40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-53442
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2024 1 PoC

whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component.

CVE-2024-13804
HPE Insight Cluster Management Utility (CMU) General
9.8
CRITICAL
EPSS
0.3%
2024 1 PoC

Unauthenticated RCE in HPE Insight Cluster Management Utility

CVE-2024-56431
Software Genérico General
9.8
CRITICAL
EPSS
11.1%
2024 4 PoCs

oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid negative left shift. NOTE: this is disputed by third parties because there is no evidence of a security impact, e.g., an application would not crash.

CVE-2024-50507
DS.DownloadList General
9.8
CRITICAL
EPSS
22.1%
2024 CWE-502 1 PoC

Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This issue affects DS.DownloadList: from n/a through <= 1.3.

CVE-2024-25421
Software Genérico General
9.8
CRITICAL
EPSS
2.6%
2024 1 PoC

An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.

CVE-2024-28394
Software Genérico General
9.8
CRITICAL
EPSS
2.0%
2024 1 PoC

An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & Export module.

CVE-2024-54383
WooCommerce PDF Vouchers General
9.8
CRITICAL
EPSS
7.1%
2024 CWE-266 1 PoC

Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Privilege Escalation.This issue affects WooCommerce PDF Vouchers: from n/a through < 4.9.9.

CVE-2024-50944
Software Genérico General
9.8
CRITICAL
EPSS
2.8%
2024 1 PoC

Integer overflow vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f in the shopping cart functionality. The issue lies in the quantity parameter in the CartController's AddToCart method.

CVE-2024-56059
Partners General
9.8
CRITICAL
EPSS
32.3%
2024 CWE-1321 1 PoC

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Partners partners allows Object Injection.This issue affects Partners: from n/a through <= 0.2.0.

CVE-2024-44410
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2024 1 PoC

D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.

CVE-2024-25169
Software Genérico General
9.8
CRITICAL
EPSS
1.1%
2024 1 PoC

An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted request.

CVE-2019-20461
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2019 1 PoC

An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP protocol to start and control video and audio services. The protocol has been partially reverse engineered. Based upon the reverse engineering, no password or username is ever transferred over this protocol. Thus, one can set up the camera connection feed with only the encoded UID. It is possible to set up sessions with the camera over the Internet by using the encoded UID and the custom UDP protocol, because authentication happens at the client side.

CVE-2019-3396
🔥 KEV Confluence Server General ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2019 26 PoCs

The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x), and from version 6.14.0 before 6.14.2 (the fixed version for 6.14.x), allows remote attackers to achieve path traversal and remote code execution on a Confluence Server or Data Center instance via server-side template injection.

CVE-2019-18935
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
93.6%
2019 14 PoCs

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)

CVE-2019-5029
Exhibitor General
9.8
CRITICAL
EPSS
85.2%
2019 CWE-78 3 PoCs

An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches ZooKeeper. An attacker can execute any command as the user running the Exhibitor process.

CVE-2019-16057
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.0%
2019 1 PoC

The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.

CVE-2019-9884
eclass General
9.8
CRITICAL
EPSS
0.4%
2019 CWE-284 1 PoC

eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page.

CVE-2019-13658
CA Network Flow Analysis General
9.8
CRITICAL
EPSS
1.3%
2019 CWE-798 1 PoC

CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security.

CVE-2019-5083
Accusoft General
9.8
CRITICAL
EPSS
2.2%
2019 CWE-787 1 PoC

An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll TIFdecodethunderscan function of Accusoft ImageGear 19.3.0 library. A specially crafted TIFF file can cause an out of bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.