94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-40474
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2024 1 PoC

A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0.

CVE-2024-41992
Software Genérico General
8.8
HIGH
EPSS
27.9%
2024 1 PoC

Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP port 8000 or 8080 on a LAN interface. On other devices, this may be exploitable over a WAN interface.

CVE-2024-11621
Remote Desktop Manager General
8.8
HIGH
EPSS
0.2%
2024 CWE-295 1 PoC

Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier Remote Desktop Manager Powershell 2024.3.6.0 and earlier

CVE-2024-27497
Software Genérico General ⚡ nuclei
8.8
HIGH
EPSS
81.9%
2024 0 PoCs

Linksys E2000 Ver.1.0.06 build 1 is vulnerable to authentication bypass via the position.js file.

CVE-2024-8504
VICIdial General
8.8
HIGH
EPSS
93.1%
2024 CWE-78 3 PoCs

An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.

CVE-2024-51144
Software Genérico Web
8.8
HIGH
EPSS
3.1%
2024 2 PoCs

Cross Site Request Forgery (CSRF) vulnerability exists in the 'pvmsg.php?action=add_message', pvmsg.php?action=confirm_delete , and ajax.server.php?page=user&action=flip_follow endpoints in Ampache <= 6.6.0.

CVE-2024-44381
Software Genérico Web
8.8
HIGH
EPSS
2.9%
2024 1 PoC

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.

CVE-2024-9821
Bot for Telegram on WooCommerce Web Windows
8.8
HIGH
EPSS
47.6%
2024 CWE-200 1 PoC

The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'stm_wpcfto_get_settings' AJAX action in all versions up to, and including, 1.2.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to view the Telegram Bot Token, a secret token used to control the bot, which can then be used to log in as any existing user on the site, such as an administrator, if they know the username, due to the Login with Telegram feature.

CVE-2024-5076
wp-eMember Web Windows
8.8
HIGH
EPSS
0.7%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-51442
Software Genérico General
8.8
HIGH
EPSS
32.7%
2024 1 PoC

Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specially crafted minidlna.conf configuration file.

CVE-2024-44341
Software Genérico General
8.8
HIGH
EPSS
3.8%
2024 2 PoCs

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.

CVE-2024-24328
Software Genérico General ⚡ nuclei
8.8
HIGH
EPSS
84.4%
2024 0 PoCs

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules function.

CVE-2024-21411
Skype for Consumer General
8.8
HIGH
EPSS
5.0%
2024 CWE-453 1 PoC

Skype for Consumer Remote Code Execution Vulnerability

CVE-2024-21802
llama.cpp General
8.8
HIGH
EPSS
0.6%
2024 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the GGUF library info-&gt;ne functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-36790
Software Genérico General
8.8
HIGH
EPSS
0.0%
2024 1 PoC

Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.

CVE-2024-7340
Software Genérico Web ⚡ nuclei
8.8
HIGH
EPSS
87.7%
2024 CWE-22 1 PoC

The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.

CVE-2024-4244
W9 General
8.8
HIGH
EPSS
0.4%
2024 CWE-121 1 PoC

A vulnerability classified as critical was found in Tenda W9 1.0.0.7(4456). Affected by this vulnerability is the function fromDhcpSetSer of the file /goform/DhcpSetSer. The manipulation of the argument dhcpStartIp/dhcpEndIp/dhcpGw/dhcpMask/dhcpLeaseTime/dhcpDns1/dhcpDns2 leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-262135. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-28888
Foxit Reader Web
8.8
HIGH
EPSS
4.1%
2024 CWE-416 3 PoCs

A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2024-1962
CM Download Manager Web Windows
8.8
HIGH
EPSS
0.8%
2024 1 PoC

The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins edit downloads via a CSRF attack

CVE-2024-49576
Foxit Reader Web
8.8
HIGH
EPSS
0.1%
2024 CWE-416 2 PoCs

A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a checkbox CBF_Widget object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.