9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-50427
SurveyJS General
9.9
CRITICAL
EPSS
69.7%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects SurveyJS: from n/a through <= 1.9.136.

CVE-2024-4701
Genie General
9.9
CRITICAL
EPSS
17.6%
2024 CWE-22 2 PoCs

A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18

CVE-2024-25693
Portal for ArcGIS General
9.9
CRITICAL
EPSS
9.9%
2024 CWE-22 1 PoC

There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory. 

CVE-2024-31390
Breakdance General
9.9
CRITICAL
EPSS
0.1%
2024 CWE-94 3 PoCs

: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.

CVE-2024-9014
pgAdmin 4 General ⚡ nuclei
9.9
CRITICAL
EPSS
92.9%
2024 2 PoCs

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.

CVE-2024-31380
Oxygen Builder General
9.9
CRITICAL
EPSS
0.1%
2024 CWE-94 4 PoCs

Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, refuses to patch the issue.This issue affects Oxygen Builder: from n/a through 4.9.

CVE-2024-31286
WP Photo Album Plus General
9.9
CRITICAL
EPSS
0.6%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.

CVE-2024-49653
Portfolleo General
9.9
CRITICAL
EPSS
59.0%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in james-eggers Portfolleo portfolleo allows Upload a Web Shell to a Web Server.This issue affects Portfolleo: from n/a through <= 1.2.

CVE-2024-37762
Software Genérico General
9.9
CRITICAL
EPSS
28.0%
2024 1 PoC

MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

CVE-2024-54262
Import Export For WooCommerce General
9.9
CRITICAL
EPSS
54.8%
2024 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Import Export For WooCommerce: from n/a through <= 1.6.2.

CVE-2024-42448
Service Provider Console General
9.9
CRITICAL
EPSS
64.4%
2024 2 PoCs

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

CVE-2019-5138
Moxa General
9.9
CRITICAL
EPSS
3.7%
2019 CWE-78 1 PoC

An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file can cause arbitrary busybox commands to be executed, resulting in remote control over the device. An attacker can send diagnostic while authenticated as a low privilege user to trigger this vulnerability.

CVE-2019-10758
🔥 KEV mongo-express General ⚡ nuclei
9.9
CRITICAL
EPSS
94.4%
2019 4 PoCs

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.

CVE-2019-5153
Moxa General
9.9
CRITICAL
EPSS
2.3%
2019 CWE-121 1 PoC

An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

CVE-2019-8992
TIBCO ActiveMatrix BPM General
9.9
CRITICAL
EPSS
0.7%
2019 1 PoC

The administrative server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, TIBCO ActiveMatrix Policy Director, TIBCO ActiveMatrix Service Bus, TIBCO ActiveMatrix Service Grid, TIBCO ActiveMatrix Service Grid Distribution for TIBCO Silver Fabric, TIBCO Silver Fabric Enabler for ActiveMatrix BPM, and TIBCO Silver Fabric Enabler for ActiveMatrix Service Grid contains a vulnerability wherein a user without privileges to upload distributed application archives ("Upload DAA" permission) can theoretically upload arbitrary code, an

CVE-2019-5162
Moxa General
9.9
CRITICAL
EPSS
0.5%
2019 CWE-284 1 PoC

An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell access to the device as that user. An attacker can send commands while authenticated as a low privilege user to trigger this vulnerability.

CVE-2019-11510
🔥 KEV Software Genérico General ⚡ nuclei
9.9
CRITICAL
EPSS
94.5%
2019 12 PoCs

In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

CVE-2019-13343
Software Genérico General
9.9
CRITICAL
EPSS
0.7%
2019 5 PoCs

Butor Portal before 1.0.27 is affected by a Path Traversal vulnerability leading to a pre-authentication arbitrary file download. Effectively, a remote anonymous user can download any file on servers running Butor Portal. WhiteLabelingServlet is responsible for this vulnerability. It does not properly sanitize user input on the theme t parameter before reusing it in a path. This path is then used without validation to fetch a file and return its raw content to the user via the /wl?t=../../...&h= substring followed by a filename.

CVE-2021-35047
Fidelis Network General
9.9
CRITICAL
EPSS
0.9%
2021 CWE-78 1 PoC

Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the component and neighboring Fidelis components. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.

CVE-2021-21466
SAP Business Warehouse General
9.9
CRITICAL
EPSS
2.5%
2021 2 PoCs

SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Via the function module an attacker can create a malicious ABAP report which could be used to get access to sensitive data, to inject malicious UPDATE statements that could have also impact on the operating system, to disrupt the functionality of the SAP system which can thereby lead to a Denial of Service.