3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-51005
Software Genérico Windows
8.0
HIGH
EPSS
0.7%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-51240
Software Genérico Web
8.0
HIGH
EPSS
0.0%
2024 1 PoC

An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc package

CVE-2024-41596
Software Genérico General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form parameters.

CVE-2024-12693
Chrome General
8.0
HIGH
EPSS
2.5%
2024 1 PoC

Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2024-46431
Software Genérico General
8.0
HIGH
EPSS
0.0%
2024 1 PoC

Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can exploit this vulnerability by sending specially crafted data to the delWewifiPic function.

CVE-2024-52951
Software Genérico Web
8.0
HIGH
EPSS
0.1%
2024 3 PoCs

Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History

CVE-2024-13918
Laravel Framework Web
8.0
HIGH
EPSS
1.1%
2024 CWE-79 1 PoC

The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request parameters in the debug-mode error page.

CVE-2024-48093
Software Genérico General
8.0
HIGH
EPSS
3.8%
2024 1 PoC

Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Execution via uploading and executing malicious files without validating file extensions or content types.

CVE-2024-7059
Genetec Security Center General
8.0
HIGH
EPSS
0.4%
2024 CWE-470 1 PoC

A high-severity vulnerability that can lead to arbitrary code execution on the system hosting the Web SDK role was found in the Genetec Security Center product line.

CVE-2024-52022
Software Genérico General
8.0
HIGH
EPSS
0.4%
2024 1 PoC

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component wlg_adv.cgi via the apmode_gateway parameter. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-48638
Software Genérico Networking
8.0
HIGH
EPSS
0.8%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SubnetMask parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-44667
Software Genérico Networking
8.0
HIGH
EPSS
0.3%
2024 2 PoCs

Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads to information exposure and root shell access.

CVE-2024-52018
Software Genérico General
8.0
HIGH
EPSS
0.4%
2024 1 PoC

Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at genie_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-54887
Software Genérico General
8.0
HIGH
EPSS
1.3%
2024 1 PoC

TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the remote device in the context of the root user.

CVE-2024-46435
Software Genérico General
8.0
HIGH
EPSS
1.7%
2024 1 PoC

A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote attacker to cause a denial of service or potentially execute arbitrary code. This vulnerability occurs due to improper input validation when handling user-supplied data in the delFacebookPic function.

CVE-2024-44565
Software Genérico General
8.0
HIGH
EPSS
0.2%
2024 1 PoC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the serverName parameter in the function form_fast_setting_internet_set.

CVE-2024-41586
Software Genérico General
8.0
HIGH
EPSS
1.1%
2024 1 PoC

A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to execute arbitrary code via a long query string to the cgi-bin/ipfedr.cgi component.

CVE-2024-20815
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

CVE-2024-51009
Software Genérico General
8.0
HIGH
EPSS
1.1%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at ether.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-51186
Software Genérico General
8.0
HIGH
EPSS
1.3%
2024 1 PoC

D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 and ping_v6 functions.