9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2023-29084
Software Genérico General ⚡ nuclei
7.2
HIGH
EPSS
93.9%
2023 2 PoCs

Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.

CVE-2023-33634
Software Genérico General
7.2
HIGH
EPSS
0.1%
2023 2 PoCs

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the EdittriggerList interface at /goform/aspForm.

CVE-2023-26262
Software Genérico General
7.2
HIGH
EPSS
17.5%
2023 1 PoC

An issue was discovered in Sitecore XP/XM 10.3. As an authenticated Sitecore user, a unrestricted language file upload vulnerability exists the can lead to direct code execution on the content management (CM) server.

CVE-2023-33638
Software Genérico General
7.2
HIGH
EPSS
0.1%
2023 1 PoC

H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the Edit_BasicSSID_5G interface at /goform/aspForm.

CVE-2023-0046
lirantal/daloradius General
7.2
HIGH
EPSS
0.4%
2023 CWE-641 1 PoC

Improper Restriction of Names for Files and Other Resources in GitHub repository lirantal/daloradius prior to master-branch.

CVE-2024-54385
Radio Player General ⚡ nuclei
7.2
HIGH
EPSS
81.0%
2024 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio Player: from n/a through <= 2.0.83.

CVE-2024-40318
Software Genérico General
7.2
HIGH
EPSS
10.1%
2024 1 PoC

An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-22274
VMware vCenter Server General
7.2
HIGH
EPSS
63.5%
2024 4 PoCs

The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.

CVE-2024-33529
Software Genérico General
7.2
HIGH
EPSS
0.8%
2024 1 PoC

ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to execute operating system commands via file uploads with dangerous types.

CVE-2024-33250
Software Genérico General
7.2
HIGH
EPSS
0.4%
2024 1 PoC

An issue in Open-Source Technology Committee SRS real-time video server RS/4.0.268(Leo) and SRS/4.0.195(Leo) allows a remote attacker to execute arbitrary code via a crafted request.

CVE-2024-21518
opencart/opencart General
7.2
HIGH
EPSS
2.1%
2024 CWE-29 1 PoC

This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sanitization of the target path, allowing files within a malicious archive to traverse the filesystem and be extracted to arbitrary locations. An attacker can create arbitrary files in the web root of the application and overwrite other existing files by exploiting this vulnerability.

CVE-2024-41199
Software Genérico General
7.2
HIGH
EPSS
0.1%
2024 1 PoC

An issue in Ocuco Innovation - JOBMANAGER.EXE v2.10.24.16 allows attackers to bypass authentication and escalate privileges to Administrator via a crafted TCP packet.

CVE-2024-3154
Software Genérico General
7.2
HIGH
EPSS
0.2%
2024 CWE-77 1 PoC

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.

CVE-2024-50960
Software Genérico General
7.2
HIGH
EPSS
4.3%
2024 1 PoC

A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.

CVE-2024-48454
Software Genérico General
7.2
HIGH
EPSS
2.7%
2024 2 PoCs

An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via the /admin?page=user component

CVE-2024-31485
CPCI85 Central Processing/Communication General
7.2
HIGH
EPSS
0.6%
2024 CWE-77 1 PoC

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.30), SICORE Base system (All versions < V1.3.0). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.

CVE-2024-36694
Software Genérico General
7.2
HIGH
EPSS
1.0%
2024 2 PoCs

OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.

CVE-2024-25955
Virtual Appliance (vApp) Manager General
7.2
HIGH
EPSS
0.4%
2024 CWE-78 1 PoC

Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.

CVE-2024-25946
Virtual Appliance (vApp) Manager General
7.2
HIGH
EPSS
0.4%
2024 CWE-78 1 PoC

Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.

CVE-2024-22722
Software Genérico General
7.2
HIGH
EPSS
0.1%
2024 1 PoC

Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.