7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-50998
Software Genérico Networking
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component openvpn.cgi via the openvpn_service_port and openvpn_service_port_tun parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-52028
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at wiz_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-27766
Software Genérico Database
5.7
MEDIUM
EPSS
30.2%
2024 1 PoC

An issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.

CVE-2024-50997
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-8044
infolinks Ad Wrap Web Windows
5.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2024-3972
Similarity Web Windows
5.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Similarity WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CVE-2024-51011
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at pppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-51017
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the l2tp_user_netmask parameter at l2tp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-52029
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at genie_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-52030
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at ru_wan_flow.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-6502
GitLab DevOps
5.7
MEDIUM
EPSS
0.1%
2024 CWE-684 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prior to 17.2.4, and starting from 17.3 prior to 17.3.1, which allows an attacker to create a branch with the same name as a deleted tag.

CVE-2024-52013
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at wiz_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-50999
Software Genérico General
5.7
MEDIUM
EPSS
0.3%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at password.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-8043
Vikinghammer Tweet Web Windows
5.7
MEDIUM
EPSS
0.1%
2024 1 PoC

The Vikinghammer Tweet WordPress plugin through 0.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2024-51000
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component wireless.cgi via the opmode, opmode_an, and opmode_an_2 parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-20866
Samsung Mobile Devices General
5.7
MEDIUM
EPSS
0.0%
2024 1 PoC

Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.

CVE-2024-23448
APM Server Database
5.7
MEDIUM
EPSS
0.3%
2024 CWE-532 1 PoC

An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and that response would contain parts of the original document. Depending on the nature of the document that the APM Server attempted to ingest, this could lead to the insertion of sensitive or private information in the APM Server logs.

CVE-2024-52711
Software Genérico General
5.7
MEDIUM
EPSS
3.2%
2024 1 PoC

DI-8100 v16.07.26A1 is vulnerable to Buffer Overflow In the ip_position_asp function via the ip parameter.

CVE-2024-52016
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component wlg_adv.cgi via the apmode_dns1_pri and apmode_dns1_sec parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.

CVE-2024-50996
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2024 1 PoC

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the bpa_server parameter at genie_bpa.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.