3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-1675
Chrome General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-9954
Chrome General
8.8
HIGH
EPSS
6.5%
2024 CWE-416 3 PoCs

Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-10230
Chrome General
8.8
HIGH
EPSS
0.2%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-7968
Chrome General
8.8
HIGH
EPSS
1.3%
2024 CWE-416 1 PoC

Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-9890
User Toolkit Web Windows
8.8
HIGH
EPSS
14.5%
2024 CWE-288 1 PoC

The User Toolkit plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.3. This is due to an improper capability check in the 'switchUser' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator. CVE-2024-50503 may be a duplicate.

CVE-2024-6101
Chrome General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2024-21345
Windows Server 2022, 23H2 Edition (Server Core installation) Windows
8.8
HIGH
EPSS
31.9%
2024 CWE-122 2 PoCs

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-6075
wp-cart-for-digital-products Web Windows
8.8
HIGH
EPSS
0.4%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-55506
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter.

CVE-2024-5844
Chrome General
8.8
HIGH
EPSS
0.4%
2024 1 PoC

Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-22515
Software Genérico General
8.8
HIGH
EPSS
13.7%
2024 1 PoC

Unrestricted File Upload vulnerability in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to upload arbitrary files via the upload audio component.

CVE-2024-3193
MailCleaner General
8.8
HIGH
EPSS
2.2%
2024 CWE-78 1 PoC

A vulnerability has been found in MailCleaner up to 2023.03.14 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Admin Endpoints. The manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier VDB-262309 was assigned to this vulnerability.

CVE-2024-0692
Security Event Manager General ⚡ nuclei
8.8
HIGH
EPSS
78.3%
2024 CWE-502 0 PoCs

The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.

CVE-2024-1655
ExpertWiFi EBM63 Networking
8.8
HIGH
EPSS
14.6%
2024 CWE-78 1 PoC

Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system commands by sending a specially crafted request.

CVE-2024-7646
ingress-nginx Web
8.8
HIGH
EPSS
22.2%
2024 CWE-20 4 PoCs

A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.

CVE-2024-55517
Software Genérico Database
8.8
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the groupType parameter in /SCGController is mishandled before being used in SQL queries, allowing SQL injection in an authenticated session.

CVE-2024-6132
Pexels: Free Stock Photos Web Windows
8.8
HIGH
EPSS
48.1%
2024 CWE-434 1 PoC

The Pexels: Free Stock Photos plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'pexels_fsp_images_options_validate' function in all versions up to, and including, 1.2.2. This makes it possible for authenticated attackers, with contributor-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-3406
WP Prayer Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-48416
Software Genérico Networking
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/fromSetLanDhcpsClientbinding.