94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-44340
Software Genérico General
8.8
HIGH
EPSS
1.2%
2024 2 PoCs

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings.

CVE-2024-11697
Firefox General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

CVE-2024-0575
LR1200GB General
8.8
HIGH
EPSS
0.4%
2024 CWE-121 1 PoC

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been classified as critical. This affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250791. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-34058
Software Genérico Web
8.8
HIGH
EPSS
0.3%
2024 3 PoCs

The WebTop package for NethServer 7 and 8 allows stored XSS (for example, via the Subject field if an e-mail message).

CVE-2024-44589
Software Genérico General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows attackers to execute of arbitrary code.

CVE-2024-1675
Chrome General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-9954
Chrome General
8.8
HIGH
EPSS
6.5%
2024 CWE-416 3 PoCs

Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-10230
Chrome General
8.8
HIGH
EPSS
0.2%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-7968
Chrome General
8.8
HIGH
EPSS
1.3%
2024 CWE-416 1 PoC

Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-9890
User Toolkit Web Windows
8.8
HIGH
EPSS
14.5%
2024 CWE-288 1 PoC

The User Toolkit plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.3. This is due to an improper capability check in the 'switchUser' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to log in as any existing user on the site, such as an administrator. CVE-2024-50503 may be a duplicate.

CVE-2024-6101
Chrome General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2024-21345
Windows Server 2022, 23H2 Edition (Server Core installation) Windows
8.8
HIGH
EPSS
31.9%
2024 CWE-122 2 PoCs

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-6075
wp-cart-for-digital-products Web Windows
8.8
HIGH
EPSS
0.4%
2024 1 PoC

The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-55506
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter.

CVE-2024-5844
Chrome General
8.8
HIGH
EPSS
0.4%
2024 1 PoC

Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-22515
Software Genérico General
8.8
HIGH
EPSS
13.7%
2024 1 PoC

Unrestricted File Upload vulnerability in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to upload arbitrary files via the upload audio component.

CVE-2024-3193
MailCleaner General
8.8
HIGH
EPSS
2.2%
2024 CWE-78 1 PoC

A vulnerability has been found in MailCleaner up to 2023.03.14 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Admin Endpoints. The manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The identifier VDB-262309 was assigned to this vulnerability.

CVE-2024-0692
Security Event Manager General ⚡ nuclei
8.8
HIGH
EPSS
78.3%
2024 CWE-502 0 PoCs

The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.

CVE-2024-1655
ExpertWiFi EBM63 Networking
8.8
HIGH
EPSS
14.6%
2024 CWE-78 1 PoC

Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system commands by sending a specially crafted request.