7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-36442
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 2 PoCs

cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrary files on the device's file system.

CVE-2024-48416
Software Genérico Networking
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/fromSetLanDhcpsClientbinding.

CVE-2024-12381
Chrome General
8.8
HIGH
EPSS
6.6%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-42902
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the js_localize.php function

CVE-2024-44381
Software Genérico Web
8.8
HIGH
EPSS
2.9%
2024 1 PoC

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.

CVE-2024-6778
Chrome General
8.8
HIGH
EPSS
12.8%
2024 CWE-362 2 PoCs

Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

CVE-2024-33891
Software Genérico Web
8.8
HIGH
EPSS
0.5%
2024 4 PoCs

Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP API in SecretServer/webservices/SSWebService.asmx. This is related to a hardcoded key, the use of the integer 2 for the Admin user, and removal of the oauthExpirationId attribute.

CVE-2024-32003
wn-dusk-plugin Web
8.8
HIGH
EPSS
0.1%
2024 CWE-269 1 PoC

wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin provides some special routes as part of its testing framework to allow a browser environment (such as headless Chrome) to act as a user in the Backend or User plugin without having to go through authentication. This route is `[[URL]]/_dusk/login/[[USER ID]]/[[MANAGER]]` - where `[[URL]]` is the base URL of the site, `[[USER ID]]` is the ID of the user account and `[[MANAGER]]` is the authentication manager (either `backend` for Backend, or `user` for the User plugin). If a co

CVE-2024-8193
Chrome General
8.8
HIGH
EPSS
0.7%
2024 CWE-122 2 PoCs

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-47897
Graphics DDK General
8.8
HIGH
EPSS
0.2%
2024 CWE-787 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls resulting in platform instability and reboots.

CVE-2024-22903
Software Genérico General
8.8
HIGH
EPSS
3.9%
2024 1 PoC

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.

CVE-2024-51144
Software Genérico Web
8.8
HIGH
EPSS
3.1%
2024 2 PoCs

Cross Site Request Forgery (CSRF) vulnerability exists in the 'pvmsg.php?action=add_message', pvmsg.php?action=confirm_delete , and ajax.server.php?page=user&action=flip_follow endpoints in Ampache <= 6.6.0.

CVE-2024-35584
Software Genérico Web Database ⚡ nuclei
8.8
HIGH
EPSS
82.5%
2024 1 PoC

SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.

CVE-2024-51023
Software Genérico General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the SetNetworkTomographySettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.

CVE-2024-11643
Accessibility by AllAccessible Web Windows
8.8
HIGH
EPSS
1.5%
2024 CWE-862 1 PoC

The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'AllAccessible_save_settings' function in all versions up to, and including, 1.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

CVE-2024-1755
NPS computy Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The NPS computy WordPress plugin through 2.7.5 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks

CVE-2024-45175
Software Genérico General
8.8
HIGH
EPSS
0.7%
2024 3 PoCs

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It was found out that sensitive information, for example login credentials of cameras, is stored in cleartext. Thus, an attacker with filesystem access, for example exploiting a path traversal attack, has access to the login data of all configured cameras, or the configured FTP server.

CVE-2024-5705
Pentaho Data Integration & Analytics General
8.8
HIGH
EPSS
0.0%
2024 CWE-863 1 PoC

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions. (CWE-863)     Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, have modules enabled by default that allow execution of system level processes.   When access control checks are incorrectly applied, users can access data or perform actions that they should not be allowed to perform. This can lead to a wide

CVE-2024-5080
wp-eMember Web Windows
8.8
HIGH
EPSS
0.9%
2024 1 PoC

The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload arbitrary files such as PHP on the server

CVE-2024-8637
Chrome Networking
8.8
HIGH
EPSS
0.3%
2024 CWE-416 1 PoC

Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)