94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-48123
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue in the USB Autorun function of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to execute arbitrary code via uploading a crafted script from a USB device.

CVE-2024-48877
xls2csv General
8.4
HIGH
EPSS
0.2%
2024 CWE-680 2 PoCs

A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-52333
DCMTK General
8.4
HIGH
EPSS
0.1%
2024 CWE-119 1 PoC

An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-51381
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security and integrity of the platform, especially if an attacker gains administrative control.

CVE-2024-2448
LoadMaster General
8.4
HIGH
EPSS
44.8%
2024 CWE-78 1 PoC

An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.

CVE-2024-41340
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to upload crafted APP Enforcement modules, leading to arbitrary code execution.

CVE-2024-32503
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper memory deallocation checking, which can result in a UAF (Use-After-Free) vulnerability.

CVE-2024-5009
WhatsUp Gold General
8.4
HIGH
EPSS
36.0%
2024 CWE-269 2 PoCs

In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.InstallController.SetAdminPassword allows local attackers to modify admin's password.

CVE-2024-38399
Snapdragon General
8.4
HIGH
EPSS
0.1%
2024 CWE-416 1 PoC

Memory corruption while processing user packets to generate page faults.

CVE-2019-25332
FTP Commander Pro General
8.4
HIGH
EPSS
0.1%
2019 CWE-121 2 PoCs

FTP Commander Pro 8.03 contains a local stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting the EIP register through a custom command input. Attackers can craft a malicious payload of 4108 bytes to overwrite memory and execute shellcode, demonstrating remote code execution potential.

CVE-2019-18897
SUSE Linux Enterprise Server 12 General
8.4
HIGH
EPSS
0.1%
2019 CWE-59 2 PoCs

A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to root. This issue affects: SUSE Linux Enterprise Server 12 salt-master version 2019.2.0-46.83.1 and prior versions. SUSE Linux Enterprise Server 15 salt-master version 2019.2.0-6.21.1 and prior versions. openSUSE Factory salt-master version 2019.2.2-3.1 and prior versions.

CVE-2019-25318
AVS Audio Converter General
8.4
HIGH
EPSS
0.0%
2019 CWE-121 2 PoCs

AVS Audio Converter 9.1.2.600 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by manipulating the output folder text input. Attackers can craft a malicious payload that overwrites stack memory and triggers a bind shell on port 9999 when the 'Browse' button is clicked.

CVE-2019-25327
Prime95 General
8.4
HIGH
EPSS
0.3%
2019 CWE-122 1 PoC

Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the PrimeNet user ID and proxy host fields to trigger a bind shell on port 3110.

CVE-2019-25357
Control Center PRO Windows
8.4
HIGH
EPSS
0.0%
2019 CWE-121 1 PoC

Control Center PRO 6.2.9 contains a stack-based buffer overflow vulnerability in the user creation module's username field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious payload exceeding 664 bytes to inject shellcode and potentially execute arbitrary code on vulnerable Windows systems.

CVE-2019-16641
Software Genérico Web
8.4
HIGH
EPSS
0.0%
2019 1 PoC

An issue was found on the Ruijie EG-2000 series gateway. There is a buffer overflow in client.so. Consequently, an attacker can use login.php to login to any account, without providing its password. This affects EG-2000SE EG_RGOS 11.1(1)B1.

CVE-2019-25435
Sricam DeviceViewer General
8.4
HIGH
EPSS
0.0%
2019 CWE-121 1 PoC

Sricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function that allows authenticated attackers to execute arbitrary code by bypassing data execution prevention. Attackers can inject a malicious payload through the Username field in User Management to trigger a stack-based buffer overflow and execute commands via ROP chain gadgets.

CVE-2019-25336
Nsauditor SpotAuditor General
8.4
HIGH
EPSS
0.0%
2019 CWE-121 2 PoCs

SpotAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that allows attackers to execute arbitrary code by crafting a malicious payload. Attackers can generate a specially crafted Base64 encoded payload to trigger a Structured Exception Handler (SEH) overwrite and execute shellcode on the vulnerable system.

CVE-2019-25232
NetPCLinker General
8.4
HIGH
EPSS
0.0%
2019 CWE-120 1 PoC

NetPCLinker 1.0.0.0 contains a buffer overflow vulnerability in the Clients Control Panel DNS/IP field that allows attackers to execute arbitrary shellcode. Attackers can craft a malicious payload in the DNS/IP input to overwrite SEH handlers and execute shellcode when adding a new client.

CVE-2019-25319
Domain Quester Pro General
8.4
HIGH
EPSS
0.3%
2019 CWE-121 1 PoC

Domain Quester Pro 6.02 contains a stack overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload targeting the 'Domain Name Keywords' input field to trigger an access violation and execute a bind shell on port 9999.

CVE-2019-20459
Software Genérico General
8.4
HIGH
EPSS
0.0%
2019 1 PoC

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. With the SNMPv1 public community, all values can be read, and with the epson community, all the changeable values can be written/updated, as demonstrated by permanently disabling the network card or changing the DNS servers.