94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-52335
syngo.plaza VB30E Database
9.8
CRITICAL
EPSS
1.2%
2024 CWE-89 1 PoC

A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF05). The affected application do not properly sanitize input data before sending it to the SQL server. This could allow an attacker with access to the application could use this vulnerability to execute malicious SQL commands to compromise the whole database.

CVE-2024-22633
Software Genérico General
9.8
CRITICAL
EPSS
4.2%
2024 1 PoC

Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hprinter parameter. This vulnerability is triggered via a crafted POST request.

CVE-2024-37782
Software Genérico Windows
9.8
CRITICAL
EPSS
0.1%
2024 2 PoCs

An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.

CVE-2024-13375
Adifier System Web Windows
9.8
CRITICAL
EPSS
10.6%
2024 CWE-620 1 PoC

The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.1.7. This is due to the plugin not properly validating a user's identity prior to updating their details like password through the adifier_recover() function. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

CVE-2024-8517
SPIP Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.3%
2024 CWE-73 2 PoCs

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.

CVE-2024-23708
Android General
9.8
CRITICAL
EPSS
0.1%
2024 1 PoC

In multiple functions of NotificationManagerService.java, there is a possible way to not show a toast message when a clipboard message has been accessed. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-8381
Firefox General
9.8
CRITICAL
EPSS
11.6%
2024 1 PoC

A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

CVE-2024-57045
Software Genérico Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
66.8%
2024 0 PoCs

A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals to bypass the authentication. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page.

CVE-2024-33375
Software Genérico Networking
9.8
CRITICAL
EPSS
0.2%
2024 1 PoC

LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.

CVE-2024-22729
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
91.2%
2024 0 PoCs

NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.

CVE-2024-23113
🔥 KEV FortiSwitchManager Networking
9.8
CRITICAL
EPSS
54.4%
2024 CWE-134 19 PoCs

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.

CVE-2024-27683
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2024 1 PoC

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacker can send a POST request to trigger the vulnerablilify.

CVE-2024-3806
Porto Web Windows
9.8
CRITICAL
EPSS
59.4%
2024 CWE-98 2 PoCs

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the 'porto_ajax_posts' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where php file type can be uploaded and included.

CVE-2024-27173
Toshiba Tec e-Studio multi-function peripheral (MFP) Web
9.8
CRITICAL
EPSS
45.4%
2024 CWE-22 3 PoCs

Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing executable code. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.

CVE-2024-45166
Software Genérico General
9.8
CRITICAL
EPSS
4.8%
2024 2 PoCs

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution. There is an access violation and EIP overwrite after five logins.

CVE-2024-22853
Software Genérico General
9.8
CRITICAL
EPSS
86.9%
2024 2 PoCs

D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.

CVE-2024-39332
Software Genérico Web
9.8
CRITICAL
EPSS
2.5%
2024 1 PoC

Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via modification of shell scripts on the server.

CVE-2024-48202
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.

CVE-2024-29937
Software Genérico General
9.8
CRITICAL
EPSS
4.4%
2024 1 PoC

NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.