7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-24551
Bludit Web
8.9
HIGH
EPSS
0.2%
2024 CWE-77 1 PoC

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

CVE-2024-24550
Bludit Web
8.9
HIGH
EPSS
0.1%
2024 CWE-77 1 PoC

A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload and execute PHP files.

CVE-2024-49368
nginx-ui Web
8.9
HIGH
EPSS
57.7%
2024 CWE-20 1 PoC

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 fixes this issue.

CVE-2024-0919
TEW-815DAP General
8.8
HIGH
EPSS
36.8%
2024 CWE-77 2 PoCs

A vulnerability was found in TRENDnet TEW-815DAP 1.0.2.0. It has been classified as critical. This affects the function do_setNTP of the component POST Request Handler. The manipulation of the argument NtpDstStart/NtpDstEnd leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252123. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-4119
W15E General
8.8
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda W15E 15.11.0.14. It has been declared as critical. This vulnerability affects the function formIPMacBindDel of the file /goform/delIpMacBind. The manipulation of the argument IPMacBindIndex leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-261862 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-44381
Software Genérico Web
8.8
HIGH
EPSS
2.9%
2024 1 PoC

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.

CVE-2024-38458
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Xenforo before 2.2.16 allows code injection.

CVE-2024-6776
Chrome General
8.8
HIGH
EPSS
0.4%
2024 CWE-416 1 PoC

Use after free in Audio in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-24725
Software Genérico Web
8.8
HIGH
EPSS
81.1%
2024 2 PoCs

Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.

CVE-2024-0779
Enjoy Social Feed plugin for WordPress website Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation and CSRF in various function hooked to admin_init, allowing unauthenticated users to call them and unlink arbitrary users Instagram Account for example

CVE-2024-54780
Software Genérico Networking
8.8
HIGH
EPSS
8.1%
2024 1 PoC

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp parameter.

CVE-2024-25938
Foxit Reader Web
8.8
HIGH
EPSS
3.5%
2024 CWE-416 2 PoCs

A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widget. A specially crafted JavaScript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2024-22514
Software Genérico General
8.8
HIGH
EPSS
17.6%
2024 1 PoC

An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.

CVE-2024-22779
Software Genérico General
8.8
HIGH
EPSS
13.3%
2024 1 PoC

Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin.java.

CVE-2024-3909
AC500 General
8.8
HIGH
EPSS
0.3%
2024 CWE-121 1 PoC

A vulnerability classified as critical was found in Tenda AC500 2.0.1.9(1307). Affected by this vulnerability is the function formexeCommand of the file /goform/execCommand. The manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-261145 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-11621
Remote Desktop Manager General
8.8
HIGH
EPSS
0.2%
2024 CWE-295 1 PoC

Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communications via a man-in-the-middle attack. Versions affected are : Remote Desktop Manager macOS 2024.3.9.0 and earlier Remote Desktop Manager Linux 2024.3.2.5 and earlier Remote Desktop Manager Android 2024.3.3.7 and earlier Remote Desktop Manager iOS 2024.3.3.0 and earlier Remote Desktop Manager Powershell 2024.3.6.0 and earlier

CVE-2024-6605
Firefox General
8.8
HIGH
EPSS
0.6%
2024 1 PoC

Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.

CVE-2024-39840
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Factorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the ability of certain Lua base module functions to execute bytecode and generate fake objects.

CVE-2024-3833
Chrome General
8.8
HIGH
EPSS
3.1%
2024 1 PoC

Object corruption in WebAssembly in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-42902
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the js_localize.php function