3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-48419
Software Genérico Networking
8.8
HIGH
EPSS
3.6%
2024 1 PoC

Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an attacker with access to the web interface to inject and execute arbitrary shell commands, with "root" privileges.

CVE-2024-10488
Chrome General
8.8
HIGH
EPSS
0.4%
2024 CWE-416 1 PoC

Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-3406
WP Prayer Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-54379
Minterpress General
8.8
HIGH
EPSS
2.1%
2024 CWE-862 1 PoC

Missing Authorization vulnerability in blokhauswp Minterpress minterpress allows Privilege Escalation.This issue affects Minterpress: from n/a through <= 1.0.5.

CVE-2024-7022
Chrome General
8.8
HIGH
EPSS
0.2%
2024 CWE-457 1 PoC

Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-6101
Chrome General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2024-3834
Chrome General
8.8
HIGH
EPSS
1.2%
2024 2 PoCs

Use after free in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-7479
Remote Full Client Networking Windows
8.8
HIGH
EPSS
5.9%
2024 CWE-347 2 PoCs

Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install drivers.

CVE-2024-22145
InstaWP Connect General
8.8
HIGH
EPSS
48.9%
2024 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.

CVE-2024-5720
Unified SecOps Platform Web
8.8
HIGH
EPSS
1.0%
2024 CWE-78 1 PoC

Logsign Unified SecOps Platform Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the implementation of the HTTP API. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the con

CVE-2024-25251
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.

CVE-2024-42658
Software Genérico Networking
8.8
HIGH
EPSS
14.4%
2024 2 PoCs

An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information via the cookie's parameter

CVE-2024-41969
CC100 0751-9x01 General
8.8
HIGH
EPSS
1.2%
2024 CWE-306 1 PoC

A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS.

CVE-2024-36597
Software Genérico Web Database
8.8
HIGH
EPSS
87.0%
2024 1 PoC

Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.

CVE-2024-44333
Software Genérico General
8.8
HIGH
EPSS
0.7%
2024 1 PoC

D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution. An attacker can achieve arbitrary command execution by sending a carefully crafted malicious string to the CGI function responsible for handling usb_paswd.asp.

CVE-2024-24409
ADManager Plus General
8.8
HIGH
EPSS
8.3%
2024 CWE-269 1 PoC

Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.

CVE-2024-8193
Chrome General
8.8
HIGH
EPSS
0.7%
2024 CWE-122 2 PoCs

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-3833
Chrome General
8.8
HIGH
EPSS
3.1%
2024 1 PoC

Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-7969
Chrome General
8.8
HIGH
EPSS
0.2%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-3281
Poly CCX devices General
8.8
HIGH
EPSS
0.3%
2024 1 PoC

A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in the firmware build process did not properly restrict access to a resource from an unauthorized actor.