33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-39274
Mattermost General
8.7
HIGH
EPSS
0.2%
2024 CWE-284 1 PoC

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the channel that comes from the sync message is a shared channel, when shared channels are enabled, which allows a malicious remote to add users to arbitrary teams and channels

CVE-2024-6189
A301 General
8.7
HIGH
EPSS
0.4%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda A301 15.13.08.12. It has been classified as critical. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269160. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-10282
RX9 General
8.7
HIGH
EPSS
0.4%
2024 CWE-121 1 PoC

A vulnerability classified as critical was found in Tenda RX9 and RX9 Pro 22.03.02.10/22.03.02.20. Affected by this vulnerability is the function sub_42EA38 of the file /goform/SetVirtualServerCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-35306
Pandora FMS Web
8.7
HIGH
EPSS
0.5%
2024 CWE-78 1 PoC

OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 through <777.

CVE-2024-9912
DIR-619L B1 General
8.7
HIGH
EPSS
0.1%
2024 CWE-120 1 PoC

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been declared as critical. This vulnerability affects the function formSetQoS of the file /goform/formSetQoS. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-58294
FreePBX Web
8.7
HIGH
EPSS
0.7%
2024 CWE-78 1 PoC

FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access.

CVE-2024-9556
DIR-605L General
8.7
HIGH
EPSS
0.1%
2024 CWE-120 1 PoC

A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetEnableWizard of the file /goform/formSetEnableWizard. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-58276
Obi08/Enrollment System Web Database
8.7
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

Obi08/Enrollment System 1.0 contains a SQL injection vulnerability in the keyword parameter of /get_subject.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can use UNION-based injection to extract sensitive information from the users table including usernames and passwords.

CVE-2024-52302
Java-springboot-codebase Web
8.7
HIGH
EPSS
4.4%
2024 CWE-434 1 PoC

common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the application endpoint /api/v1/customer/profile-picture. This endpoint allows file uploads without proper validation or restrictions, enabling attackers to upload malicious files that can lead to Remote Code Execution (RCE).

CVE-2024-58314
100M IP Phones General
8.7
HIGH
EPSS
0.4%
2024 CWE-78 1 PoC

Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web configuration CGI script that allows attackers to execute arbitrary system commands. Attackers can inject shell commands through the 'cmd' parameter in web_cgi_main.cgi, enabling remote code execution with administrative credentials.

CVE-2024-58337
Akuvox Smart Doorphone Web
8.7
HIGH
EPSS
0.0%
2024 CWE-862 1 PoC

Akuvox Smart Intercom S539 contains an improper access control vulnerability that allows users with 'User' privileges to modify API access settings and configurations. Attackers can exploit this vulnerability to escalate privileges and gain unauthorized access to administrative functionalities.

CVE-2019-25255
VideoFlow Digital Video Protection DVP Web
8.7
HIGH
EPSS
0.1%
2019 CWE-78 3 PoCs

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows attackers to execute system commands with root privileges. Attackers can exploit the vulnerability through a cross-site request forgery (CSRF) mechanism to gain unauthorized system access.

CVE-2019-25552
CEWE PHOTO SHOW General
8.7
HIGH
EPSS
0.1%
2019 CWE-836 1 PoC

CEWE PHOTO SHOW 6.4.3 contains a denial of service vulnerability that allows attackers to crash the application by submitting an excessively long buffer to the password field. Attackers can paste a large string of repeated characters into the password input during the upload process to trigger an application crash.

CVE-2019-25470
eWON General
8.7
HIGH
EPSS
0.1%
2019 CWE-798 1 PoC

eWON Firmware versions 12.2 to 13.0 contain an authentication bypass vulnerability that allows attackers with minimal privileges to retrieve sensitive user data by exploiting the wsdReadForm endpoint. Attackers can send POST requests to /wrcgi.bin/wsdReadForm with base64-encoded partial credentials and a crafted wsdList parameter to extract encrypted passwords for all users, which can be decrypted using a hardcoded XOR key.

CVE-2019-25465
HiIpcam General
8.7
HIGH
EPSS
0.4%
2019 CWE-260 1 PoC

Hisilicon HiIpcam V100R003 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by exploiting directory listing in the cgi-bin directory. Attackers can request the getadslattr.cgi endpoint to retrieve ADSL credentials and network configuration parameters including usernames, passwords, and DNS settings.

CVE-2019-25358
FileOptimizer General
8.7
HIGH
EPSS
0.0%
2019 CWE-1282 1 PoC

FileOptimizer 14.00.2524 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the FileOptimizer32.ini configuration file. Attackers can overwrite the TempDirectory parameter with a 5000-character buffer to cause the application to crash when opening options.

CVE-2019-25647
PhreeBooks ERP Web
8.7
HIGH
EPSS
0.3%
2019 CWE-434 1 PoC

PhreeBooks ERP 5.2.3 contains a remote code execution vulnerability in the image manager that allows authenticated attackers to upload and execute arbitrary PHP files by bypassing file extension controls. Attackers can upload malicious PHP files through the image manager endpoint and execute them to establish reverse shell connections and execute system commands.

CVE-2019-25333
Momentum Series JAWS Web Cloud
8.7
HIGH
EPSS
0.8%
2019 CWE-22 1 PoC

Bullwark Momentum Series JAWS 1.0 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP request paths. Attackers can exploit the vulnerability by sending crafted GET requests with multiple '../' sequences to read sensitive files like /etc/passwd outside the web root directory.

CVE-2019-25237
SOL GPON/EPON OLT Platform Web
8.7
HIGH
EPSS
0.1%
2019 CWE-863 2 PoCs

V-SOL GPON/EPON OLT Platform v2.03 contains a privilege escalation vulnerability that allows normal users to gain administrative access by manipulating the user role parameter. Attackers can send a crafted HTTP POST request to the user management endpoint with 'user_role_mod' set to integer value '1' to elevate their privileges.

CVE-2019-25243
FaceSentry Access Control System Web
8.7
HIGH
EPSS
1.1%
2019 CWE-78 2 PoCs

FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters.