6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-41588
Software Genérico General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strncpy function.

CVE-2024-54954
Software Genérico General
8.0
HIGH
EPSS
0.8%
2024 1 PoC

OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.

CVE-2024-42845
Software Genérico General
8.0
HIGH
EPSS
71.1%
2024 2 PoCs

An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to execute arbitrary code via loading a crafted DICOM file.

CVE-2024-28157
Jenkins GitBucket Plugin DevOps Web
8.0
HIGH
EPSS
3.7%
2024 1 PoC

Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.

CVE-2024-51240
Software Genérico Web
8.0
HIGH
EPSS
0.0%
2024 1 PoC

An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc package

CVE-2024-12693
Chrome General
8.0
HIGH
EPSS
2.5%
2024 1 PoC

Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2024-52951
Software Genérico Web
8.0
HIGH
EPSS
0.1%
2024 3 PoCs

Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History

CVE-2024-7059
Genetec Security Center General
8.0
HIGH
EPSS
0.4%
2024 CWE-470 1 PoC

A high-severity vulnerability that can lead to arbitrary code execution on the system hosting the Web SDK role was found in the Genetec Security Center product line.

CVE-2024-46435
Software Genérico General
8.0
HIGH
EPSS
1.7%
2024 1 PoC

A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote attacker to cause a denial of service or potentially execute arbitrary code. This vulnerability occurs due to improper input validation when handling user-supplied data in the delFacebookPic function.

CVE-2024-52020
Software Genérico General
8.0
HIGH
EPSS
0.4%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at wiz_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-44563
Software Genérico General
8.0
HIGH
EPSS
0.2%
2024 1 PoC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.

CVE-2024-46658
Software Genérico General
8.0
HIGH
EPSS
32.6%
2024 1 PoC

Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.

CVE-2024-33788
Software Genérico Web
8.0
HIGH
EPSS
2.6%
2024 1 PoC

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.

CVE-2024-44815
Software Genérico Networking
8.0
HIGH
EPSS
10.8%
2024 1 PoC

Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.

CVE-2024-53375
Software Genérico Networking
8.0
HIGH
EPSS
70.7%
2024 1 PoC

An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exists in the "tmp_get_sites" function of the HomeShield functionality provided by TP-Link. This vulnerability is still exploitable without the activation of the HomeShield functionality.

CVE-2024-33438
Software Genérico General
8.0
HIGH
EPSS
0.2%
2024 1 PoC

File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.

CVE-2024-45264
Software Genérico Web
8.0
HIGH
EPSS
9.3%
2024 1 PoC

A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges.

CVE-2024-6508
Software Genérico Web
8.0
HIGH
EPSS
1.0%
2024 CWE-331 1 PoC

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.

CVE-2024-51021
Software Genérico General
8.0
HIGH
EPSS
0.4%
2024 1 PoC

Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a command injection vulnerability via the wan_gateway parameter at genie_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-52019
Software Genérico General
8.0
HIGH
EPSS
0.4%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at genie_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.