6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-46429
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with administrative privileges.

CVE-2024-25092
NextMove Lite General
8.8
HIGH
EPSS
71.4%
2024 CWE-862 2 PoCs

Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0.

CVE-2024-41992
Software Genérico General
8.8
HIGH
EPSS
27.9%
2024 1 PoC

Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP port 8000 or 8080 on a LAN interface. On other devices, this may be exploitable over a WAN interface.

CVE-2024-12471
Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator Web Windows
8.8
HIGH
EPSS
62.7%
2024 CWE-94 1 PoC

The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is vulnerable to arbitrary files uploads due to a missing capability check and file type validation on the add_image_to_library AJAX action function in all versions up to, and including, 1.3.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files that make remote code execution possible.

CVE-2024-22263
Spring Cloud Skipper DevOps Web Cloud
8.8
HIGH
EPSS
77.7%
2024 1 PoC

Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The Skipper server has the ability to receive upload package requests. However, due to improper sanitization for upload path, a malicious user who has access to skipper server api can use a crafted upload request to write arbitrary file to any location on file system, may even compromises the server.

CVE-2024-6995
Chrome General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-40548
Software Genérico Web
8.8
HIGH
EPSS
0.3%
2024 1 PoC

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-46626
Software Genérico Database
8.8
HIGH
EPSS
0.3%
2024 1 PoC

OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.

CVE-2024-41622
Software Genérico General
8.8
HIGH
EPSS
1.7%
2024 2 PoCs

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.

CVE-2024-40474
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2024 1 PoC

A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0.

CVE-2024-37758
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attackers to escalate privileges.

CVE-2024-48217
Software Genérico General
8.8
HIGH
EPSS
1.4%
2024 1 PoC

An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.

CVE-2024-53376
Software Genérico Web
8.8
HIGH
EPSS
91.2%
2024 3 PoCs

CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.

CVE-2024-12053
Chrome General
8.8
HIGH
EPSS
0.1%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-4237
AX1806 General
8.8
HIGH
EPSS
0.3%
2024 CWE-121 1 PoC

A vulnerability, which was classified as critical, was found in Tenda AX1806 1.0.0.1. Affected is the function R7WebsSecurityHandler of the file /goform/execCommand. The manipulation of the argument password leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-262128. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-2174
Chrome General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-28888
Foxit Reader Web
8.8
HIGH
EPSS
4.1%
2024 CWE-416 3 PoCs

A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2024-6975
SDP Client Windows
8.8
HIGH
EPSS
0.1%
2024 CWE-426 1 PoC

Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34.

CVE-2024-27656
Software Genérico General
8.8
HIGH
EPSS
2.6%
2024 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Cookie parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.

CVE-2024-29988
🔥 KEV Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
60.5%
2024 CWE-693 2 PoCs

SmartScreen Prompt Security Feature Bypass Vulnerability