94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-5290
wpa_supplicant General
8.8
HIGH
EPSS
0.3%
2024 CWE-427 2 PoCs

An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root). Membership in the netdev group or access to the dbus interface of wpa_supplicant allow an unprivileged user to specify an arbitrary path to a module to be loaded by the wpa_supplicant process; other escalation paths might exist.

CVE-2024-49699
ARPrice General
8.8
HIGH
EPSS
4.6%
2024 CWE-502 1 PoC

Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue affects ARPrice: from n/a through <= 4.1.3.

CVE-2024-2376
WPQA Builder Web Windows
8.8
HIGH
EPSS
0.4%
2024 1 PoC

The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-9941
WPGYM - Wordpress Gym Management System Web Windows
8.8
HIGH
EPSS
0.1%
2024 CWE-269 1 PoC

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function in all versions up to, and including, 67.1.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to create new user accounts with the administrator role.

CVE-2024-30485
Finale Lite General
8.8
HIGH
EPSS
55.4%
2024 CWE-862 1 PoC

Missing Authorization vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.

CVE-2024-10771
SICK InspectorP61x General
8.8
HIGH
EPSS
4.5%
2024 CWE-94 1 PoC

Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code execution. With network access and the user level ”Service”, an attacker can execute arbitrary system commands in the root user’s contexts.

CVE-2024-45979
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. This allows attackers to arbitrarily reset other users' passwords and compromise their accounts.

CVE-2024-25852
Software Genérico General ⚡ nuclei
8.8
HIGH
EPSS
93.0%
2024 0 PoCs

Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use the vulnerability to obtain device administrator rights.

CVE-2024-10629
GPX Viewer Web Windows
8.8
HIGH
EPSS
57.6%
2024 CWE-862 2 PoCs

The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file type validation in the gpxv_file_upload() function in all versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2024-20039
MT2731, MT2735, MT2737, MT3967, MT6297, MT6298, MT6739, MT6761, MT6762, MT6762D, MT6762M, MT6763, MT6765, MT6765T, MT6767, MT6768, MT6769, MT6769T, MT6769Z, MT6771, MT6779, MT6781, MT6783, MT6785, MT6785T, MT6785U, MT6789, MT6813, MT6815, MT6833, MT6835, MT6853, MT6855, MT6873, MT6875, MT6875T, MT6877, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6895T, MT6896, MT6897, MT6980, MT6980D, MT6983, MT6985, MT6986, MT6986D, MT6989, MT6990, MT8666, MT8667, MT8673, MT8675, MT8676, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8791, MT8791T, MT8792, MT8796, MT8797, MT8798 General
8.8
HIGH
EPSS
2.9%
2024 1 PoC

In modem protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01240012; Issue ID: MSV-1215.

CVE-2024-57778
Software Genérico General
8.8
HIGH
EPSS
11.4%
2024 1 PoC

An issue in Orbe ONetView Roeador Onet-1200 Orbe 1680210096 allows a remote attacker to escalate privileges via the servers response from status code 500 to status code 200.

CVE-2024-13146
Booknetic Web Windows
8.8
HIGH
EPSS
0.1%
2024 1 PoC

The Booknetic WordPress plugin before 4.1.5 does not have CSRF check when creating Staff accounts, which could allow attackers to make logged in admin add arbitrary Staff members via a CSRF attack

CVE-2024-2805
AC15 General
8.8
HIGH
EPSS
0.5%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been rated as critical. Affected by this issue is the function formSetSpeedWan of the file /goform/SetSpeedWan. The manipulation of the argument speed_dir leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257660. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-37857
Software Genérico Web Database
8.8
HIGH
EPSS
0.5%
2024 2 PoCs

SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via id parameter to php-lfis/admin/categories/view_category.php.

CVE-2024-36396
WFO General
8.8
HIGH
EPSS
0.2%
2024 CWE-434 1 PoC

Verint - CWE-434: Unrestricted Upload of File with Dangerous Type

CVE-2024-31759
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2024 2 PoCs

An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.

CVE-2024-5846
Chrome General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

CVE-2024-46434
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized remote attacker to gain administrative access by sending a specially crafted HTTP request.

CVE-2024-45981
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.

CVE-2024-5157
Chrome General
8.8
HIGH
EPSS
0.7%
2024 1 PoC

Use after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)