7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-0858
Innovs HR Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The Innovs HR WordPress plugin through 1.0.3.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding them as employees.

CVE-2024-7481
Remote Full Client Windows
8.8
HIGH
EPSS
0.4%
2024 CWE-347 1 PoC

Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install drivers.

CVE-2024-12381
Chrome General
8.8
HIGH
EPSS
6.6%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-10772
SICK InspectorP61x General
8.8
HIGH
EPSS
0.3%
2024 CWE-649 1 PoC

Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high impact on the availabilty, integrity and confidentiality up to the complete compromise of the device.

CVE-2024-38144
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
79.8%
2024 CWE-190 1 PoC

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

CVE-2024-43044
Jenkins DevOps
8.8
HIGH
EPSS
65.9%
2024 4 PoCs

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` method in the Remoting library.

CVE-2024-35584
Software Genérico Web Database ⚡ nuclei
8.8
HIGH
EPSS
82.5%
2024 1 PoC

SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.

CVE-2024-12692
Chrome General
8.8
HIGH
EPSS
5.4%
2024 CWE-843 1 PoC

Type Confusion in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-55505
Software Genérico Web
8.8
HIGH
EPSS
0.6%
2024 1 PoC

An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.

CVE-2024-7968
Chrome General
8.8
HIGH
EPSS
1.3%
2024 CWE-416 1 PoC

Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-5159
Chrome General
8.8
HIGH
EPSS
0.4%
2024 1 PoC

Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

CVE-2024-3172
Chrome General
8.8
HIGH
EPSS
0.8%
2024 1 PoC

Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVE-2024-46432
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2024 1 PoC

Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POST request to the setQuickCfgWifiAndLogin function, which allows unauthorized changes to WiFi configuration settings and administrative credentials.

CVE-2024-51144
Software Genérico Web
8.8
HIGH
EPSS
3.1%
2024 2 PoCs

Cross Site Request Forgery (CSRF) vulnerability exists in the 'pvmsg.php?action=add_message', pvmsg.php?action=confirm_delete , and ajax.server.php?page=user&action=flip_follow endpoints in Ampache <= 6.6.0.

CVE-2024-0578
LR1200GB General
8.8
HIGH
EPSS
0.4%
2024 CWE-121 1 PoC

A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-250794 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-44381
Software Genérico Web
8.8
HIGH
EPSS
2.9%
2024 1 PoC

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.

CVE-2024-11638
Gtbabel Web Windows
8.8
HIGH
EPSS
0.5%
2024 1 PoC

The Gtbabel WordPress plugin before 6.6.9 does not ensure that the URL to perform code analysis upon belongs to the blog which could allow unauthenticated attackers to retrieve a logged in user (such as admin) cookies by making them open a crafted URL as the request made to analysed the URL contains such cookies.

CVE-2024-41209
Software Genérico General
8.8
HIGH
EPSS
1.6%
2024 1 PoC

A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS) and Code Execution via a crafted MOV video file.

CVE-2024-10488
Chrome General
8.8
HIGH
EPSS
0.4%
2024 CWE-416 1 PoC

Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)