3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-55544
IAP-420 General
8.7
HIGH
EPSS
21.2%
2024 CWE-77 2 PoCs

Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.01e and below.

CVE-2024-11274
GitLab DevOps
8.7
HIGH
EPSS
0.4%
2024 CWE-601 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.

CVE-2024-7737
3DSwymer Web
8.7
HIGH
EPSS
0.1%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-3594
IDonate Web Windows
8.7
HIGH
EPSS
1.0%
2024 1 PoC

The IDonate WordPress plugin through 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-8576
AC1200 T8 General
8.7
HIGH
EPSS
0.3%
2024 CWE-120 1 PoC

A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been classified as critical. Affected is the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument desc leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-11959
DIR-605L General
8.7
HIGH
EPSS
3.1%
2024 CWE-120 2 PoCs

A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function formResetStatistic of the file /goform/formResetStatistic. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-12092
ENOVIA Collaborative Industry Innovator Web
8.7
HIGH
EPSS
1.5%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-10345
Helix Core General
8.7
HIGH
EPSS
0.7%
2024 CWE-400 1 PoC

In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karol Więsek.

CVE-2024-9786
DIR-619L B1 General
8.7
HIGH
EPSS
0.3%
2024 CWE-120 1 PoC

A vulnerability, which was classified as critical, has been found in D-Link DIR-619L B1 2.06. Affected by this issue is the function formSetLog of the file /goform/formSetLog. The manipulation of the argument curTime leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-52301
framework Web
8.7
HIGH
EPSS
65.7%
2024 CWE-88 3 PoCs

Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0. The framework now ignores argv values for environment detection on non-cli SAPIs.

CVE-2024-6378
ENOVIA Collaborative Industry Innovator Web
8.7
HIGH
EPSS
1.3%
2024 CWE-79 1 PoC

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-58277
Radio Network FM Transmitter General
8.7
HIGH
EPSS
0.2%
2024 CWE-312 2 PoCs

R Radio Network FM Transmitter 1.07 allows unauthenticated attackers to access the admin user's password through the system.cgi endpoint, enabling authentication bypass and FM station setup access.

CVE-2024-7463
CP900 General
8.7
HIGH
EPSS
9.9%
2024 CWE-120 1 PoC

A vulnerability classified as critical was found in TOTOLINK CP900 6.3c.566. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273556. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-8575
AC1200 T8 General
8.7
HIGH
EPSS
0.3%
2024 CWE-120 1 PoC

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220 and classified as critical. This issue affects the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument desc leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-58311
Dormakaba Saflok System 6000 General
8.7
HIGH
EPSS
0.1%
2024 CWE-1245 1 PoC

Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique identifier. Attackers can exploit the deterministic key generation process by calculating valid access keys using a simple mathematical transformation of the card's unique identifier.

CVE-2024-13982
SPON IP Network Broadcast System Web
8.7
HIGH
EPSS
2.4%
2024 CWE-22 1 PoC

SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an arbitrary file read vulnerability in the rj_get_token.php endpoint. The flaw arises from insufficient input validation on the jsondata[url] parameter, which allows attackers to perform directory traversal and access sensitive files on the server. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted POST request to read arbitrary files, potentially exposing system configuration, credentials, or internal logic. An affected version range is undefi

CVE-2024-43685
TimeProvider 4100 General
8.7
HIGH
EPSS
0.8%
2024 CWE-613 1 PoC

Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

CVE-2024-11960
DIR-605L General
8.7
HIGH
EPSS
3.1%
2024 CWE-120 1 PoC

A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the function formSetPortTr of the file /goform/formSetPortTr. The manipulation of the argument curTime leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-13986
Nagios XI Web Cloud
8.7
HIGH
EPSS
2.4%
2024 CWE-434 2 PoCs

Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Core Config Snapshots interface. The issue arises from insufficient validation of file paths and extensions during MIB upload and snapshot rename operations. Exploitation results in the placement of attacker-controlled PHP files in a web-accessible directory, executed as the www-data user.

CVE-2024-7932
3DSwymer Web
8.7
HIGH
EPSS
0.9%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.