EPSS
12.1%
2024 CWE-693 1 PoC

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-0769
🔥 KEV DIR-859 Web
5.3
MEDIUM
EPSS
75.2%
2024 CWE-22 2 PoCs

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251666 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer sup

CVE-2024-39891
🔥 KEV Software Genérico Web
5.3
MEDIUM
EPSS
17.1%
2024 1 PoC

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. Specifically, the endpoint accepted a stream of requests containing phone numbers, and responded with information about whether each phone number was registered with Authy. (Authy accounts were not compromised, however.)

CVE-2024-8069
🔥 KEV Citrix Session Recording Networking
5.1
MEDIUM
EPSS
66.3%
2024 CWE-502 1 PoC

Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server

CVE-2024-55550
🔥 KEV Software Genérico General ⚡ nuclei
4.4
MEDIUM
EPSS
17.7%
2024 0 PoCs

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.