6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-54851
Software Genérico Web
8.8
HIGH
EPSS
0.0%
2024 1 PoC

Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.

CVE-2024-46429
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with administrative privileges.

CVE-2024-25386
Software Genérico General
8.8
HIGH
EPSS
9.5%
2024 1 PoC

Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file.

CVE-2024-58341
OpenCart Core Database
8.8
HIGH
EPSS
0.1%
2024 CWE-89 1 PoC

OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'search' parameter. Attackers can send GET requests to the product search endpoint with malicious 'search' values to extract sensitive database information using boolean-based blind or time-based blind SQL injection techniques.

CVE-2024-36984
Splunk Enterprise Windows
8.8
HIGH
EPSS
2.6%
2024 CWE-502 1 PoC

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use to serialize untrusted data. The attacker could use the query to execute arbitrary code.

CVE-2024-44381
Software Genérico Web
8.8
HIGH
EPSS
2.9%
2024 1 PoC

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.

CVE-2024-6022
ContentLock Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-0779
Enjoy Social Feed plugin for WordPress website Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation and CSRF in various function hooked to admin_init, allowing unauthenticated users to call them and unlink arbitrary users Instagram Account for example

CVE-2024-30973
Software Genérico Networking
8.8
HIGH
EPSS
0.8%
2024 2 PoCs

An issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code and obtain sensitive information via crafted POST request to /boaform/getASPdata/formFirewall, /boaform/getASPdata/formAcc.

CVE-2024-13146
Booknetic Web Windows
8.8
HIGH
EPSS
0.1%
2024 1 PoC

The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack

CVE-2024-7297
Software Genérico Web
8.8
HIGH
EPSS
0.3%
2024 CWE-913 1 PoC

Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing a mass assignment request on the '/api/v1/users' endpoint.

CVE-2024-0919
TEW-815DAP General
8.8
HIGH
EPSS
36.8%
2024 CWE-77 2 PoCs

A vulnerability was found in TRENDnet TEW-815DAP 1.0.2.0. It has been classified as critical. This affects the function do_setNTP of the component POST Request Handler. The manipulation of the argument NtpDstStart/NtpDstEnd leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252123. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-6605
Firefox General
8.8
HIGH
EPSS
0.6%
2024 1 PoC

Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.

CVE-2024-4119
W15E General
8.8
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda W15E 15.11.0.14. It has been declared as critical. This vulnerability affects the function formIPMacBindDel of the file /goform/delIpMacBind. The manipulation of the argument IPMacBindIndex leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-261862 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-38458
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Xenforo before 2.2.16 allows code injection.

CVE-2024-6990
Chrome General
8.8
HIGH
EPSS
0.3%
2024 CWE-457 1 PoC

Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

CVE-2024-5324
Waitlist Woocommerce ( Back in stock notifier ) Web Windows
8.8
HIGH
EPSS
43.7%
2024 CWE-862 1 PoC

Multiple plugins for WordPress utilizing the XootiX Framework are vulnerable to unauthorized modification of data due to a missing capability check on the 'import_settings' function in various versions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change arbitrary options on affected sites. This can be used to enable new user registration and set the default role for new users to Administrator.

CVE-2024-0750
Firefox General
8.8
HIGH
EPSS
1.5%
2024 1 PoC

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

CVE-2024-24725
Software Genérico Web
8.8
HIGH
EPSS
81.1%
2024 2 PoCs

Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.

CVE-2024-55354
Lucee Server General
8.8
HIGH
EPSS
0.1%
2024 CWE-807 1 PoC

Lucee before 5.4.7.3 LTS and 6 before 6.1.1.118, when an attacker can place files on the server, is vulnerable to a protection mechanism failure that can let an attacker run code that would be expected to be blocked and access resources that would be expected to be protected.