9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-50493
Automatic Translation General
10.0
CRITICAL
EPSS
55.5%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in masterhomepage Automatic Translation automatic-translation allows Upload a Web Shell to a Web Server.This issue affects Automatic Translation: from n/a through <= 1.0.4.

CVE-2024-52375
Datasets Manager by Arttia Creative General
10.0
CRITICAL
EPSS
60.6%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Arttia Creative Datasets Manager by Arttia Creative datasets-manager-by-arttia-creative.This issue affects Datasets Manager by Arttia Creative: from n/a through <= 1.5.

CVE-2024-31351
Copymatic – AI Content Writer & Generator General
10.0
CRITICAL
EPSS
53.6%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Copymatic Copymatic – AI Content Writer & Generator.This issue affects Copymatic – AI Content Writer & Generator: from n/a through 1.6.

CVE-2024-1651
Torrentpier General
10.0
CRITICAL
EPSS
80.6%
2024 CWE-502 4 PoCs

Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.

CVE-2024-13984
TianQing Management Center General
10.0
CRITICAL
EPSS
2.0%
2024 CWE-73 2 PoCs

QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the rptsvr component that allows unauthenticated attackers to upload files to arbitrary locations on the server. The /rptsvr/upload endpoint fails to sanitize the filename parameter in multipart form-data requests, enabling path traversal. This allows attackers to place executable files in web-accessible directories, potentially leading to remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-08-23 UTC.

CVE-2024-51788
The Novel Design Store Directory General
10.0
CRITICAL
EPSS
62.1%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesign-store-directory allows Upload a Web Shell to a Web Server.This issue affects The Novel Design Store Directory: from n/a through <= 4.3.0.

CVE-2024-5261
LibreOffice General
10.0
CRITICAL
EPSS
0.5%
2024 CWE-295 1 PoC

Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice functionality through C/C++. Typically this is used by third party components to reuse LibreOffice as a library to convert, view or otherwise interact with documents. LibreOffice internally makes use of "curl" to fetch remote resources such as images hosted on webservers. In affected versions of LibreOffice, when used in LibreOfficeKit mode only, then curl's TLS certification verification was disabled (CURLOPT_S

CVE-2024-9479
upKeeper Instant Privilege Access General
10.0
CRITICAL
EPSS
0.2%
2024 CWE-266 1 PoC

Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.

CVE-2024-50482
Woocommerce Product Design General
10.0
CRITICAL
EPSS
55.5%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Upload a Web Shell to a Web Server.This issue affects Woocommerce Product Design: from n/a through <= 1.0.0.

CVE-2024-51793
RepairBuddy General
10.0
CRITICAL
EPSS
51.6%
2024 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Upload a Web Shell to a Web Server.This issue affects RepairBuddy: from n/a through <= 3.8115.

CVE-2024-8878
Netman 204 General
10.0
CRITICAL
EPSS
0.7%
2024 CWE-640 2 PoCs

The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.

CVE-2024-3094
Software Genérico General
10.0
CRITICAL
EPSS
84.8%
2024 CWE-506 65 PoCs

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.

CVE-2024-25600
Bricks Builder General ⚡ nuclei
10.0
CRITICAL
EPSS
93.9%
2024 CWE-94 22 PoCs

Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.

CVE-2024-31982
xwiki-platform General ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2024 CWE-95 7 PoCs

XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's database search allows remote code execution through the search text. This allows remote code execution for any visitor of a public wiki or user of a closed wiki as the database search is by default accessible for all users. This impacts the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been patched in XWiki 14.10.20, 15.5.4 and 15.10RC1. As a workaround, one may manually apply the patch to the page `

CVE-2024-1403
OpenEdge General
10.0
CRITICAL
EPSS
16.2%
2024 CWE-305 1 PoC

In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified.  The vulnerability is a bypass to authentication based on a failure to properly handle username and password. Certain unexpected content passed into the credentials can lead to unauthorized access without proper authentication.  

CVE-2024-36388
DeviceHub General
10.0
CRITICAL
EPSS
0.2%
2024 CWE-305 1 PoC

MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function

CVE-2024-49668
Verbalize WP General
10.0
CRITICAL
EPSS
59.0%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in christopherdewese1099 Verbalize WP verbalize-wp allows Upload a Web Shell to a Web Server.This issue affects Verbalize WP: from n/a through <= 1.0.

CVE-2024-42462
upKeeper Manager General
10.0
CRITICAL
EPSS
0.1%
2024 CWE-306 1 PoC

Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.

CVE-2024-52380
Picsmize General
10.0
CRITICAL
EPSS
60.4%
2024 CWE-434 3 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in softpulseinfotech Picsmize picsmize allows Upload a Web Shell to a Web Server.This issue affects Picsmize: from n/a through <= 1.0.0.

CVE-2024-32651
changedetection.io General ⚡ nuclei
10.0
CRITICAL
EPSS
92.3%
2024 CWE-1336 3 PoCs

changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover the server machine. This can be reduced if changedetection is behind a login page, but this isn't required by the application (not by default and not enforced).