40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-1403
OpenEdge General
10.0
CRITICAL
EPSS
16.2%
2024 CWE-305 1 PoC

In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified.  The vulnerability is a bypass to authentication based on a failure to properly handle username and password. Certain unexpected content passed into the credentials can lead to unauthorized access without proper authentication.  

CVE-2024-50473
Ajar in5 Embed General
10.0
CRITICAL
EPSS
61.5%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-embed allows Upload a Web Shell to a Web Server.This issue affects Ajar in5 Embed: from n/a through <= 3.1.3.

CVE-2024-0916
UvDesk Community General
10.0
CRITICAL
EPSS
2.8%
2024 CWE-434 1 PoC

Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3.

CVE-2023-29017
vm2 General
10.0
CRITICAL
EPSS
75.0%
2023 CWE-913 3 PoCs

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host objects passed to `Error.prepareStackTrace` in case of unhandled async errors. A threat actor could bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.15 of vm2. There are no known workarounds.

CVE-2024-36388
DeviceHub General
10.0
CRITICAL
EPSS
0.2%
2024 CWE-305 1 PoC

MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function

CVE-2024-50482
Woocommerce Product Design General
10.0
CRITICAL
EPSS
55.5%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Upload a Web Shell to a Web Server.This issue affects Woocommerce Product Design: from n/a through <= 1.0.0.

CVE-2024-51793
RepairBuddy General
10.0
CRITICAL
EPSS
51.6%
2024 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Upload a Web Shell to a Web Server.This issue affects RepairBuddy: from n/a through <= 3.8115.

CVE-2024-43160
BerqWP General ⚡ nuclei
10.0
CRITICAL
EPSS
83.7%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6.

CVE-2024-8878
Netman 204 General
10.0
CRITICAL
EPSS
0.7%
2024 CWE-640 2 PoCs

The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.

CVE-2024-39700
extension-template General
10.0
CRITICAL
EPSS
3.9%
2024 CWE-94 1 PoC

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template to the latest version. Users who made changes to `update-integration-tests.yml`, accept overwriting of this file and re-apply your changes later. Users may wish to temporarily disable GitHub Actions while working on the upgrade. We recommend rebasing all open pull requests from untrusted users as

CVE-2024-13981
LiveBOS General
10.0
CRITICAL
EPSS
1.8%
2024 CWE-434 3 PoCs

LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arbitrary file upload vulnerability in its UploadFile.do;.js.jsp endpoint. This flaw affects the LiveBOS Server component and allows unauthenticated remote attackers to upload crafted files outside the intended directory structure via path traversal in the filename parameter. Successful exploitation may lead to remote code execution on the server, enabling full system compromise. The vulnerability is presumed to affect builds released prior to August 2024 and is said to be remed

CVE-2023-2024
OpenBlue Enterprise Manager Data Collector General
10.0
CRITICAL
EPSS
0.3%
2023 CWE-287 2 PoCs

Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.

CVE-2024-49668
Verbalize WP General
10.0
CRITICAL
EPSS
59.0%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in christopherdewese1099 Verbalize WP verbalize-wp allows Upload a Web Shell to a Web Server.This issue affects Verbalize WP: from n/a through <= 1.0.

CVE-2024-32651
changedetection.io General ⚡ nuclei
10.0
CRITICAL
EPSS
92.3%
2024 CWE-1336 3 PoCs

changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover the server machine. This can be reduced if changedetection is behind a login page, but this isn't required by the application (not by default and not enforced).

CVE-2024-52380
Picsmize General
10.0
CRITICAL
EPSS
60.4%
2024 CWE-434 3 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in softpulseinfotech Picsmize picsmize allows Upload a Web Shell to a Web Server.This issue affects Picsmize: from n/a through <= 1.0.0.

CVE-2024-52375
Datasets Manager by Arttia Creative General
10.0
CRITICAL
EPSS
60.6%
2024 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type vulnerability in Arttia Creative Datasets Manager by Arttia Creative datasets-manager-by-arttia-creative.This issue affects Datasets Manager by Arttia Creative: from n/a through <= 1.5.

CVE-2024-0001
FlashArray General
10.0
CRITICAL
EPSS
2.2%
2024 CWE-1188 2 PoCs

A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.

CVE-2023-2138
nuxtlabs/github-module General
10.0
CRITICAL
EPSS
0.4%
2023 CWE-798 1 PoC

Use of Hard-coded Credentials in GitHub repository nuxtlabs/github-module prior to 1.6.2.

CVE-2023-7309
Smart Park Integrated Management Platform General
10.0
CRITICAL
EPSS
2.1%
2023 CWE-434 2 PoCs

A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via crafted SOAP requests, including executable JSP payloads. Successful exploitation may lead to remote code execution (RCE) and full compromise of the affected system. The vulnerability is presumed to affect builds released prior to September 2023 and is said to be remediated in newer

CVE-2023-51409
AI Engine: ChatGPT Chatbot General ⚡ nuclei
10.0
CRITICAL
EPSS
92.9%
2023 CWE-434 4 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.