7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-44563
Software Genérico General
8.0
HIGH
EPSS
0.2%
2024 1 PoC

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.

CVE-2024-48636
Software Genérico General
8.0
HIGH
EPSS
0.8%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:0/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-48632
Software Genérico General
8.0
HIGH
EPSS
0.3%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the LocalIPAddress, TCPPorts, and UDPPorts parameters in the SetPortForwardingSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-48638
Software Genérico Networking
8.0
HIGH
EPSS
0.8%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SubnetMask parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-44667
Software Genérico Networking
8.0
HIGH
EPSS
0.3%
2024 2 PoCs

Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads to information exposure and root shell access.

CVE-2024-52739
Software Genérico General
8.0
HIGH
EPSS
3.5%
2024 1 PoC

D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.

CVE-2024-52550
Jenkins Pipeline: Groovy Plugin DevOps
8.0
HIGH
EPSS
1.4%
2024 1 PoC

Jenkins Pipeline: Groovy Plugin 3990.vd281dd77a_388 and earlier, except 3975.3977.v478dd9e956c3 does not check whether the main (Jenkinsfile) script for a rebuilt build is approved, allowing attackers with Item/Build permission to rebuild a previous build whose (Jenkinsfile) script is no longer approved.

CVE-2024-48635
Software Genérico General
8.0
HIGH
EPSS
0.8%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:2/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-53375
Software Genérico Networking
8.0
HIGH
EPSS
70.7%
2024 1 PoC

An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exists in the "tmp_get_sites" function of the HomeShield functionality provided by TP-Link. This vulnerability is still exploitable without the activation of the HomeShield functionality.

CVE-2024-45264
Software Genérico Web
8.0
HIGH
EPSS
9.3%
2024 1 PoC

A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges.

CVE-2024-48631
Software Genérico General
8.0
HIGH
EPSS
0.8%
2024 1 PoC

D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to execute arbitrary OS commands via a crafted POST request.

CVE-2024-41595
Software Genérico General
8.0
HIGH
EPSS
0.4%
2024 1 PoC

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cgi pages because of missing bounds checks on read and write operations.

CVE-2024-46658
Software Genérico General
8.0
HIGH
EPSS
32.6%
2024 1 PoC

Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.

CVE-2024-41596
Software Genérico General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form parameters.

CVE-2024-46486
Software Genérico Web
8.0
HIGH
EPSS
1.7%
2024 1 PoC

TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.

CVE-2024-41588
Software Genérico General
8.0
HIGH
EPSS
0.1%
2024 1 PoC

The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strncpy function.

CVE-2024-48093
Software Genérico General
8.0
HIGH
EPSS
3.8%
2024 1 PoC

Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Execution via uploading and executing malicious files without validating file extensions or content types.

CVE-2024-44815
Software Genérico Networking
8.0
HIGH
EPSS
10.8%
2024 1 PoC

Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credentials via SPI flash Firmware W25Q64JV.

CVE-2024-54954
Software Genérico General
8.0
HIGH
EPSS
0.8%
2024 1 PoC

OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.

CVE-2024-46435
Software Genérico General
8.0
HIGH
EPSS
1.7%
2024 1 PoC

A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote attacker to cause a denial of service or potentially execute arbitrary code. This vulnerability occurs due to improper input validation when handling user-supplied data in the delFacebookPic function.