6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-5290
wpa_supplicant General
8.8
HIGH
EPSS
0.3%
2024 CWE-427 2 PoCs

An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root). Membership in the netdev group or access to the dbus interface of wpa_supplicant allow an unprivileged user to specify an arbitrary path to a module to be loaded by the wpa_supplicant process; other escalation paths might exist.

CVE-2024-33181
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceMac parameter at ip/goform/addWifiMacFilter.

CVE-2024-4493
i21 General
8.8
HIGH
EPSS
0.2%
2024 CWE-121 1 PoC

A vulnerability, which was classified as critical, was found in Tenda i21 1.0.0.14(4656). Affected is the function formSetAutoPing. The manipulation of the argument ping1/ping2 leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263082 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-7479
Remote Full Client Networking Windows
8.8
HIGH
EPSS
5.9%
2024 CWE-347 2 PoCs

Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install drivers.

CVE-2024-3516
Chrome General
8.8
HIGH
EPSS
0.7%
2024 1 PoC

Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-11394
Transformers General
8.8
HIGH
EPSS
65.0%
2024 CWE-502 1 PoC

Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of model files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerabilit

CVE-2024-57046
Software Genérico Networking ⚡ nuclei
8.8
HIGH
EPSS
46.7%
2024 1 PoC

A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.

CVE-2024-9955
Chrome General
8.8
HIGH
EPSS
33.5%
2024 CWE-416 1 PoC

Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-6756
Social Auto Poster Web Windows
8.8
HIGH
EPSS
11.9%
2024 CWE-434 1 PoC

The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_image_path' function in all versions up to, and including, 5.3.14. This makes it possible for authenticated attackers, with Contributor-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible. An attacker can use CVE-2024-6754 to exploit with subscriber-level access.

CVE-2024-39091
Software Genérico General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary code via a crafted HTML request.

CVE-2024-33894
Software Genérico Cloud
8.8
HIGH
EPSS
0.8%
2024 1 PoC

Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges.

CVE-2024-9603
Chrome General
8.8
HIGH
EPSS
0.1%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-9602
Chrome General
8.8
HIGH
EPSS
0.4%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVE-2024-8638
Chrome General
8.8
HIGH
EPSS
0.1%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-3875
F1202 General
8.8
HIGH
EPSS
0.5%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda F1202 1.2.0.20(408). It has been rated as critical. This issue affects the function fromNatlimit of the file /goform/Natlimit. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-260909 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-45181
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70. An improper bounds check allows crafted packets to cause an arbitrary address write, resulting in kernel memory corruption.

CVE-2024-0852
coreActivity: Activity Logging for WordPress Web Windows
8.8
HIGH
EPSS
2.9%
2024 1 PoC

The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated users to perform Stored XSS attack against high privilege users such as admin

CVE-2024-44382
Software Genérico Web
8.8
HIGH
EPSS
0.8%
2024 1 PoC

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.

CVE-2024-2485
AC18 General
8.8
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda AC18 15.03.05.05 and classified as critical. Affected by this issue is the function formSetSpeedWan of the file /goform/SetSpeedWan. The manipulation of the argument speed_dir leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-256892. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-21411
Skype for Consumer General
8.8
HIGH
EPSS
5.0%
2024 CWE-453 1 PoC

Skype for Consumer Remote Code Execution Vulnerability