3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-39700
extension-template General
10.0
CRITICAL
EPSS
3.9%
2024 CWE-94 1 PoC

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template to the latest version. Users who made changes to `update-integration-tests.yml`, accept overwriting of this file and re-apply your changes later. Users may wish to temporarily disable GitHub Actions while working on the upgrade. We recommend rebasing all open pull requests from untrusted users as

CVE-2024-50498
WP Query Console General ⚡ nuclei
10.0
CRITICAL
EPSS
91.9%
2024 CWE-94 4 PoCs

Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This issue affects WP Query Console: from n/a through <= 1.0.

CVE-2024-0001
FlashArray General
10.0
CRITICAL
EPSS
2.2%
2024 CWE-1188 2 PoCs

A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.

CVE-2024-50526
Multi Purpose Mail Form General
10.0
CRITICAL
EPSS
1.1%
2024 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose-mail-form allows Upload a Web Shell to a Web Server.This issue affects Multi Purpose Mail Form: from n/a through <= 1.0.2.

CVE-2024-45519
🔥 KEV Software Genérico General
10.0
CRITICAL
EPSS
94.2%
2024 7 PoCs

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.

CVE-2024-2389
Flowmon General ⚡ nuclei
10.0
CRITICAL
EPSS
94.3%
2024 CWE-78 1 PoC

In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.

CVE-2024-32962
xml-crypto General
10.0
CRITICAL
EPSS
10.6%
2024 CWE-347 1 PoC

xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuration does not check authorization of the signer, it only checks the validity of the signature per section 3.2.2 of the w3 xmldsig-core-20080610 spec. As such, without additional validation steps, the default configuration allows a malicious actor to re-sign an XML document, place the certificate in a `<KeyInfo />` element, and pass `xml-crypto` default validation checks. As a result `xml-crypto` trusts by default any certificate provided via digitally signed XML document's `<Key

CVE-2024-27972
WP Fusion Lite General
9.9
CRITICAL
EPSS
38.2%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lite: from n/a through <= 3.41.24.

CVE-2024-37762
Software Genérico General
9.9
CRITICAL
EPSS
28.0%
2024 1 PoC

MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

CVE-2024-52429
WP Quick Setup General
9.9
CRITICAL
EPSS
41.1%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in AntonHoelstad WP Quick Setup wp-quick-setup allows Upload a Web Shell to a Web Server.This issue affects WP Quick Setup: from n/a through <= 2.0.

CVE-2024-37361
Pentaho Data Integration & Analytics General
9.9
CRITICAL
EPSS
0.4%
2024 CWE-502 1 PoC

The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502)   Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.   When developers place no restrictions on "gadget chains," or series of instances and method invocations that can self-execute during the deserialization process (i.e., before the object is returned to the caller), it is sometimes possible for attackers to le

CVE-2024-54262
Import Export For WooCommerce General
9.9
CRITICAL
EPSS
54.8%
2024 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Import Export For WooCommerce: from n/a through <= 1.6.2.

CVE-2024-4701
Genie General
9.9
CRITICAL
EPSS
17.6%
2024 CWE-22 2 PoCs

A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18

CVE-2024-50427
SurveyJS General
9.9
CRITICAL
EPSS
69.7%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in devsoftbaltic SurveyJS surveyjs.This issue affects SurveyJS: from n/a through <= 1.9.136.

CVE-2024-31286
WP Photo Album Plus General
9.9
CRITICAL
EPSS
0.6%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.

CVE-2024-31380
Oxygen Builder General
9.9
CRITICAL
EPSS
0.1%
2024 CWE-94 4 PoCs

Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, refuses to patch the issue.This issue affects Oxygen Builder: from n/a through 4.9.

CVE-2024-31390
Breakdance General
9.9
CRITICAL
EPSS
0.1%
2024 CWE-94 3 PoCs

: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.

CVE-2024-42448
Service Provider Console General
9.9
CRITICAL
EPSS
64.4%
2024 2 PoCs

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution (RCE) on the VSPC server machine.

CVE-2024-49653
Portfolleo General
9.9
CRITICAL
EPSS
59.0%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in james-eggers Portfolleo portfolleo allows Upload a Web Shell to a Web Server.This issue affects Portfolleo: from n/a through <= 1.2.

CVE-2024-9014
pgAdmin 4 General ⚡ nuclei
9.9
CRITICAL
EPSS
92.9%
2024 2 PoCs

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.