7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-51002
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the l2tp_user_ip parameter at l2tp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-44744
Software Genérico General
5.7
MEDIUM
EPSS
0.3%
2024 1 PoC

An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directories. NOTE: Malwarebytes argues that this issue requires admin privileges and that the contents cannot be altered by non-admin users.

CVE-2024-52023
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at pppoe2.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-51016
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the addName%d parameter in usb_approve.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-21306
Windows Server 2022 Windows
5.7
MEDIUM
EPSS
30.1%
2024 CWE-306 1 PoC

Microsoft Bluetooth Driver Spoofing Vulnerability

CVE-2024-51015
Software Genérico General
5.7
MEDIUM
EPSS
0.3%
2024 1 PoC

Netgear R7000P v1.3.3.154 was discovered to contain a command injection vulnerability via the device_name2 parameter at operation_mode.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-6540
OTRS General
5.7
MEDIUM
EPSS
0.5%
2024 CWE-790 1 PoC

Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS could allow an authorized user to download a list of tickets containing information about tickets of other customers. The problem only occurs if the TicketSearchLegacyEngine has been disabled by the administrator. This issue affects OTRS: 8.0.X, 2023.X, from 2024.X through 2024.4.x

CVE-2024-50994
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component ipv6_fix.cgi via the ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, and ipv6_lan_length parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-51003
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component ap_mode.cgi via the apmode_dns1_pri and apmode_dns1_sec parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-24565
crate Database ⚡ nuclei
5.7
MEDIUM
EPSS
86.5%
2024 CWE-22 0 PoCs

CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM function in the CrateDB database that is used to import file data into database tables. This function has a flaw, and authenticated attackers can use the COPY FROM function to import arbitrary file content into database tables, resulting in information leakage. This vulnerability is patched in 5.3.9, 5.4.8, 5.5.4, and 5.6.1.

CVE-2024-51022
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the ssid parameter in bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-2101
Salon booking system Web Windows
5.7
MEDIUM
EPSS
0.7%
2024 1 PoC

The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field when booking an appointment, allowing customers to conduct Stored Cross-Site Scripting attacks. The payload gets triggered when an admin visits the 'Customers' page and the malicious script is executed in the admin context.

CVE-2024-51018
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-57277
Software Genérico Web
5.7
MEDIUM
EPSS
0.0%
2024 1 PoC

InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload.

CVE-2024-52017
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-2193
CPU General
5.7
MEDIUM
EPSS
0.9%
2024 2 PoCs

A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution (related to Spectre V1) has been disclosed. An unauthenticated attacker can exploit this vulnerability to disclose arbitrary data from the CPU using race conditions to access the speculative executable code paths.

CVE-2024-8047
Visual Sound (old) Web Windows
5.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-36255
Mattermost General
5.7
MEDIUM
EPSS
0.2%
2024 CWE-352 1 PoC

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist task command as another user via creating and sharing a deceptive post action that unexpectedly runs a slash command in some arbitrary channel.

CVE-2024-55415
Software Genérico General ⚡ nuclei
5.7
MEDIUM
EPSS
59.7%
2024 0 PoCs

DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.

CVE-2024-50995
Software Genérico Windows
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.