7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-0578
LR1200GB General
8.8
HIGH
EPSS
0.4%
2024 CWE-121 1 PoC

A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250794 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-6995
Chrome General
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-11638
Gtbabel Web Windows
8.8
HIGH
EPSS
0.5%
2024 1 PoC

The Gtbabel WordPress plugin before 6.6.9 does not ensure that the URL to perform code analysis upon belongs to the blog which could allow unauthenticated attackers to retrieve a logged in user (such as admin) cookies by making them open a crafted URL as the request made to analysed the URL contains such cookies.

CVE-2024-46429
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with administrative privileges.

CVE-2024-0750
Firefox General
8.8
HIGH
EPSS
1.5%
2024 1 PoC

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

CVE-2024-3172
Chrome General
8.8
HIGH
EPSS
0.8%
2024 1 PoC

Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVE-2024-3474
Wow Skype Buttons Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

CVE-2024-46432
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setQuickCfgWifiAndLogin function, which allows unauthorized changes to WiFi configuration settings and administrative credentials.

CVE-2024-28888
Foxit Reader Web
8.8
HIGH
EPSS
4.1%
2024 CWE-416 3 PoCs

A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2024-10673
Top Store Web Windows
8.8
HIGH
EPSS
51.9%
2024 CWE-862 1 PoC

The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the top_store_install_and_activate_callback() function in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to install arbitrary plugins which can contain other exploitable vulnerabilities to elevate privileges and gain remote code execution.

CVE-2024-34310
Software Genérico Database
8.8
HIGH
EPSS
0.4%
2024 1 PoC

Jin Fang Times Content Management System v3.2.3 was discovered to contain a SQL injection vulnerability via the id parameter.

CVE-2024-32258
Software Genérico General
8.8
HIGH
EPSS
50.1%
2024 2 PoCs

The network server of fceux 2.7.0 has a path traversal vulnerability, allowing attackers to overwrite any files on the server without authentication by fake ROM.

CVE-2024-1670
Chrome General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-44381
Software Genérico Web
8.8
HIGH
EPSS
2.9%
2024 1 PoC

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.

CVE-2024-7533
Chrome General
8.8
HIGH
EPSS
0.3%
2024 CWE-416 1 PoC

Use after free in Sharing in Google Chrome on iOS prior to 127.0.6533.99 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-2485
AC18 General
8.8
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda AC18 15.03.05.05 and classified as critical. Affected by this issue is the function formSetSpeedWan of the file /goform/SetSpeedWan. The manipulation of the argument speed_dir leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-256892. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-56116
Software Genérico Web
8.8
HIGH
EPSS
12.1%
2024 1 PoC

A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator account.

CVE-2024-48419
Software Genérico Networking
8.8
HIGH
EPSS
3.6%
2024 1 PoC

Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an attacker with access to the web interface to inject and execute arbitrary shell commands, with "root" privileges.

CVE-2024-39840
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

Factorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the ability of certain Lua base module functions to execute bytecode and generate fake objects.

CVE-2024-35584
Software Genérico Web Database ⚡ nuclei
8.8
HIGH
EPSS
82.5%
2024 1 PoC

SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.