3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-3293
rtMedia for WordPress, BuddyPress and bbPress Web Database Windows
8.8
HIGH
EPSS
26.6%
2024 CWE-89 1 PoC

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to blind SQL Injection via the rtmedia_gallery shortcode in all versions up to, and including, 4.6.18 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-33894
Software Genérico Cloud
8.8
HIGH
EPSS
0.8%
2024 1 PoC

Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges.

CVE-2024-10771
SICK InspectorP61x General
8.8
HIGH
EPSS
4.5%
2024 CWE-94 1 PoC

Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code execution. With network access and the user level ”Service”, an attacker can execute arbitrary system commands in the root user’s contexts.

CVE-2024-9821
Bot for Telegram on WooCommerce Web Windows
8.8
HIGH
EPSS
47.6%
2024 CWE-200 1 PoC

The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'stm_wpcfto_get_settings' AJAX action in all versions up to, and including, 1.2.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to view the Telegram Bot Token, a secret token used to control the bot, which can then be used to log in as any existing user on the site, such as an administrator, if they know the username, due to the Login with Telegram feature.

CVE-2024-10487
Chrome General
8.8
HIGH
EPSS
0.3%
2024 CWE-787 1 PoC

Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

CVE-2024-5076
wp-eMember Web Windows
8.8
HIGH
EPSS
0.7%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-46625
Software Genérico General
8.8
HIGH
EPSS
0.3%
2024 1 PoC

An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted SVG file.

CVE-2024-2813
AC15 General
8.8
HIGH
EPSS
0.3%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda AC15 15.03.20_multi. It has been declared as critical. This vulnerability affects the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257668. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-51442
Software Genérico General
8.8
HIGH
EPSS
32.7%
2024 1 PoC

Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specially crafted minidlna.conf configuration file.

CVE-2024-56898
Software Genérico General
8.8
HIGH
EPSS
6.9%
2024 1 PoC

Broken access control vulnerability in Geovision GV-ASWeb with version v6.1.0.0 or less. This vulnerability allows low privilege users perform actions that they aren't authorized to, which can be leveraged to escalate privileges, create, modify or delete accounts.

CVE-2024-12381
Chrome General
8.8
HIGH
EPSS
6.6%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-27656
Software Genérico General
8.8
HIGH
EPSS
2.6%
2024 1 PoC

D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Cookie parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input, and possibly remote code execution.

CVE-2024-9602
Chrome General
8.8
HIGH
EPSS
0.4%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

CVE-2024-22106
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS).

CVE-2024-22899
Software Genérico General
8.8
HIGH
EPSS
21.2%
2024 2 PoCs

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

CVE-2024-26362
Software Genérico Windows
8.8
HIGH
EPSS
0.2%
2024 1 PoC

HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note.

CVE-2024-44341
Software Genérico General
8.8
HIGH
EPSS
3.8%
2024 2 PoCs

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.

CVE-2024-24328
Software Genérico General ⚡ nuclei
8.8
HIGH
EPSS
84.4%
2024 0 PoCs

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules function.

CVE-2024-6774
Chrome General
8.8
HIGH
EPSS
0.7%
2024 CWE-416 1 PoC

Use after free in Screen Capture in Google Chrome prior to 126.0.6478.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-21411
Skype for Consumer General
8.8
HIGH
EPSS
5.0%
2024 CWE-453 1 PoC

Skype for Consumer Remote Code Execution Vulnerability