3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-48635
Software Genérico General
8.0
HIGH
EPSS
0.8%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:2/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-20816
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

CVE-2024-48631
Software Genérico General
8.0
HIGH
EPSS
0.8%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-51021
Software Genérico General
8.0
HIGH
EPSS
0.4%
2024 1 PoC

Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a command injection vulnerability via the wan_gateway parameter at genie_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-41588
Software Genérico General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strncpy function.

CVE-2024-54954
Software Genérico General
8.0
HIGH
EPSS
0.8%
2024 1 PoC

OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.

CVE-2024-52550
Jenkins Pipeline: Groovy Plugin DevOps
8.0
HIGH
EPSS
1.4%
2024 1 PoC

Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved.

CVE-2024-41596
Software Genérico General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form parameters.

CVE-2024-42845
Software Genérico General
8.0
HIGH
EPSS
71.1%
2024 2 PoCs

An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to execute arbitrary code via loading a crafted DICOM file.

CVE-2024-52019
Software Genérico General
8.0
HIGH
EPSS
0.4%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at genie_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-41595
Software Genérico General
8.0
HIGH
EPSS
0.4%
2024 1 PoC

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cgi pages because of missing bounds checks on read and write operations.

CVE-2024-27521
Software Genérico General
8.0
HIGH
EPSS
1.8%
2024 1 PoC

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parameters in the "setOpModeCfg" function. This security issue allows an attacker to take complete control of the device. In detail, exploitation allows unauthenticated, remote attackers to execute arbitrary system commands with administrative privileges (i.e., as user "root").

CVE-2024-28157
Jenkins GitBucket Plugin DevOps Web
8.0
HIGH
EPSS
3.7%
2024 1 PoC

Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.

CVE-2024-21673
Confluence Data Center General
8.0
HIGH
EPSS
9.2%
2024 2 PoCs

This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.0 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H allows an authenticated attacker to expose assets in your environment susceptible to exploitation which has high impact to confidentiality, high impact to integrity, high impact to availability, and does not require user interaction. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version,

CVE-2024-48093
Software Genérico General
8.0
HIGH
EPSS
3.8%
2024 1 PoC

Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Execution via uploading and executing malicious files without validating file extensions or content types.

CVE-2024-46486
Software Genérico Web
8.0
HIGH
EPSS
1.7%
2024 1 PoC

TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.

CVE-2024-50625
Software Genérico General
8.0
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation of file paths via POST requests. This can lead to arbitrary file uploads within specific directories, potentially enabling privilege escalation when combined with other vulnerabilities.

CVE-2024-48634
Software Genérico General
8.0
HIGH
EPSS
3.7%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the key parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-51005
Software Genérico Windows
8.0
HIGH
EPSS
0.7%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-51240
Software Genérico Web
8.0
HIGH
EPSS
0.0%
2024 1 PoC

An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc package