7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-25736
Software Genérico General
7.5
HIGH
EPSS
9.1%
2024 1 PoC

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request.

CVE-2024-8198
Chrome General
7.5
HIGH
EPSS
0.3%
2024 CWE-122 2 PoCs

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-34669
Samsung Mobile Devices General
7.5
HIGH
EPSS
5.1%
2024 1 PoC

Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2024-32825
Simply Static General ⚡ nuclei
7.5
HIGH
EPSS
25.8%
2024 CWE-201 0 PoCs

Insertion of Sensitive Information Into Sent Data vulnerability in Simply Static Simply Static simply-static.This issue affects Simply Static: from n/a through <= 3.1.3.

CVE-2024-12270
Beautiful taxonomy filters Web Database Windows
7.5
HIGH
EPSS
66.0%
2024 CWE-89 1 PoC

The Beautiful taxonomy filters plugin for WordPress is vulnerable to SQL Injection via the 'selects[0][term]' parameter in all versions up to, and including, 2.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-26026
BIG-IP Next Central Manager Web Database
7.5
HIGH
EPSS
89.4%
2024 CWE-89 2 PoCs

An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI).  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2024-21538
cross-spawn General
7.5
HIGH
EPSS
0.1%
2024 CWE-1333 2 PoCs

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

CVE-2024-24416
Software Genérico Networking
7.5
HIGH
EPSS
0.2%
2024 1 PoC

The Linux Foundation Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) was discovered to contain a buffer overflow in the decode_access_point_name_ie function at /3gpp/3gpp_24.008_sm_ies.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

CVE-2024-11067
DSL6740C General
7.5
HIGH
EPSS
0.3%
2024 CWE-23 1 PoC

The D-Link DSL6740C modem has a Path Traversal Vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files. Additionally, since the device's default password is a combination of the MAC address, attackers can obtain the MAC address through this vulnerability and attempt to log in to the device using the default password.

CVE-2024-25164
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionality.

CVE-2024-47915
VaeMendis Ubooquity version 2.1.2 General
7.5
HIGH
EPSS
0.3%
2024 CWE-200 1 PoC

VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-32738
CyberPower PowerPanel Enterprise Database ⚡ nuclei
7.5
HIGH
EPSS
51.6%
2024 1 PoC

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_lean" function within MCUDBHelper.

CVE-2024-45253
VideoIQ iCVR HD camera General
7.5
HIGH
EPSS
0.4%
2024 CWE-22 1 PoC

Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2024-28716
Software Genérico General
7.5
HIGH
EPSS
2.2%
2024 2 PoCs

An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.

CVE-2024-10628
Quiz Maker Business Web Database Windows
7.5
HIGH
EPSS
0.2%
2024 CWE-89 1 PoC

The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.0 (Developer), and up to, and including, 31.8.0 (Agency) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. NOTE: The three variations of

CVE-2024-39894
Software Genérico Networking
7.5
HIGH
EPSS
3.0%
2024 1 PoC

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.

CVE-2024-23837
libhtp Web
7.5
HIGH
EPSS
0.3%
2024 CWE-770 1 PoC

LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed in 0.5.46.

CVE-2024-57698
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, even after initial configuration and password change. This happens due to excessive exposure of information and the lack of adequate access control on the /user/list?culture=en-us endpoint.

CVE-2024-34666
Samsung Mobile Devices General
7.5
HIGH
EPSS
5.1%
2024 1 PoC

Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2024-6973
SDP Client Windows
7.5
HIGH
EPSS
1.5%
2024 CWE-20 1 PoC

Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34.