3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-54369
Zita Site Builder General
9.1
CRITICAL
EPSS
19.3%
2024 CWE-862 2 PoCs

Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Zita Site Builder: from n/a through <= 1.0.2.

CVE-2024-29643
Software Genérico General
9.1
CRITICAL
EPSS
0.4%
2024 1 PoC

An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.

CVE-2024-10025
SICK CLV6xx General
9.1
CRITICAL
EPSS
0.1%
2024 CWE-798 1 PoC

A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By exploiting these plaintext credentials, an attacker can log into affected SICK products as an “Authorized Client” if the customer has not changed the default password.

CVE-2024-31114
Shortcode Addons General
9.1
CRITICAL
EPSS
48.7%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in biplob018 Shortcode Addons.This issue affects Shortcode Addons: from n/a through 3.2.5.

CVE-2024-35293
Series 700 General
9.1
CRITICAL
EPSS
1.9%
2024 CWE-306 2 PoCs

An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resulting in data loss and/or a DoS.

CVE-2024-5806
MOVEit Transfer General
9.1
CRITICAL
EPSS
89.9%
2024 CWE-287 2 PoCs

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

CVE-2024-48905
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.

CVE-2024-37310
everest-core General
9.1
CRITICAL
EPSS
1.9%
2024 CWE-122 1 PoC

EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp implementation can allow a remote attacker to overflow the process' heap. This vulnerability is fixed in 2024.3.1 and 2024.6.0.

CVE-2024-4399
cas General ⚡ nuclei
9.1
CRITICAL
EPSS
25.0%
2024 1 PoC

The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack

CVE-2024-56249
WPMasterToolKit General
9.1
CRITICAL
EPSS
41.6%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Upload a Web Shell to a Web Server.This issue affects WPMasterToolKit: from n/a through <= 1.13.1.

CVE-2024-53553
Software Genérico General
9.1
CRITICAL
EPSS
0.1%
2024 1 PoC

An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web requests.

CVE-2024-20720
Adobe Commerce General
9.1
CRITICAL
EPSS
7.2%
2024 CWE-78 1 PoC

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.

CVE-2024-43401
xwiki-platform General
9.1
CRITICAL
EPSS
1.5%
2024 CWE-269 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The user with elevated rights is not warned beforehand that they are going to edit possibly dangerous content. The payload is executed at edit time. This vulnerability has been patched in XWiki 15.10RC1.

CVE-2024-34451
Software Genérico General
9.1
CRITICAL
EPSS
0.7%
2024 1 PoC

Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers.

CVE-2024-48145
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

CVE-2024-36394
SysAid General
9.1
CRITICAL
EPSS
0.1%
2024 CWE-78 1 PoC

SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CVE-2024-25735
Software Genérico General ⚡ nuclei
9.1
CRITICAL
EPSS
90.4%
2024 2 PoCs

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.

CVE-2024-28987
🔥 KEV Web Help Desk General ⚡ nuclei
9.1
CRITICAL
EPSS
94.3%
2024 CWE-798 7 PoCs

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

CVE-2024-48144
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2024 1 PoC

A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

CVE-2024-57766
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2024 1 PoC

MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField.