7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-7481
Remote Full Client Windows
8.8
HIGH
EPSS
0.4%
2024 CWE-347 1 PoC

Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install drivers.

CVE-2024-45173
Software Genérico General
8.8
HIGH
EPSS
0.3%
2024 3 PoCs

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vulnerable to a privilege escalation attack. The Linux user www-data running the C-MOR web interface can execute some OS commands as root via Sudo without having to enter the root password. These commands, for example, include cp, chown, and chmod, which enable an attacker to modify the system's sudoers file in order to execute all commands with root privileges. Thus, it is possible to escalate the limited privileges of the user www-data to root priv

CVE-2024-10772
SICK InspectorP61x General
8.8
HIGH
EPSS
0.3%
2024 CWE-649 1 PoC

Since the firmware update is not validated, an attacker can install modified firmware on the device. This has a high impact on the availabilty, integrity and confidentiality up to the complete compromise of the device.

CVE-2024-36821
Software Genérico General
8.8
HIGH
EPSS
13.1%
2024 1 PoC

Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.

CVE-2024-38144
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
79.8%
2024 CWE-190 1 PoC

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

CVE-2024-55505
Software Genérico Web
8.8
HIGH
EPSS
0.6%
2024 1 PoC

An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.

CVE-2024-23767
Software Genérico General
8.8
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network configurations.

CVE-2024-2450
Mattermost General
8.8
HIGH
EPSS
0.2%
2024 CWE-287 1 PoC

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership when switching from email to SAML authentication, allowing an authenticated attacker to take over other user accounts via a crafted switch request under specific conditions.

CVE-2024-21537
lilconfig General
8.8
HIGH
EPSS
0.4%
2024 CWE-94 1 PoC

Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function. An attacker can exploit this vulnerability by passing a malicious input through the defaultLoaders function.

CVE-2024-0858
Innovs HR Web Windows
8.8
HIGH
EPSS
0.3%
2024 1 PoC

The Innovs HR WordPress plugin through 1.0.3.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as adding them as employees.

CVE-2024-4242
W9 General
8.8
HIGH
EPSS
0.4%
2024 CWE-121 1 PoC

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been rated as critical. This issue affects the function formwrlSSIDget of the file /goform/wifiSSIDget. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-262133 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-45507
Apache OFBiz Web ⚡ nuclei
8.8
HIGH
EPSS
89.5%
2024 CWE-918 1 PoC

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

CVE-2024-10488
Chrome General
8.8
HIGH
EPSS
0.4%
2024 CWE-416 1 PoC

Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-6101
Chrome General
8.8
HIGH
EPSS
0.5%
2024 1 PoC

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

CVE-2024-1751
Tutor LMS – eLearning and online course solution Web Database Windows ⚡ nuclei
8.8
HIGH
EPSS
35.2%
2024 CWE-89 0 PoCs

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and including, 2.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber/student access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2024-3476
Side Menu Lite Web Windows
8.8
HIGH
EPSS
0.4%
2024 1 PoC

The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting buttons via CSRF attacks

CVE-2024-11267
JSP Store Locator Web Database Windows
8.8
HIGH
EPSS
1.3%
2024 1 PoC

The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks.

CVE-2024-36787
Software Genérico General
8.8
HIGH
EPSS
0.0%
2024 1 PoC

An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the administrative interface via unspecified vectors.

CVE-2024-8193
Chrome General
8.8
HIGH
EPSS
0.7%
2024 CWE-122 2 PoCs

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-6756
Social Auto Poster Web Windows
8.8
HIGH
EPSS
11.9%
2024 CWE-434 1 PoC

The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_image_path' function in all versions up to, and including, 5.3.14. This makes it possible for authenticated attackers, with Contributor-level and above permissions, to upload arbitrary files on the affected site's server which may make remote code execution possible. An attacker can use CVE-2024-6754 to exploit with subscriber-level access.