1641 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-32962
xml-crypto General
10.0
CRITICAL
EPSS
10.6%
2024 CWE-347 1 PoC

xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorization of the signer, it only checks the validity of the signature per section 3.2.2 of the w3 xmldsig-core-20080610 spec. As such, without additional validation steps, the default configuration allows a malicious actor to re-sign an XML document, place the certificate in a `<KeyInfo />` element, and pass `xml-crypto` default validation checks. As a result `xml-crypto` trusts by default any certificate provided via digitally signed XML document's `<Key

CVE-2024-9478
upKeeper Instant Privilege Access General
10.0
CRITICAL
EPSS
0.2%
2024 CWE-266 1 PoC

Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.

CVE-2024-21650
xwiki-platform General ⚡ nuclei
10.0
CRITICAL
EPSS
92.5%
2024 CWE-95 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to execute arbitrary code by crafting malicious payloads in the "first name" or "last name" fields during user registration. This impacts all installations that have user registration enabled for guests. This vulnerability has been patched in XWiki 14.10.17, 15.5.3 and 15.8 RC1.

CVE-2024-43160
BerqWP General ⚡ nuclei
10.0
CRITICAL
EPSS
83.7%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6.

CVE-2024-13981
LiveBOS General
10.0
CRITICAL
EPSS
1.8%
2024 CWE-434 3 PoCs

LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arbitrary file upload vulnerability in its UploadFile.do;.js.jsp endpoint. This flaw affects the LiveBOS Server component and allows unauthenticated remote attackers to upload crafted files outside the intended directory structure via path traversal in the filename parameter. Successful exploitation may lead to remote code execution on the server, enabling full system compromise. The vulnerability is presumed to affect builds released prior to August 2024 and is said to be remed

CVE-2024-49607
WP Dropbox Dropins General
10.0
CRITICAL
EPSS
23.5%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in redhopit WP Dropbox Dropins wp-dropbox-dropins allows Upload a Web Shell to a Web Server.This issue affects WP Dropbox Dropins: from n/a through <= 1.0.

CVE-2024-0916
UvDesk Community General
10.0
CRITICAL
EPSS
2.8%
2024 CWE-434 1 PoC

Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3.

CVE-2024-56064
WP SuperBackup General
10.0
CRITICAL
EPSS
55.5%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in azzaroco WP SuperBackup indeed-wp-superbackup allows Upload a Web Shell to a Web Server.This issue affects WP SuperBackup: from n/a through <= 2.3.3.

CVE-2024-51568
Software Genérico General ⚡ nuclei
10.0
CRITICAL
EPSS
93.0%
2024 2 PoCs

CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacters.

CVE-2024-54085
🔥 KEV MegaRAC-SPx General
10.0
CRITICAL
EPSS
43.0%
2024 CWE-290 3 PoCs

AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.

CVE-2024-50526
Multi Purpose Mail Form General
10.0
CRITICAL
EPSS
1.1%
2024 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose-mail-form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through <= 1.0.2.

CVE-2024-7591
LoadMaster General ⚡ nuclei
10.0
CRITICAL
EPSS
31.5%
2024 CWE-78 1 PoC

Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above

CVE-2024-13980
Intelligent Management Center (iMC) General
10.0
CRITICAL
EPSS
2.9%
2024 CWE-502 4 PoCs

H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulnerability in the /byod/index.xhtml endpoint. Improper handling of JSF ViewState allows unauthenticated attackers to craft POST requests with forged javax.faces.ViewState parameters, potentially leading to arbitrary command execution. This flaw does not require authentication and may be exploited without session cookies. An affected version range is undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-08-28 UTC.

CVE-2024-45409
ruby-saml General
10.0
CRITICAL
EPSS
42.4%
2024 CWE-347 1 PoC

The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as arbitrary user within the vulnerable system. This vulnerability is fixed in 1.17.0 and 1.12.3.

CVE-2024-29847
EPM General
10.0
CRITICAL
EPSS
62.8%
2024 2 PoCs

Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

CVE-2024-1212
🔥 KEV LoadMaster General ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2024 CWE-78 5 PoCs

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

CVE-2024-50510
AR For Woocommerce General
10.0
CRITICAL
EPSS
33.0%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For Woocommerce ar-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects AR For Woocommerce: from n/a through <= 6.3.

CVE-2024-51378
🔥 KEV Software Genérico General ⚡ nuclei
10.0
CRITICAL
EPSS
93.9%
2024 5 PoCs

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX. Versions through 2.3.6 and (unpatched) 2.3.7 are affected.

CVE-2024-50473
Ajar in5 Embed General
10.0
CRITICAL
EPSS
61.5%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through <= 3.1.3.

CVE-2024-39700
extension-template General
10.0
CRITICAL
EPSS
3.9%
2024 CWE-94 1 PoC

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template to the latest version. Users who made changes to `update-integration-tests.yml`, accept overwriting of this file and re-apply your changes later. Users may wish to temporarily disable GitHub Actions while working on the upgrade. We recommend rebasing all open pull requests from untrusted users as