6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-22514
Software Genérico General
8.8
HIGH
EPSS
17.6%
2024 1 PoC

An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.

CVE-2024-42902
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the js_localize.php function

CVE-2024-22903
Software Genérico General
8.8
HIGH
EPSS
3.9%
2024 1 PoC

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.

CVE-2024-8637
Chrome Networking
8.8
HIGH
EPSS
0.3%
2024 CWE-416 1 PoC

Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-38144
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
79.8%
2024 CWE-190 1 PoC

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

CVE-2024-36787
Software Genérico General
8.8
HIGH
EPSS
0.0%
2024 1 PoC

An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspecified vectors.

CVE-2024-31842
Software Genérico General
8.8
HIGH
EPSS
0.3%
2024 1 PoC

An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string for the URL could be saved in the browser's history, passed through Referers to other web sites, stored in web logs, or otherwise recorded in other sources. If the query string contains sensitive information such as session identifiers, then attackers can use this information to launch further attacks. Because the access token in sent in GET requests, this vulnerability could lead to complete account takeover.

CVE-2024-54379
Minterpress General
8.8
HIGH
EPSS
2.1%
2024 CWE-862 1 PoC

Missing Authorization vulnerability in blokhauswp Minterpress minterpress allows Privilege Escalation.This issue affects Minterpress: from n/a through <= 1.0.5.

CVE-2024-3834
Chrome General
8.8
HIGH
EPSS
1.2%
2024 2 PoCs

Use after free in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-41969
CC100 0751-9x01 General
8.8
HIGH
EPSS
1.2%
2024 CWE-306 1 PoC

A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS.

CVE-2024-3281
Poly CCX devices General
8.8
HIGH
EPSS
0.3%
2024 1 PoC

A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process did not properly restrict access to a resource from an unauthorized actor.

CVE-2024-25723
Software Genérico Web ⚡ nuclei
8.8
HIGH
EPSS
86.8%
2024 1 PoC

ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on the basis of a valid username along with a new password in the request body. These are also patched versions: 0.44.4, 0.43.1, and 0.42.2.

CVE-2024-12920
FoodBakery | Delivery Restaurant Directory WordPress Theme Web Windows
8.8
HIGH
EPSS
0.2%
2024 CWE-862 1 PoC

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save, export_widget_settings, ajax_import_widget_data, foodbakery_var_settings_backup_generate, foodbakery_var_backup_file_restore, and theme_option_rest_all functions in all versions up to, and including, 4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary file

CVE-2024-0519
🔥 KEV Chrome General
8.8
HIGH
EPSS
0.4%
2024 2 PoCs

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-38189
🔥 KEV Microsoft Office 2019 General
8.8
HIGH
EPSS
43.7%
2024 CWE-20 1 PoC

Microsoft Project Remote Code Execution Vulnerability

CVE-2024-1672
Chrome General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-11075
SICK Incoming Goods Suite DevOps Networking
8.8
HIGH
EPSS
0.1%
2024 CWE-250 1 PoC

A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact that an attacker can gain administrative control. over the whole system.

CVE-2024-11393
Transformers General
8.8
HIGH
EPSS
79.5%
2024 CWE-502 1 PoC

Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of model files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnera

CVE-2024-3807
Porto Web Windows
8.8
HIGH
EPSS
5.5%
2024 CWE-98 1 PoC

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'porto_page_header_shortcode_type', 'slideshow_type' and 'post_layout' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included. This was partially patched in version 7.1.0

CVE-2024-33212
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter in ip/goform/setcfm.