3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-40318
Software Genérico General
7.2
HIGH
EPSS
10.1%
2024 1 PoC

An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-50960
Software Genérico General
7.2
HIGH
EPSS
4.3%
2024 1 PoC

A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.

CVE-2024-40442
Software Genérico General
7.2
HIGH
EPSS
0.5%
2024 1 PoC

An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via a crafted REST Request.

CVE-2024-34370
EAN for WooCommerce General
7.2
HIGH
EPSS
9.2%
2024 CWE-269 1 PoC

Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.

CVE-2024-48454
Software Genérico General
7.2
HIGH
EPSS
2.7%
2024 2 PoCs

An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via the /admin?page=user component

CVE-2024-6333
AltaLink® B8045 / B8055 / B8065 / B8075 / B8090 | C8030 / C8035 / C8045 / C8055 / C807 General
7.2
HIGH
EPSS
3.7%
2024 CWE-78 1 PoC

Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.

CVE-2024-24386
Software Genérico General
7.2
HIGH
EPSS
1.4%
2024 1 PoC

An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder.

CVE-2024-31485
CPCI85 Central Processing/Communication General
7.2
HIGH
EPSS
0.6%
2024 CWE-77 1 PoC

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.30), SICORE Base system (All versions < V1.3.0). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges.

CVE-2024-0200
Enterprise Server General ⚡ nuclei
7.2
HIGH
EPSS
70.8%
2024 CWE-470 1 PoC

An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-controlled methods and remote code execution. To exploit this bug, an actor would need to be logged into an account on the GHES instance with the organization owner role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.8.13, 3.9.8, 3.10.5, and 3.11.3. This vulnerability was reported via the GitHub Bug Bounty program.

CVE-2024-0998
N200RE General
7.2
HIGH
EPSS
0.5%
2024 CWE-121 1 PoC

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. This affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252267. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-22274
VMware vCenter Server General
7.2
HIGH
EPSS
63.5%
2024 4 PoCs

The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating system.

CVE-2024-36694
Software Genérico General
7.2
HIGH
EPSS
1.0%
2024 2 PoCs

OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.

CVE-2024-5672
mbNET.mini General
7.2
HIGH
EPSS
0.7%
2024 CWE-78 1 PoC

A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.

CVE-2024-21683
Confluence Data Center General ⚡ nuclei
7.2
HIGH
EPSS
94.1%
2024 9 PoCs

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction.  Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version. If you are unable to do so, upgrade your instance to one of the specified supported fixed versions. See the

CVE-2024-22722
Software Genérico General
7.2
HIGH
EPSS
0.1%
2024 1 PoC

Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.

CVE-2024-1001
N200RE General
7.2
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability classified as critical has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected is the function main of the file /cgi-bin/cstecgi.cgi. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-252270 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-21518
opencart/opencart General
7.2
HIGH
EPSS
2.1%
2024 CWE-29 1 PoC

This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sanitization of the target path, allowing files within a malicious archive to traverse the filesystem and be extracted to arbitrary locations. An attacker can create arbitrary files in the web root of the application and overwrite other existing files by exploiting this vulnerability.

CVE-2024-25955
Virtual Appliance (vApp) Manager General
7.2
HIGH
EPSS
0.4%
2024 CWE-78 1 PoC

Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.

CVE-2024-54385
Radio Player General ⚡ nuclei
7.2
HIGH
EPSS
81.0%
2024 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio Player: from n/a through <= 2.0.83.

CVE-2024-1003
N200RE General
7.2
HIGH
EPSS
0.1%
2024 CWE-121 1 PoC

A vulnerability, which was classified as critical, has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this issue is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument lang leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252272. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.