3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-21537
lilconfig General
8.8
HIGH
EPSS
0.4%
2024 CWE-94 1 PoC

Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function. An attacker can exploit this vulnerability by passing a malicious input through the defaultLoaders function.

CVE-2024-4242
W9 General
8.8
HIGH
EPSS
0.4%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been rated as critical. This issue affects the function formwrlSSIDget of the file /goform/wifiSSIDget. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-262133 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-12695
Chrome General
8.8
HIGH
EPSS
2.2%
2024 CWE-787 1 PoC

Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2024-41226
Software Genérico Web
8.8
HIGH
EPSS
0.3%
2024 3 PoCs

A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes this report, arguing the attacker executes everything from the client side and does not attack the Control Room. The payload is being injected in the http Response from the client-side, so the owner of the Response and payload is the end user in this case. They contend that the server's security controls have no impact or role to play in this situation and therefore this is not a valid vulnerability.

CVE-2024-4020
FH1206 General
8.8
HIGH
EPSS
0.1%
2024 CWE-120 1 PoC

A vulnerability was found in Tenda FH1206 1.2.0.8(8155) and classified as critical. This issue affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument entrys leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261671. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-27655
Software Genérico General
8.8
HIGH
EPSS
2.6%
2024 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SOAPACTION parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.

CVE-2024-36821
Software Genérico General
8.8
HIGH
EPSS
13.1%
2024 1 PoC

Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.

CVE-2024-28066
Software Genérico General
8.8
HIGH
EPSS
0.0%
2024 2 PoCs

In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).

CVE-2024-48441
Software Genérico Networking
8.8
HIGH
EPSS
0.3%
2024 2 PoCs

Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.

CVE-2024-3217
WP Directory Kit Web Database Windows
8.8
HIGH
EPSS
52.9%
2024 CWE-89 1 PoC

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-44335
Software Genérico General
8.8
HIGH
EPSS
0.7%
2024 1 PoC

D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.

CVE-2024-6772
Chrome General
8.8
HIGH
EPSS
0.6%
2024 1 PoC

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2024-50488
Token Login General
8.8
HIGH
EPSS
26.5%
2024 CWE-288 1 PoC

Authentication Bypass Using an Alternate Path or Channel vulnerability in yespbs Token Login token-login allows Authentication Bypass.This issue affects Token Login: from n/a through <= 1.0.3.

CVE-2024-6075
wp-cart-for-digital-products Web Windows
8.8
HIGH
EPSS
0.4%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-38144
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
79.8%
2024 CWE-190 1 PoC

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

CVE-2024-1670
Chrome General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-5034
SULly Web Windows
8.8
HIGH
EPSS
0.2%
2024 1 PoC

The SULly WordPress plugin before 4.3.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-34221
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.

CVE-2024-5844
Chrome General
8.8
HIGH
EPSS
0.4%
2024 1 PoC

Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)