3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-21112
VM VirtualBox Database
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availabili

CVE-2024-46625
Software Genérico General
8.8
HIGH
EPSS
0.3%
2024 1 PoC

An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted SVG file.

CVE-2024-5499
Chrome Web
8.8
HIGH
EPSS
1.3%
2024 1 PoC

Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2024-41226
Software Genérico Web
8.8
HIGH
EPSS
0.3%
2024 3 PoCs

A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes this report, arguing the attacker executes everything from the client side and does not attack the Control Room. The payload is being injected in the http Response from the client-side, so the owner of the Response and payload is the end user in this case. They contend that the server's security controls have no impact or role to play in this situation and therefore this is not a valid vulnerability.

CVE-2024-0745
Firefox General
8.8
HIGH
EPSS
0.8%
2024 1 PoC

The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 122.

CVE-2024-50626
Software Genérico General
8.8
HIGH
EPSS
0.3%
2024 1 PoC

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This allows an attacker on the local area network to manipulate URLs to include traversal sequences, potentially leading to unauthorized access to data.

CVE-2024-48419
Software Genérico Networking
8.8
HIGH
EPSS
3.6%
2024 1 PoC

Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an attacker with access to the web interface to inject and execute arbitrary shell commands, with "root" privileges.

CVE-2024-3856
Firefox General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 125.

CVE-2024-6100
Chrome General
8.8
HIGH
EPSS
0.7%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVE-2024-34310
Software Genérico Database
8.8
HIGH
EPSS
0.4%
2024 1 PoC

Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter.

CVE-2024-55270
Software Genérico Web Database
8.8
HIGH
EPSS
0.0%
2024 1 PoC

phpgurukul Student Management System 1.0 is vulnerable to SQL Injection in studentms/admin/search.php via the searchdata parameter.

CVE-2024-3169
Chrome General
8.8
HIGH
EPSS
0.7%
2024 1 PoC

Use after free in V8 in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-34942
Software Genérico General
8.8
HIGH
EPSS
0.3%
2024 1 PoC

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/exeCommand.

CVE-2024-48271
Software Genérico General
8.8
HIGH
EPSS
0.0%
2024 1 PoC

D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device via a bruteforce attack.

CVE-2024-4493
i21 General
8.8
HIGH
EPSS
0.2%
2024 CWE-121 1 PoC

A vulnerability, which was classified as critical, was found in Tenda i21 1.0.0.14(4656). Affected is the function formSetAutoPing. The manipulation of the argument ping1/ping2 leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-263082 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-54498
macOS General
8.8
HIGH
EPSS
8.1%
2024 1 PoC

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to break out of its sandbox.

CVE-2024-5847
Chrome General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

CVE-2024-45352
Xiaomi smarthome application General
8.8
HIGH
EPSS
0.0%
2024 CWE-346 3 PoCs

An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.

CVE-2024-46624
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2024 1 PoC

An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via a crafted payload sent to /api/users.

CVE-2024-5792
Houzez CRM Web Database Windows
8.8
HIGH
EPSS
0.5%
2024 CWE-89 1 PoC

The Houzez CRM plugin for WordPress is vulnerable to time-based SQL Injection via the notes ‘belong_to’ parameter in all versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Custom-level (seller) access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.