94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-58306
minaliC DevOps Web
8.7
HIGH
EPSS
0.3%
2024 CWE-400 1 PoC

minaliC 2.0.0 contains a denial of service vulnerability that allows remote attackers to crash the web server by sending oversized GET requests. Attackers can send crafted HTTP requests with excessive data to overwhelm the server and cause service interruption.

CVE-2024-3393
🔥 KEV Cloud NGFW Networking Cloud
8.7
HIGH
EPSS
77.7%
2024 CWE-754 2 PoCs

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will cause the firewall to enter maintenance mode.

CVE-2024-6911
ProcessPlus Windows ⚡ nuclei
8.7
HIGH
EPSS
93.3%
2024 CWE-552 2 PoCs

Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in PerkinElmer ProcessPlus.This issue affects ProcessPlus: through 1.11.6507.0.

CVE-2024-11061
AC10 General
8.7
HIGH
EPSS
0.3%
2024 CWE-121 2 PoCs

A vulnerability classified as critical was found in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function FUN_0044db3c of the file /goform/fast_setting_wifi_set. The manipulation of the argument timeZone leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-6648
AP Page Builder General
8.7
HIGH
EPSS
0.3%
2024 CWE-22 1 PoC

Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.

CVE-2024-6963
O3 General
8.7
HIGH
EPSS
0.8%
2024 CWE-121 1 PoC

A vulnerability, which was classified as critical, has been found in Tenda O3 1.0.0.10. This issue affects the function formexeCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272117 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-11056
AC10 General
8.7
HIGH
EPSS
0.3%
2024 CWE-121 1 PoC

A vulnerability, which was classified as critical, was found in Tenda AC10 16.03.10.13. Affected is the function FUN_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-58336
Akuvox Smart Doorphone General
8.7
HIGH
EPSS
0.1%
2024 CWE-306 1 PoC

Akuvox Smart Intercom S539 contains an unauthenticated vulnerability that allows remote attackers to access live video streams by requesting the video.cgi endpoint on port 8080. Attackers can retrieve video stream data without authentication by directly accessing the specified endpoint on affected Akuvox doorphone and intercom devices.

CVE-2024-26291
Avid NEXIS E-series General ⚡ nuclei
8.7
HIGH
EPSS
1.9%
2024 CWE-285 1 PoC

An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filename does not validate the path thus allowing users to read arbitrary files. As the application runs with the highest privileges (root/NT_AUTHORITY SYSTEM) by default attackers are able to obtain sensitive information. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1.

CVE-2024-9535
DIR-605L General
8.7
HIGH
EPSS
0.3%
2024 CWE-120 1 PoC

A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been declared as critical. Affected by this vulnerability is the function formEasySetupWWConfig of the file /goform/formEasySetupWWConfig. The manipulation of the argument curTime leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-7938
3DSwymer Web
8.7
HIGH
EPSS
0.9%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-6964
O3 General
8.7
HIGH
EPSS
0.2%
2024 CWE-121 1 PoC

A vulnerability, which was classified as critical, was found in Tenda O3 1.0.0.10. Affected is the function fromDhcpSetSer. The manipulation of the argument dhcpEn/startIP/endIP/preDNS/altDNS/mask/gateway leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-272118 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-55544
IAP-420 General
8.7
HIGH
EPSS
21.2%
2024 CWE-77 2 PoCs

Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.01e and below.

CVE-2024-11274
GitLab DevOps
8.7
HIGH
EPSS
0.4%
2024 CWE-601 1 PoC

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.

CVE-2024-7737
3DSwymer Web
8.7
HIGH
EPSS
0.1%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-3594
IDonate Web Windows
8.7
HIGH
EPSS
1.0%
2024 1 PoC

The IDonate WordPress plugin through 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

CVE-2024-8576
AC1200 T8 General
8.7
HIGH
EPSS
0.3%
2024 CWE-120 1 PoC

A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been classified as critical. Affected is the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument desc leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-11959
DIR-605L General
8.7
HIGH
EPSS
3.1%
2024 CWE-120 2 PoCs

A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function formResetStatistic of the file /goform/formResetStatistic. The manipulation of the argument curTime leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2024-12092
ENOVIA Collaborative Industry Innovator Web
8.7
HIGH
EPSS
1.5%
2024 CWE-79 1 PoC

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.

CVE-2024-10345
Helix Core General
8.7
HIGH
EPSS
0.7%
2024 CWE-400 1 PoC

In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karol Więsek.