6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-2896
AC7 General
8.8
HIGH
EPSS
0.6%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. This issue affects the function formWifiWpsStart of the file /goform/WifiWpsStart. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-257939. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-55506
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter.

CVE-2024-0538
W9 Web
8.8
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability has been found in Tenda W9 1.0.0.7(4456) and classified as critical. This vulnerability affects the function formQosManage_auto of the component httpd. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250708. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-12920
FoodBakery | Delivery Restaurant Directory WordPress Theme Web Windows
8.8
HIGH
EPSS
0.2%
2024 CWE-862 1 PoC

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the foodbakery_var_backup_file_delete, foodbakery_widget_file_delete, theme_option_save, export_widget_settings, ajax_import_widget_data, foodbakery_var_settings_backup_generate, foodbakery_var_backup_file_restore, and theme_option_rest_all functions in all versions up to, and including, 4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary file

CVE-2024-6075
wp-cart-for-digital-products Web Windows
8.8
HIGH
EPSS
0.4%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-24409
ADManager Plus General
8.8
HIGH
EPSS
8.3%
2024 CWE-269 1 PoC

Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.

CVE-2024-0519
🔥 KEV Chrome General
8.8
HIGH
EPSS
0.4%
2024 2 PoCs

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-1755
NPS computy Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The NPS computy WordPress plugin through 2.7.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-5720
Unified SecOps Platform Web
8.8
HIGH
EPSS
1.0%
2024 CWE-78 1 PoC

Logsign Unified SecOps Platform Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the implementation of the HTTP API. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the con

CVE-2024-48292
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An issue in the wssrvc.exe service of QuickHeal Antivirus Pro Version v24.0 and Quick Heal Total Security v24.0 allows authenticated attackers to escalate privileges.

CVE-2024-7519
Firefox General
8.8
HIGH
EPSS
0.4%
2024 1 PoC

Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

CVE-2024-38189
🔥 KEV Microsoft Office 2019 General
8.8
HIGH
EPSS
43.7%
2024 CWE-20 1 PoC

Microsoft Project Remote Code Execution Vulnerability

CVE-2024-1672
Chrome General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-45171
Software Genérico Web
8.8
HIGH
EPSS
0.5%
2024 4 PoCs

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to upload dangerous files, for instance PHP code, to the C-MOR system. By analyzing the C-MOR web interface, it was found out that the upload functionality for backup files allows an authenticated user to upload arbitrary files. The only condition is that the filename contains a .cbkf string. Therefore, webshell.cbkf.php is considered a valid file name for the C-MOR web application. Uploaded files are stored within the directory "/srv/www/backups" on the C-MOR system, a

CVE-2024-11075
SICK Incoming Goods Suite DevOps Networking
8.8
HIGH
EPSS
0.1%
2024 CWE-250 1 PoC

A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local or via SSH) a privilege escalation to the administrative level due to the usage of component vendor Docker images running with root permissions. Exploiting this misconfiguration leads to the fact that an attacker can gain administrative control. over the whole system.

CVE-2024-22145
InstaWP Connect General
8.8
HIGH
EPSS
48.9%
2024 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.

CVE-2024-25251
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.

CVE-2024-34448
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Ghost before 5.82.0 allows CSV Injection during a member CSV export.

CVE-2024-28983
Pentaho Business Analytics Server General
8.8
HIGH
EPSS
0.5%
2024 CWE-79 1 PoC

Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.

CVE-2024-2486
AC18 General
8.8
HIGH
EPSS
0.5%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda AC18 15.03.05.05. It has been classified as critical. This affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-256893 was assigned to this vulnerability.