6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-27521
Software Genérico General
8.0
HIGH
EPSS
1.8%
2024 1 PoC

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parameters in the "setOpModeCfg" function. This security issue allows an attacker to take complete control of the device. In detail, exploitation allows unauthenticated, remote attackers to execute arbitrary system commands with administrative privileges (i.e., as user "root").

CVE-2024-21673
Confluence Data Center General
8.0
HIGH
EPSS
9.2%
2024 2 PoCs

This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.0 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H allows an authenticated attacker to expose assets in your environment susceptible to exploitation which has high impact to confidentiality, high impact to integrity, high impact to availability, and does not require user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version,

CVE-2024-50625
Software Genérico General
8.0
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation of file paths via POST requests. This can lead to arbitrary file uploads within specific directories, potentially enabling privilege escalation when combined with other vulnerabilities.

CVE-2024-46431
Software Genérico General
8.0
HIGH
EPSS
0.0%
2024 1 PoC

Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can exploit this vulnerability by sending specially crafted data to the delWewifiPic function.

CVE-2024-52022
Software Genérico General
8.0
HIGH
EPSS
0.4%
2024 1 PoC

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component wlg_adv.cgi via the apmode_gateway parameter. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-48638
Software Genérico Networking
8.0
HIGH
EPSS
0.8%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SubnetMask parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-44667
Software Genérico Networking
8.0
HIGH
EPSS
0.3%
2024 2 PoCs

Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads to information exposure and root shell access.

CVE-2024-44565
Software Genérico General
8.0
HIGH
EPSS
0.2%
2024 1 PoC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the serverName parameter in the function form_fast_setting_internet_set.

CVE-2024-20815
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

CVE-2024-51009
Software Genérico General
8.0
HIGH
EPSS
1.1%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at ether.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-42915
Software Genérico General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This will allow attackers to arbitrarily reset other users' passwords and compromise their accounts.

CVE-2024-41596
Software Genérico General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form parameters.

CVE-2024-48633
Software Genérico General
8.0
HIGH
EPSS
0.3%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtualServerSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-1845
VikRentCar Car Rental Management System Web Windows
8.0
HIGH
EPSS
0.3%
2024 1 PoC

The VikRentCar Car Rental Management System WordPress plugin before 1.3.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-52021
Software Genérico General
8.0
HIGH
EPSS
0.4%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at bsw_fix.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-4835
GitLab DevOps Web
8.0
HIGH
EPSS
7.5%
2024 CWE-79 1 PoC

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information.

CVE-2024-51186
Software Genérico General
8.0
HIGH
EPSS
1.3%
2024 1 PoC

D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 and ping_v6 functions.

CVE-2024-54887
Software Genérico General
8.0
HIGH
EPSS
1.3%
2024 1 PoC

TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the remote device in the context of the root user.

CVE-2024-52018
Software Genérico General
8.0
HIGH
EPSS
0.4%
2024 1 PoC

Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at genie_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-48093
Software Genérico General
8.0
HIGH
EPSS
3.8%
2024 1 PoC

Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Execution via uploading and executing malicious files without validating file extensions or content types.