3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-0852
coreActivity: Activity Logging for WordPress Web Windows
8.8
HIGH
EPSS
2.9%
2024 1 PoC

The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated users to perform Stored XSS attack against high privilege users such as admin

CVE-2024-2984
FH1202 General
8.8
HIGH
EPSS
0.6%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been classified as critical. This affects the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-258153 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-27497
Software Genérico General ⚡ nuclei
8.8
HIGH
EPSS
81.9%
2024 0 PoCs

Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.

CVE-2024-11691
Firefox General
8.8
HIGH
EPSS
0.2%
2024 2 PoCs

Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, Thunderbird < 128.5, and Thunderbird < 115.18.

CVE-2024-26198
Microsoft Exchange Server 2019 Cumulative Update 14 Windows
8.8
HIGH
EPSS
2.7%
2024 CWE-426 2 PoCs

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2024-6974
SDP Client Windows
8.8
HIGH
EPSS
0.1%
2024 CWE-426 1 PoC

Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34.

CVE-2024-8504
VICIdial General
8.8
HIGH
EPSS
93.1%
2024 CWE-78 3 PoCs

An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.

CVE-2024-51144
Software Genérico Web
8.8
HIGH
EPSS
3.1%
2024 2 PoCs

Cross Site Request Forgery (CSRF) vulnerability exists in the 'pvmsg.php?action=add_message', pvmsg.php?action=confirm_delete , and ajax.server.php?page=user&action=flip_follow endpoints in Ampache <= 6.6.0.

CVE-2024-44381
Software Genérico Web
8.8
HIGH
EPSS
2.9%
2024 1 PoC

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.

CVE-2024-1138
TIBCO FTL - Enterprise Edition General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected releases are TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition: versions 6.10.1 and below.

CVE-2024-39924
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It permits an attacker with granted emergency access to escalate their privileges by changing the access level and modifying the wait time. Consequently, the attacker can gain full control over the vault (when only intended to have read access) while bypassing the necessary wait period.

CVE-2024-22106
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS).

CVE-2024-29509
Software Genérico General
8.8
HIGH
EPSS
2.1%
2024 2 PoCs

Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.

CVE-2024-33894
Software Genérico Cloud
8.8
HIGH
EPSS
0.8%
2024 1 PoC

Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges.

CVE-2024-9821
Bot for Telegram on WooCommerce Web Windows
8.8
HIGH
EPSS
47.6%
2024 CWE-200 1 PoC

The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'stm_wpcfto_get_settings' AJAX action in all versions up to, and including, 1.2.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to view the Telegram Bot Token, a secret token used to control the bot, which can then be used to log in as any existing user on the site, such as an administrator, if they know the username, due to the Login with Telegram feature.

CVE-2024-7256
Chrome General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVE-2024-5076
wp-eMember Web Windows
8.8
HIGH
EPSS
0.7%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-2813
AC15 General
8.8
HIGH
EPSS
0.3%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda AC15 15.03.20_multi. It has been declared as critical. This vulnerability affects the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257668. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-51442
Software Genérico General
8.8
HIGH
EPSS
32.7%
2024 1 PoC

Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specially crafted minidlna.conf configuration file.

CVE-2024-2018
WP Activity Log Premium Web Database Windows
8.8
HIGH
EPSS
0.5%
2024 CWE-89 1 PoC

The WP Activity Log Premium plugin for WordPress is vulnerable to SQL Injection via the entry->roles parameter in all versions up to, and including, 4.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with subscriber privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. One demonstrated attack included the injection of a PHP Object.