2350 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-48914
vendure General ⚡ nuclei
9.1
CRITICAL
EPSS
92.5%
2024 CWE-22 1 PoC

Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an attacker to craft a request which is able to traverse the server file system and retrieve the contents of arbitrary files, including sensitive data such as configuration files, environment variables, and other critical data stored on the server. In the same code path is an additional vector for crashing the server via a malformed URI. Patches are available in versions 3.0.5 and 2.3.3. Some workarounds are also available. One may use object storage

CVE-2024-46505
Software Genérico General
9.1
CRITICAL
EPSS
0.0%
2024 1 PoC

Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

CVE-2024-40583
Software Genérico General
9.1
CRITICAL
EPSS
0.4%
2024 1 PoC

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.

CVE-2024-33661
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

Portainer before 2.20.0 allows redirects when the target is not index.yaml.

CVE-2024-54794
Software Genérico General
9.1
CRITICAL
EPSS
2.2%
2024 2 PoCs

The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.

CVE-2024-10025
SICK CLV6xx General
9.1
CRITICAL
EPSS
0.1%
2024 CWE-798 1 PoC

A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Authorized Client” if the customer has not changed the default password.

CVE-2024-21887
🔥 KEV ICS General ⚡ nuclei
9.1
CRITICAL
EPSS
94.4%
2024 9 PoCs

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

CVE-2024-34451
Software Genérico General
9.1
CRITICAL
EPSS
0.7%
2024 1 PoC

Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.

CVE-2024-10474
Focus for iOS General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

Focus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumventing some URL safety checks This vulnerability affects Focus for iOS < 132.

CVE-2024-20720
Adobe Commerce General
9.1
CRITICAL
EPSS
7.2%
2024 CWE-78 1 PoC

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.

CVE-2024-23717
Android General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

In access_secure_service_from_temp_bond of btm_sec.cc, there is a possible way to achieve keystroke injection due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-48942
Software Genérico General
9.1
CRITICAL
EPSS
0.5%
2024 1 PoC

The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 30 tokens are valid.

CVE-2024-2862
LG LED Assistant General ⚡ nuclei
9.1
CRITICAL
EPSS
74.5%
2024 CWE-287 0 PoCs

This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.

CVE-2024-56249
WPMasterToolKit General
9.1
CRITICAL
EPSS
41.6%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Upload a Web Shell to a Web Server.This issue affects WPMasterToolKit: from n/a through <= 1.13.1.

CVE-2024-53553
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests.

CVE-2024-31114
Shortcode Addons General
9.1
CRITICAL
EPSS
48.7%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in biplob018 Shortcode Addons.This issue affects Shortcode Addons: from n/a through 3.2.5.

CVE-2024-36391
DeviceHub General
9.1
CRITICAL
EPSS
0.0%
2024 CWE-320 1 PoC

MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic

CVE-2024-45436
Software Genérico General
9.1
CRITICAL
EPSS
29.1%
2024 4 PoCs

extractFromZipFile in model.go in Ollama before 0.1.47 can extract members of a ZIP archive outside of the parent directory.

CVE-2024-4399
cas General ⚡ nuclei
9.1
CRITICAL
EPSS
25.0%
2024 1 PoC

The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack

CVE-2024-48941
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint of Jira, Confluence, or Bitbucket. In the default configuration, /rest is allowlisted.