3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-10915
DNS-320 General ⚡ nuclei
9.2
CRITICAL
EPSS
94.1%
2024 CWE-78 1 PoC

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument group leads to os command injection. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

CVE-2024-5217
🔥 KEV Now Platform General ⚡ nuclei
9.2
CRITICAL
EPSS
94.1%
2024 CWE-184 2 PoCs

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

CVE-2024-10914
DNS-320 General ⚡ nuclei
9.2
CRITICAL
EPSS
94.0%
2024 CWE-78 14 PoCs

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument name leads to os command injection. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

CVE-2024-27448
Software Genérico General
9.1
CRITICAL
EPSS
13.0%
2024 1 PoC

MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js writing arbitrary code into the routes.js file.

CVE-2024-41713
🔥 KEV Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
94.1%
2024 5 PoCs

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized access, enabling the attacker to view, corrupt, or delete users' data and system configurations.

CVE-2024-32002
git General
9.1
CRITICAL
EPSS
79.6%
2024 CWE-22 62 PoCs

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a way that exploits a bug in Git whereby it can be fooled into writing files not into the submodule's worktree but into a `.git/` directory. This allows writing a hook that will be executed while the clone operation is still running, giving the user no opportunity to inspect the code that is being executed. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. If symbolic link support is dis

CVE-2024-53900
Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
52.2%
2024 2 PoCs

Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

CVE-2024-38883
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation.

CVE-2024-21887
🔥 KEV ICS General ⚡ nuclei
9.1
CRITICAL
EPSS
94.4%
2024 9 PoCs

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

CVE-2024-31114
Shortcode Addons General
9.1
CRITICAL
EPSS
48.7%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in biplob018 Shortcode Addons.This issue affects Shortcode Addons: from n/a through 3.2.5.

CVE-2024-36391
DeviceHub General
9.1
CRITICAL
EPSS
0.0%
2024 CWE-320 1 PoC

MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic

CVE-2024-53553
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests.

CVE-2024-25413
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved Import And Export v3.8.6 allows attackers to execute arbitrary commands via a crafted XSLT file.

CVE-2024-45163
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 4 PoCs

The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, an attacker can send a recognized username (such as root), or can send arbitrary data.

CVE-2024-37899
xwiki-platform General
9.1
CRITICAL
EPSS
14.1%
2024 CWE-94 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an admin disables a user account, the user's profile is executed with the admin's rights. This allows a user to place malicious code in the user profile before getting an admin to disable the user account. To reproduce, as a user without script nor programming rights, edit the about section of your user profile and add `{{groovy}}services.logging.getLogger("attacker").error("Hello from Groovy!"){{/groovy}}`. As an admin, go to the user profile and click the "Disable this account" butto

CVE-2024-56249
WPMasterToolKit General
9.1
CRITICAL
EPSS
41.6%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Upload a Web Shell to a Web Server.This issue affects WPMasterToolKit: from n/a through <= 1.13.1.

CVE-2024-46505
Software Genérico General
9.1
CRITICAL
EPSS
0.0%
2024 1 PoC

Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

CVE-2024-46627
Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
91.7%
2024 1 PoC

Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.

CVE-2024-45168
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 2 PoCs

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without any authentication mechanism. Thus, communication endpoints are not verifiable.

CVE-2024-2862
LG LED Assistant General ⚡ nuclei
9.1
CRITICAL
EPSS
74.5%
2024 CWE-287 0 PoCs

This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.